Hewlett Packard Enterprise Aruba Airwave vulnerabilities
2 known vulnerabilities affecting hewlett_packard_enterprise/aruba_airwave.
Total CVEs
2
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2016-8526HIGHCVSS 8.8PoCvall versions up to, but not including, 8.2.3.12018-08-06
CVE-2016-8526 [HIGH] CWE-611 CVE-2016-8526: Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entiti
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to access storage that exist on external systems. If an unprivileged user is permitted to control the contents of XML files, XXE can be used as an attack vector. Because the XML parser has access to the local
cvelistv5nvd
CVE-2016-8527MEDIUMCVSS 6.1PoCvall versions up to, but not including, 8.2.3.12018-08-06
CVE-2016-8527 [MEDIUM] CWE-79 CVE-2016-8527: Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is present in the VisualRF component of AirWave. By exploiting this vulnerability, an attacker who can trick a logged-in AirWave administrative user into clicking a link could obtain sensitive information, such as sess
cvelistv5nvd