Hewlett Packard Enterprise Aruba Clearpass Policy Manager vulnerabilities
127 known vulnerabilities affecting hewlett_packard_enterprise/aruba_clearpass_policy_manager.
Total CVEs
127
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH69MEDIUM42
Vulnerabilities
Page 2 of 7
CVE-2023-25592MEDIUMCVSS 6.1v6.11.1 and belowv6.10.8 and below+1 more2023-03-22
CVE-2023-25592 [MEDIUM] CWE-79 CVE-2023-25592: Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a
Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
cvelistv5nvd
CVE-2023-25591MEDIUMCVSS 6.5v6.11.1 and belowv6.10.8 and below+1 more2023-03-22
CVE-2023-25591 [MEDIUM] CWE-266 CVE-2023-25591: A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remo
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further privileges on the ClearPass instance.
cvelistv5nvd
CVE-2022-43536HIGHCVSS 8.8vClearPass Policy Manager 6.10.x: 6.10.7 and below, ClearPass Policy Manager 6.9.x: 6.9.12 and below2023-01-05
CVE-2022-43536 [HIGH] CWE-78 CVE-2022-43536: Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenti
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager ver
cvelistv5nvd
CVE-2022-43533HIGHCVSS 7.8vClearPass Policy Manager 6.10.x: 6.10.7 and below, ClearPass Policy Manager 6.9.x: 6.9.12 and below2023-01-05
CVE-2022-43533 [HIGH] CWE-269 CVE-2022-43533: A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instanc
A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with root level privileges on the macOS instance in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below an
cvelistv5nvd
CVE-2022-43534HIGHCVSS 7.8vClearPass Policy Manager 6.10.x: 6.10.7 and below, ClearPass Policy Manager 6.9.x: 6.9.12 and below2023-01-05
CVE-2022-43534 [HIGH] CWE-269 CVE-2022-43534: A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with root level privileges on the Linux instance in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below an
cvelistv5nvd
CVE-2022-43535HIGHCVSS 7.8vClearPass Policy Manager 6.10.x: 6.10.7 and below, ClearPass Policy Manager 6.9.x: 6.9.12 and below2023-01-05
CVE-2022-43535 [HIGH] CWE-269 CVE-2022-43535: A vulnerability in the ClearPass OnGuard Windows agent could allow malicious users on a Windows inst
A vulnerability in the ClearPass OnGuard Windows agent could allow malicious users on a Windows instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with NT AUTHORITY\SYSTEM level privileges on the Windows instance in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x
cvelistv5nvd
CVE-2022-43538HIGHCVSS 7.2vClearPass Policy Manager 6.10.x: 6.10.7 and below, ClearPass Policy Manager 6.9.x: 6.9.12 and below2023-01-05
CVE-2022-43538 [HIGH] CWE-78 CVE-2022-43538: Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenti
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager ver
cvelistv5nvd
CVE-2022-43531HIGHCVSS 8.8vClearPass Policy Manager 6.10.x: 6.10.7 and below, ClearPass Policy Manager 6.9.x: 6.9.12 and below2023-01-05
CVE-2022-43531 [HIGH] CWE-89 CVE-2022-43531: Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an au
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to comple
cvelistv5nvd
CVE-2022-43530HIGHCVSS 8.8vClearPass Policy Manager 6.10.x: 6.10.7 and below, ClearPass Policy Manager 6.9.x: 6.9.12 and below2023-01-05
CVE-2022-43530 [HIGH] CWE-89 CVE-2022-43530: Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an aut
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to comple
cvelistv5nvd
CVE-2022-43537HIGHCVSS 7.2vClearPass Policy Manager 6.10.x: 6.10.7 and below, ClearPass Policy Manager 6.9.x: 6.9.12 and below2023-01-05
CVE-2022-43537 [HIGH] CWE-78 CVE-2022-43537: Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenti
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager ver
cvelistv5nvd
CVE-2022-43532MEDIUMCVSS 4.8vClearPass Policy Manager 6.10.x: 6.10.7 and below, ClearPass Policy Manager 6.9.x: 6.9.12 and below2023-01-05
CVE-2022-43532 [MEDIUM] CWE-79 CVE-2022-43532: A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an au
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affec
cvelistv5nvd
CVE-2022-43540MEDIUMCVSS 5.5vClearPass Policy Manager 6.10.x: 6.10.7 and below, ClearPass Policy Manager 6.9.x: 6.9.12 and below2023-01-05
CVE-2022-43540 [MEDIUM] CWE-200 CVE-2022-43540: A vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local m
A vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information that is of a sensitive nature in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7
cvelistv5nvd
CVE-2022-43539MEDIUMCVSS 4.5vClearPass Policy Manager 6.10.x: 6.10.7 and below, ClearPass Policy Manager 6.9.x: 6.9.12 and below2023-01-05
CVE-2022-43539 [MEDIUM] CWE-200 CVE-2022-43539: A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an att
A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privileged network position to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information that allows for unauthorized actions as a privileged user on the ClearPass Policy Manager cluster i
cvelistv5nvd
CVE-2022-37882HIGHCVSS 7.2v6.10.x: 6.10.6 and belowv6.9.x: 6.9.11 and below2022-09-20
CVE-2022-37882 [HIGH] CVE-2022-37882: Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the under
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system comp
cvelistv5
CVE-2022-37883HIGHCVSS 7.2v6.10.x: 6.10.6 and belowv6.9.x: 6.9.11 and below2022-09-20
CVE-2022-37883 [HIGH] CVE-2022-37883: Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the under
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system comp
cvelistv5
CVE-2022-23696HIGHCVSS 8.8vClearPass Policy Manager 6.10.x: 6.10.6 and belowvClearPass Policy Manager 6.9.x: 6.9.11 and below2022-09-20
CVE-2022-23696 [HIGH] CVE-2022-23696: Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injectio
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underl
cvelistv5
CVE-2022-37877HIGHCVSS 7.8v6.10.x: 6.10.6 and belowv6.9.x: 6.9.11 and below2022-09-20
CVE-2022-37877 [HIGH] CVE-2022-37877: A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their user privileges
A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with root level privileges on the macOS instance in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6
cvelistv5
CVE-2022-37879HIGHCVSS 7.2v6.10.x: 6.10.6 and belowv6.9.x: 6.9.11 and below2022-09-20
CVE-2022-37879 [HIGH] CVE-2022-37879: Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the under
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system comp
cvelistv5
CVE-2022-37880HIGHCVSS 7.2v6.10.x: 6.10.6 and belowv6.9.x: 6.9.11 and below2022-09-20
CVE-2022-37880 [HIGH] CVE-2022-37880: Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the under
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system comp
cvelistv5
CVE-2022-37878HIGHCVSS 7.2v6.10.x: 6.10.6 and belowv6.9.x: 6.9.11 and below2022-09-20
CVE-2022-37878 [HIGH] CVE-2022-37878: Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the under
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system comp
cvelistv5