Known vulnerabilities in ClearPass Policy Manager 6.9.13 Cumulative Hotfix Patch 3
Vendor:
Aruba Networks
Software:
ClearPass Policy Manager
Version:
6.9.13 Cumulative Hotfix Patch 3
Software CPE:
cpe:2.3:a:aruba_networks:clearpass_policy_manager:*:*:*:*:*:*:*:*
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Vulnerabilities by Severity
6.12.4
6.11.8
6.11.6
6.12.0
6.12.3
6.11.10
6.12.2
6.11.9
6.9.13 Hotfix Patch 7
6.10.8 Hotfix Patch 8
6.11.7
6.12.1
6.9.13 Cumulative Hotfix Patch 3
6.10.8 Cumulative Hotfix Patch 5
6.11.4
4
6.11.3
6.9.13 Hotfix Q4 2023
6.10.8 Hotfix Q4 2023
6.11.5
6.8.9 Hotfix 2
6.9.13 Hotfix 1
6.10.8 Hotfix 1
6.11.2
6.11.1
6.10.5
6.10.4
6.10.3
6.10.2
6.10.1
6.10.0
6.9.10
6.9.9
6.9.8
6.9.7
6.9.6
6.9.5
6.9.4
6.9.3
6.9.2
6.9.1
6.9.0
6.11.0
6.9.13
6.10.8
6.9.12
6.10.7
6.9.11
6.10.6
-
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU82913 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2023-43510 |
CWE-78 | Low | 6.9.13 Hotfix Q4 2023, 6.10.8 Hotfix Q4 2023, 6.11.5 | 08.11.2023 |
SB2023110812 |
||
| #VU82912 - Improper Access Control CVE-2023-43509 |
CWE-284 | Medium | 6.9.13 Hotfix Q4 2023, 6.10.8 Hotfix Q4 2023, 6.11.5 | 08.11.2023 |
SB2023110812 |
||
| #VU82911 - Incorrect Authorization CVE-2023-43508 |
CWE-863 | Medium | 6.9.13 Hotfix Q4 2023, 6.10.8 Hotfix Q4 2023, 6.11.5 | 08.11.2023 |
SB2023110812 |
||
| #VU82910 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2023-43507 |
CWE-89 | Low | 6.9.13 Hotfix Q4 2023, 6.10.8 Hotfix Q4 2023, 6.11.5 | 08.11.2023 |
SB2023110812 |
||
| #VU82909 - Permissions, Privileges, and Access Controls CVE-2023-43506 |
CWE-264 | Low | 6.9.13 Hotfix Q4 2023, 6.10.8 Hotfix Q4 2023, 6.11.5 | 08.11.2023 |
SB2023110812 |