Known vulnerabilities in ClearPass Policy Manager - page 2

Software CPE: cpe:2.3:a:aruba_networks:clearpass_policy_manager:*:*:*:*:*:*:*:*
Website:
Total vulnerabilities: 59
Public exploits: 3
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ClearPass Policy Manager ClearPass Policy Manager is affected by 59 known vulnerabilities: 1 high, 16 medium, 42 low Critical High Medium Low

Vulnerabilities (59)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU82913 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-43510
CWE-78 Low
No
No
6.9.13 Hotfix Q4 2023, 6.10.8 Hotfix Q4 2023, 6.11.5 08.11.2023 SB2023110812
#VU82912 - Improper Access Control
CVE-2023-43509
CWE-284 Medium
No
No
6.9.13 Hotfix Q4 2023, 6.10.8 Hotfix Q4 2023, 6.11.5 08.11.2023 SB2023110812
#VU82911 - Incorrect Authorization
CVE-2023-43508
CWE-863 Medium
No
No
6.9.13 Hotfix Q4 2023, 6.10.8 Hotfix Q4 2023, 6.11.5 08.11.2023 SB2023110812
#VU82910 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-43507
CWE-89 Low
No
No
6.9.13 Hotfix Q4 2023, 6.10.8 Hotfix Q4 2023, 6.11.5 08.11.2023 SB2023110812
#VU73717 - Exposure of sensitive information to an unauthorized actor
CVE-2023-25596
CWE-200 Low
No
No
6.9.13 Hotfix 1, 6.10.8 Hotfix 1, 6.11.2 15.03.2023 SB2023031530
#VU73716 - Exposure of sensitive information to an unauthorized actor
CVE-2023-25595
CWE-200 Low
No
No
6.9.13 Hotfix 1, 6.10.8 Hotfix 1, 6.11.2 15.03.2023 SB2023031530
#VU73715 - Improper Authorization
CVE-2023-25594
CWE-285 Medium
No
No
6.9.13 Hotfix 1, 6.10.8 Hotfix 1, 6.11.2 15.03.2023 SB2023031530
#VU73714 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-25593
CWE-79 Low
No
No
6.9.13 Hotfix 1, 6.10.8 Hotfix 1, 6.11.2 15.03.2023 SB2023031530
#VU73713 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-25592
CWE-79 Low
No
No
6.9.13 Hotfix 1, 6.10.8 Hotfix 1, 6.11.2 15.03.2023 SB2023031530
#VU73712 - Exposure of sensitive information to an unauthorized actor
CVE-2023-25591
CWE-200 Medium
No
No
6.9.13 Hotfix 1, 6.10.8 Hotfix 1, 6.11.2 15.03.2023 SB2023031530
#VU73711 - Permissions, Privileges, and Access Controls
CVE-2023-25590
CWE-264 Low
No
No
6.9.13 Hotfix 1, 6.10.8 Hotfix 1, 6.11.2 15.03.2023 SB2023031530
#VU73710 - Improper Access Control
CVE-2023-25589
CWE-284 High
No
No
6.9.13 Hotfix 1, 6.10.8 Hotfix 1, 6.11.2 15.03.2023 SB2023031530
#VU70028 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-43537
CWE-78 Low
No
No
6.9.13, 6.10.8, 6.11.0 07.12.2022 SB2022120715
#VU70027 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-43538
CWE-78 Low
No
No
6.9.13, 6.10.8, 6.11.0 07.12.2022 SB2022120715
#VU70025 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-43536
CWE-78 Low
No
No
6.9.13, 6.10.8, 6.11.0 07.12.2022 SB2022120715
#VU70024 - Permissions, Privileges, and Access Controls
CVE-2022-43535
CWE-264 Low
No
No
6.9.13, 6.10.8, 6.11.0 07.12.2022 SB2022120715
#VU70020 - Permissions, Privileges, and Access Controls
CVE-2022-43534
CWE-264 Low
No
No
6.9.13, 6.10.8, 6.11.0 07.12.2022 SB2022120715
#VU70011 - Permissions, Privileges, and Access Controls
CVE-2022-43533
CWE-264 Low
No
No
6.9.13, 6.10.8, 6.11.0 07.12.2022 SB2022120715
#VU70004 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-43532
CWE-79 Low
No
No
6.9.13, 6.10.8, 6.11.0 07.12.2022 SB2022120715
#VU60007 - Improper input validation
CVE-2021-4034
CWE-20 Medium
Available
Exploited
6.8.9 Hotfix 2, 6.9.10, 6.10.4 26.01.2022 SB2022012601
SB2022012604
SB2022012605
and 51 more


Showing elements 21 - 40 out of 59