Known vulnerabilities in Aruba Networking ClearPass Policy Manager

Vendor: HPE
Software CPE: cpe:2.3:a:hpe:aruba_networking_clearpass_policy_manager:*:*:*:*:*:*:*:*
Total vulnerabilities: 16
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Aruba Networking ClearPass Policy Manager Aruba Networking ClearPass Policy Manager is affected by 16 known vulnerabilities: 1 high, 1 medium, 14 low Critical High Medium Low

Vulnerabilities (16)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU115772 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-37122
CWE-79 Low
No
No
6.11.12 Hotfix Patch, 6.12.6 18.09.2025 SB2025091846
#VU103673 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-25039
CWE-78 Low
No
No
6.11.10, 6.12.4 06.02.2025 SB2025020622
SB2025022013
#VU103672 - Exposure of sensitive information to an unauthorized actor
CVE-2025-23060
CWE-200 Low
No
No
6.11.10, 6.12.4 06.02.2025 SB2025020622
SB2025022013
#VU103671 - Exposure of sensitive information to an unauthorized actor
CVE-2025-23059
CWE-200 Low
No
No
6.11.10, 6.12.4 06.02.2025 SB2025020622
SB2025022013
#VU103662 - Improper Access Control
CVE-2025-23058
CWE-284 Medium
No
No
6.11.10, 6.12.4 06.02.2025 SB2025020622
SB2025022013
#VU95605 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2024-7348
CWE-367 Low
No
No
6.11.10, 6.12.4 08.08.2024 SB2024080866
SB2024080954
SB2024080955
and 63 more
#VU89892 - Exposure of sensitive information to an unauthorized actor
CVE-2024-26302
CWE-200 Low
No
No
6.9.13 Hotfix Patch 7 Q1 2024, 6.10.8 Hotfix Patch 8 Q1 2024, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89891 - Exposure of sensitive information to an unauthorized actor
CVE-2024-26301
CWE-200 Low
No
No
6.9.13 Hotfix Patch 7 Q1 2024, 6.10.8 Hotfix Patch 8 Q1 2024, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89890 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-26300
CWE-79 Low
No
No
6.9.13 Hotfix Patch 7 Q1 2024, 6.10.8 Hotfix Patch 8 Q1 2024, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89889 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-26299
CWE-79 Low
No
No
6.9.13 Hotfix Patch 7 Q1 2024, 6.10.8 Hotfix Patch 8 Q1 2024, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89884 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-26294
CWE-78 Low
No
No
6.9.13 Hotfix Patch 7 Q1 2024, 6.10.8 Hotfix Patch 8 Q1 2024, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89885 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-26295
CWE-78 Low
No
No
6.9.13 Hotfix Patch 7 Q1 2024, 6.10.8 Hotfix Patch 8 Q1 2024, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89886 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-26296
CWE-78 Low
No
No
6.9.13 Hotfix Patch 7 Q1 2024, 6.10.8 Hotfix Patch 8 Q1 2024, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89887 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-26297
CWE-78 Low
No
No
6.9.13 Hotfix Patch 7 Q1 2024, 6.10.8 Hotfix Patch 8 Q1 2024, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89888 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-26298
CWE-78 Low
No
No
6.9.13 Hotfix Patch 7 Q1 2024, 6.10.8 Hotfix Patch 8 Q1 2024, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU83960 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-50164
CWE-22 High
Available
Exploited
6.9.13 Hotfix Patch 7 Q1 2024, 6.10.8 Hotfix Patch 8 Q1 2024, 6.11.7, 6.12.1 07.12.2023 SB2023120703
SB2023121830
SB2024011029
and 7 more