#VU50920 XML External Entity injection in AirWave Management Platform - CVE-2021-26969
Published: February 24, 2021 / Updated: June 1, 2021
AirWave Management Platform
Aruba Networks
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input in the web-based management interface. A remote administrator can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system, leading to denial of service (DoS) attack.