CVE-2014-4013: SQL Injection
SQL injection vulnerability in the Policy Manager in Aruba Networks ClearPass 5.x, 6.0.x, 6.1.x through 6.1.4.61696, 6.2.x through 6.2.6.62196, and 6.3.x before 6.3.4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4013?
CVE-2014-4013 is classified as a critical SQL injection vulnerability that can lead to unauthorized access to database information.
How do I fix CVE-2014-4013?
To fix CVE-2014-4013, users should upgrade to Aruba Networks ClearPass version 6.3.4 or later.
Who is affected by CVE-2014-4013?
CVE-2014-4013 affects Aruba Networks ClearPass versions 5.x, 6.0.x, 6.1.x, 6.2.x, and all versions prior to 6.3.4.
What kind of attack can be executed using CVE-2014-4013?
CVE-2014-4013 allows remote authenticated users to execute arbitrary SQL commands on the affected applications.
Is CVE-2014-4013 being actively exploited?
While there's no public confirmation of active exploitation, SQL injection vulnerabilities like CVE-2014-4013 are commonly targeted and should be addressed promptly.