CVE-2014-8367: SQL Injection
SQL injection vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) 6.2.x, 6.3.x before 6.3.6, and 6.4.x before 6.4.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8367?
CVE-2014-8367 is rated as a high severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2014-8367?
To remediate CVE-2014-8367, update to Aruba ClearPass Policy Manager version 6.3.6 or later, or 6.4.2 or later.
What products are affected by CVE-2014-8367?
CVE-2014-8367 affects Aruba Networks ClearPass Policy Manager versions 6.2.x, 6.3.x prior to 6.3.6, and 6.4.x prior to 6.4.2.
Can CVE-2014-8367 be exploited remotely?
Yes, CVE-2014-8367 allows remote attackers to execute arbitrary SQL commands, making it a critical remote exploitation vulnerability.
What types of attacks can CVE-2014-8367 enable?
CVE-2014-8367 can enable attackers to manipulate database queries, potentially leading to data leakage or unauthorized access.