First published: Thu May 28 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aruba ClearPass Policy Manager | <=6.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4132 is classified as a medium-severity vulnerability due to its potential for exploitation by remote administrators.
To mitigate CVE-2015-4132, upgrade to Aruba Networks ClearPass Policy Manager version 6.4.5 or later.
CVE-2015-4132 allows for cross-site scripting attacks, enabling attackers to inject arbitrary web scripts or HTML.
CVE-2015-4132 affects users of Aruba Networks ClearPass Policy Manager versions prior to 6.4.5.
CVE-2015-4132 is primarily a server-side vulnerability affecting the application’s handling of user input.