CVE-2021-26685: SQL Injection
A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface API of ClearPass could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26685?
CVE-2021-26685 has a medium severity rating due to the potential for SQL injection attacks by authenticated users.
How do I fix CVE-2021-26685?
To fix CVE-2021-26685, upgrade Aruba ClearPass Policy Manager to versions 6.9.5, 6.8.8-HF1, or 6.7.14-HF1 or later.
Who is affected by CVE-2021-26685?
CVE-2021-26685 affects users of Aruba ClearPass Policy Manager versions prior to 6.9.5, 6.8.8-HF1, and 6.7.14-HF1.
What systems are vulnerable to CVE-2021-26685?
Systems running Aruba ClearPass Policy Manager versions older than 6.9.5, 6.8.8-HF1, or 6.7.14-HF1 are vulnerable to CVE-2021-26685.
Can CVE-2021-26685 be exploited remotely?
Yes, CVE-2021-26685 can be exploited remotely by authenticated attackers through the web-based management interface API.