First published: Fri Mar 05 2021(Updated: )
A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management interface of AirWave could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the affected interface.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Airwave | <8.2.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-26968.
The severity rating of CVE-2021-26968 is 4.8, which is considered medium.
This vulnerability affects Aruba AirWave Management Platform versions prior to 8.2.12.0.
The impact of this vulnerability is that an authenticated remote attacker could conduct a stored cross-site scripting (XSS) attack.
Yes, upgrading to version 8.2.12.0 or later of Aruba AirWave Management Platform will fix this vulnerability.