First published: Thu Apr 29 2021(Updated: )
A remote cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Clearpass | >=6.7.0<6.7.14 | |
Arubanetworks Clearpass | >=6.8.0<6.8.9 | |
Arubanetworks Clearpass | >=6.9.0<6.9.5 | |
Arubanetworks Clearpass | =6.7.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-29139 is medium with a CVSS score of 4.8.
Aruba ClearPass Policy Manager versions prior to 6.9.5, 6.8.9, 6.7.14-HF1 are affected by CVE-2021-29139.
Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability. It is recommended to update to the latest patched version.
The CVE ID of this vulnerability is CVE-2021-29139.
The CWE ID of CVE-2021-29139 is CWE-79 (Cross-Site Scripting).