First published: Tue Feb 27 2024(Updated: )
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hewlett Packard ClearPass Policy Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-26299 is rated as a medium severity vulnerability due to its ability to allow stored cross-site scripting attacks.
To fix CVE-2024-26299, apply the security patches provided by Hewlett Packard for the ClearPass Policy Manager software.
CVE-2024-26299 affects users of the web-based management interface of Hewlett Packard ClearPass Policy Manager.
The potential impacts of CVE-2024-26299 include unauthorized execution of scripts, which can compromise the security of administrative functions in ClearPass Policy Manager.
Yes, CVE-2024-26299 is a remote vulnerability that requires an authenticated attacker to exploit it against an administrative user.