First published: Tue Feb 04 2025(Updated: )
A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager exposes directories containing sensitive information. If exploited successfully, this vulnerability allows an authenticated remote attacker with high privileges to access and retrieve sensitive data, potentially compromising the integrity and security of the entire system.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Aruba ClearPass Policy Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23059 is rated as a high severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2025-23059, ensure that you apply the latest security patches provided by HPE for the Aruba Networking ClearPass Policy Manager.
Users of HPE Aruba Networking ClearPass Policy Manager with high privileges may be affected by CVE-2025-23059.
Yes, CVE-2025-23059 can be exploited remotely by an authenticated attacker with high privileges.
CVE-2025-23059 exposes directories containing sensitive information within the web-based management interface.