CVE-2025-23059: Sensitive Information Disclosure in HPE Aruba Networking ClearPass Policy Manager
A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager exposes directories containing sensitive information. If exploited successfully, this vulnerability allows an authenticated remote attacker with high privileges to access and retrieve sensitive data, potentially compromising the integrity and security of the entire system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23059?
CVE-2025-23059 is rated as a high severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2025-23059?
To fix CVE-2025-23059, ensure that you apply the latest security patches provided by HPE for the Aruba Networking ClearPass Policy Manager.
Who is affected by CVE-2025-23059?
Users of HPE Aruba Networking ClearPass Policy Manager with high privileges may be affected by CVE-2025-23059.
Can CVE-2025-23059 be exploited remotely?
Yes, CVE-2025-23059 can be exploited remotely by an authenticated attacker with high privileges.
What type of information is exposed by CVE-2025-23059?
CVE-2025-23059 exposes directories containing sensitive information within the web-based management interface.