Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.
Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.
Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users.
Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.