CVE-2021-26686

MEDIUM

Aruba ClearPass Policy Manager < 6.7.14 - Authenticated SQL Injection

Title source: llm
STIX 2.1

Description

A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface API of ClearPass could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying database.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0020
EPSS Percentile 41.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-89
Status published
Products (1)
arubanetworks/clearpass_policy_manager < 6.7.14
Published Feb 23, 2021
Tracked Since Feb 18, 2026