A remote authorization bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.
According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”
Name | Vendor | Start Version | End Version |
---|---|---|---|
Clearpass_policy_manager | Arubanetworks | * | 6.7.14 (including) |
Clearpass_policy_manager | Arubanetworks | 6.8.0 (including) | 6.8.9 (excluding) |
Clearpass_policy_manager | Arubanetworks | 6.9.0 (including) | 6.9.9 (including) |
Clearpass_policy_manager | Arubanetworks | 6.10.0 (including) | 6.10.4 (including) |
Clearpass_policy_manager | Arubanetworks | 6.8.9 (including) | 6.8.9 (including) |
Clearpass_policy_manager | Arubanetworks | 6.8.9-hotfix1 (including) | 6.8.9-hotfix1 (including) |
Clearpass_policy_manager | Arubanetworks | 6.8.9-hotfix2 (including) | 6.8.9-hotfix2 (including) |