CVE-2017-9002 Vulnerability Details

  /     /     /  

CVE-2017-9002 Metadata Quick Info

CVE Published: 06/08/2018 | CVE Updated: 05/08/2024 | CVE Year: 2017
Source: hpe | Vendor: Hewlett Packard Enterprise | Product: Aruba ClearPass
Status : PUBLISHED

CVE-2017-9002 Description

All versions of Aruba ClearPass prior to 6.6.8 contain reflected cross-site scripting vulnerabilities. By exploiting this vulnerability, an attacker who can trick a logged-in ClearPass administrative user into clicking a link could obtain sensitive information, such as session cookies or passwords. The vulnerability requires that an administrative users click on the malicious link while currently logged into ClearPass in the same browser.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: reflected cross-site scripting
Source: Hewlett Packard Enterprise

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).