CVE-2017-9002
Last modified
CVE-2017-9002 is a vulnerability of currently unknown severity. All versions of Aruba ClearPass prior to 6.6.8 contain reflected cross-site scripting vulnerabilities. By exploiting this vulnerability, an attacker who can trick a logged-in ClearPass administrative user into clicking a link could obtain sensitive information, such as session cookies or passwords. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
All versions of Aruba ClearPass prior to 6.6.8 contain reflected cross-site scripting vulnerabilities. By exploiting this vulnerability, an attacker who can trick a logged-in ClearPass administrative user into clicking a link could obtain sensitive information, such as session cookies or passwords. The vulnerability requires that an administrative users click on the malicious link while currently logged into ClearPass in the same browser.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Aruba Clearpass Policy Manager | < 6.6.8 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-9002?
How severe is CVE-2017-9002?
How do I fix CVE-2017-9002?
Are you affected by CVE-2017-9002?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
