In Aruba ClearPass, disabled API admins can still perform read/write operations. In certain circumstances, API admins in ClearPass which have been disabled may still be able to perform read/write operations on parts of the XML API. This can lead to unauthorized access to the API and complete compromise of the ClearPass instance if an attacker knows of the existence of these accounts.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: hpe
Published: 2018-12-07T21:00:00
Updated: 2024-08-05T06:17:17.407Z
Reserved: 2018-02-15T00:00:00
Link: CVE-2018-7063
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-12-07T21:29:01.123
Modified: 2024-11-21T04:11:35.280
Link: CVE-2018-7063
Redhat
No data.