Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to access storage that exist on external systems. If an unprivileged user is permitted to control the contents of XML files, XXE can be used as an attack vector. Because the XML parser has access to the local filesystem and runs with the permissions of the web server, it can access any file that is readable by the web server and copy it to an external system of the attacker's choosing. This could include files that contain passwords, which could then lead to privilege escalation.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Aruba AirWave Management Platform 安全漏洞
Vulnerability Description
Aruba AirWave是美国安移通网络(Aruba)公司的一套适用于多供应商管理系统的网络管理软件。该软件具备端到端监控能力,可改善网络操作和管理RF安全性,以及提供实时监控、主动报警和历史数据报告等功能。AirWave Management Platform(AMP)是其中的一个无线网络管理软件。 Aruba AirWave 8.2.3.1之前的版本中的AMP存在XML外部实体注入漏洞。攻击者可利用该漏洞访问任意文件,并将其复制到外部的系统上。
CVSS Information
N/A
Vulnerability Type
N/A