vendor:
Aruba AirWave
by:
P. Morimoto (Office Bangkok)
6,1
CVSS
MEDIUM
XML External Entity Injection, Reflected Cross Site Scripting
611, 79
CWE
Product Name: Aruba AirWave
Affected Version From: <=8.2.3
Affected Version To: 8.2.3.1
Patch Exists: YES
Related CWE: CVE-2016-8526, CVE-2016-8527
CPE: a:aruba_networks:airwave
Metasploit:
N/A
Other Scripts:
N/A
Tags: cve2016,aruba,xss,edb,cve
CVSS Metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Nuclei Metadata: {'max-request': 1, 'vendor': 'hp', 'product': 'airwave'}
Platforms Tested: None
2016
XML External Entity Injection (XXE), Reflected Cross Site Scripting
Aruba Airwave before version 8.2.3.1 is vulnerable to reflected cross-site scripting.
Mitigation:
SEC Consult recommends not to use the product in a production environment until a thorough security review has been performed by security professionals and all identified issues have been resolved.