ZeroHour

CVE-2021-26966

CVSS 3.1
6.5 medium
EPSS
1%p64
Published
()
Modified
Description

A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote attacker to conduct SQL injection attacks against the AirWave instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database.

Vendors
arubanetworks
Products
airwave
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.