4
CVSSv2

CVE-2016-8526

Published: 06/08/2018 Updated: 16/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to access storage that exist on external systems. If an unprivileged user is permitted to control the contents of XML files, XXE can be used as an attack vector. Because the XML parser has access to the local filesystem and runs with the permissions of the web server, it can access any file that is readable by the web server and copy it to an external system of the attacker's choosing. This could include files that contain passwords, which could then lead to privilege escalation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hp airwave

Exploits

SEC Consult Vulnerability Lab Security Advisory < 20170301-0 > ======================================================================= title: XML External Entity Injection (XXE), Reflected Cross Site Scripting product: Aruba AirWave vulnerable version: <=823 fixed version: 8231 ...
Aruba AirWave versions 823 and below suffer from XXE injection and cross site scripting vulnerabilities ...