A remote authenticated authenticated xml external entity (xxe) vulnerability exists in Aruba AirWave Management Platform version(s): before 8.2.12.0. Due to improper restrictions on XML entities a vulnerability exists in the web-based management interface of AirWave. A successful exploit could allow an authenticated malicious user to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
arubanetworks airwave |