漏洞标题
N/A
漏洞描述信息
Aruba EdgeConnect Enterprise Orchestrator的Web管理界面存在多个漏洞,可能导致未经身份验证的远程攻击者对Aruba EdgeConnect Enterprise Orchestrator实例进行SQL注入攻击。攻击者可以利用这些漏洞获取并修改底层数据库中的敏感信息,从而可能导致Aruba EdgeConnect Enterprise Orchestrator主机完全被攻击者控制:Aruba EdgeConnect Enterprise Orchestrator(在本地)、Aruba EdgeConnect Enterprise Orchestrator-as-a-Service、Aruba EdgeConnect Enterprise Orchestrator-SP和Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators版本9.2.1.40179及其以下、9.1.4.40436及其以下、9.0.7.40110及其以下、8.10.23.40015及其以下-不特别提及的任何 Orchestrator 版本。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the Aruba EdgeConnect Enterprise Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the Aruba EdgeConnect Enterprise Orchestrator host in Aruba EdgeConnect Enterprise Orchestration Software version(s): Aruba EdgeConnect Enterprise Orchestrator (on-premises), Aruba EdgeConnect Enterprise Orchestrator-as-a-Service, Aruba EdgeConnect Enterprise Orchestrator-SP and Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators - Orchestrator 9.2.1.40179 and below, - Orchestrator 9.1.4.40436 and below, - Orchestrator 9.0.7.40110 and below, - Orchestrator 8.10.23.40015 and below, - Any older branches of Orchestrator not specifically mentioned.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
Aruba Networks EdgeConnect Enterprise Orchestrator SQL注入漏洞
漏洞描述信息
Aruba Networks EdgeConnect Enterprise Orchestrator是美国Aruba Networks公司的一种集中式 SD-WAN 管理解决方案。为企业用户提供优化、管理、自动化和实时可见性和监控特性服务。 Aruba Networks EdgeConnect Enterprise Orchestrator存在安全漏洞。攻击者利用该漏洞执行SQL注入攻击,从而获取和修改基础数据库中的敏感信息。以下产品及版本受到影响: Aruba EdgeConnect Enterpris
CVSS信息
N/A
漏洞类别
SQL注入