Vulnerability Description
A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote attacker to conduct SQL injection attacks against the AirWave instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arubanetworks | Airwave | < 8.2.12.0 |
Related Weaknesses (CWE)
References
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-005.txtVendor Advisory
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-005.txtVendor Advisory
FAQ
What is CVE-2021-26966?
CVE-2021-26966 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an auth...
How severe is CVE-2021-26966?
CVE-2021-26966 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26966?
Check the references section above for vendor advisories and patch information. Affected products include: Arubanetworks Airwave.