Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass patches: Struts vulnerability : CVE-2014-0094, CVE-2014-0050, CVE-2014-0112, CVE-2014-0113

This thread has been viewed 0 times
  • 1.  ClearPass patches: Struts vulnerability : CVE-2014-0094, CVE-2014-0050, CVE-2014-0112, CVE-2014-0113

    EMPLOYEE
    Posted May 13, 2014 10:49 PM
      |   view attached

    Hello all,

     

    ClearPass fixes for Struts security vulnerabilities are now available for versions 6.1.4, 6.2.6 and 6.3.0/6.3.1  The security vulnerabilities addressed in the patches are CVE-2014-0094, CVE-2014-0050, CVE-2014-0112, CVE-2014-0113.  Please review the attached README document for more information. 

     

    Individual patches are available for ClearPass 6.1.4 and 6.2.6. For versions 6.3.1, the fixes are part of the latest cumulative update 6.3.2. There is no separate security patch available for these versions. Users should install the cumulative update 6.3.2 to obtain these fixes. 

     

    For ClearPass 6.1.4 and 6.2.6 please review the README for prerequisites before installing the patch. Customers can install the patches from the Software Updates screen in ClearPass UI. The patches are also available for offline download and install from our support site (support.arubanetworks.com) at the following locations. 



  • 2.  RE: ClearPass patches: Struts vulnerability : CVE-2014-0094, CVE-2014-0050, CVE-2014-0112, CVE-2014-0113

    Posted Mar 19, 2017 01:23 PM

    Highly recommend you change all your passwords after you apply the patch, especially if your CPPM is internet facing.  Potiental for unauthenticated users getting all your CPPM password from etc/password file due this exploit.

     

    Aruba Partner Network Consultant

    **Aruba Wireless ACMP / ClearPass ACCP / CCNP Professional **
    If a reply addresses your issue, please click on the "Accept as Solution" and "Give Kudos"



  • 3.  RE: ClearPass patches: Struts vulnerability : CVE-2014-0094, CVE-2014-0050, CVE-2014-0112, CVE-2014-0113

    EMPLOYEE
    Posted Mar 19, 2017 10:09 PM

    These vulnerabilities were patched almost 3 years ago.