CVE Database
/

CVE-2016-8526

Back to search

CVE-2016-8526

Published: Aug 6, 2018

Modified: Aug 6, 2024

PUBLISHED

Description

Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to access storage that exist on external systems. If an unprivileged user is permitted to control the contents of XML files, XXE can be used as an attack vector. Because the XML parser has access to the local filesystem and runs with the permissions of the web server, it can access any file that is readable by the web server and copy it to an external system of the attacker's choosing. This could include files that contain passwords, which could then lead to privilege escalation.

VendorProductVersions

Hewlett Packard Enterprise

Aruba AirWave

affected
all versions up to, but not including, 8.2.3.1

References

96495
vdb-entry
x_refsource_BID
41482
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now