CVE-2014-8367: Arubanetworks Clearpass Policy Manager

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

SQL injection vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) 6.2.x, 6.3.x before 6.3.6, and 6.4.x before 6.4.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Affected products

  • Arubanetworks Clearpass Policy Manager: from 6.2.0, up to and including 6.2.6; from 6.3.0, before 6.3.6 (fixed in 6.3.6); from 6.4.0, before 6.4.2 (fixed in 6.4.2); version 6.2 only

Published 2014-11-25. Last modified 2026-06-17.