Aruba Networks Security Advisory – A user authentication vulnerability was discovered during standard bug reporting procedures in the Aruba Mobility Controller. This vulnerability only affects customers using TACACS authentication for Controller management users. Cross-site scripting vulnerabilities were discovered during standard bug reporting procedures in the Aruba Mobility Controller. Certain malformed inputs to the web UI allow the injection of cross-site scripting (XSS) components, leading to a potential compromise of client web session integrity.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/66419/aid-051408.asc
Source: https://packetstormsecurity.com/files/66419/Aruba-Networks-Security-Advisory-051408.html

