NetApp / Cloud Manager
19 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-45105 | Apache Log4j2 does not always protect from infinite recursion in lookup evaluation | HIGH | 8.6 | Dec 18, 2021 |
| CVE-2021-42550 | RCE from attacker with configuration edit priviledges through JNDI lookup | MEDIUM | 6.6 | Dec 16, 2021 |
| CVE-2021-44228 KEV | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints | CRITICAL | 10.0 | Dec 10, 2021 |
| CVE-2021-27002 | NetApp Cloud Manager versions prior to 3.9.10 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to retrieve sensitive data… | HIGH | 7.5 | Oct 11, 2021 |
| CVE-2021-26999 | NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The logged information is available only to a… | MEDIUM | 4.3 | Aug 6, 2021 |
| CVE-2021-26998 | NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Customers with auto-upgrade enabled shoul… | MEDIUM | 4.3 | Aug 6, 2021 |
| CVE-2021-31807 | squid: incorrect memory management in HTTP Range header | MEDIUM | 6.5 | Jun 8, 2021 |
| CVE-2021-31808 | squid: integer overflow in HTTP Range header | MEDIUM | 6.5 | May 27, 2021 |
| CVE-2021-31806 | squid: improper input validation in HTTP Range header | MEDIUM | 6.5 | May 27, 2021 |
| CVE-2021-28651 | squid: denial of service in URN processing | HIGH | 7.5 | May 27, 2021 |
| CVE-2021-28165 | jetty: Resource exhaustion when receiving an invalid large TLS frame | HIGH | 7.5 | Apr 1, 2021 |
| CVE-2021-28164 | jetty: Ambiguous paths can access WEB-INF | MEDIUM | 5.3 | Apr 1, 2021 |
| CVE-2021-28163 | jetty: Symlink directory exposes webapp directory contents | LOW | 2.7 | Apr 1, 2021 |
| CVE-2021-26990 | Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files. | CRITICAL | 9.1 | Mar 19, 2021 |
| CVE-2021-26992 | Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability which could allow a remote attacker to cause a Denial of Service (DoS). | HIGH | 7.5 | Mar 19, 2021 |
| CVE-2021-26991 | Cloud Manager versions prior to 3.9.4 contain an insecure Cross-Origin Resource Sharing (CORS) policy which could allow a remote attacker to interact with Clou… | HIGH | 7.5 | Mar 19, 2021 |
| CVE-2020-25097 | squid: improper input validation may allow a trusted client to perform HTTP request smuggling | HIGH | 8.6 | Mar 19, 2021 |
| CVE-2021-23337 | Command Injection | HIGH | 7.2 | Feb 15, 2021 |
| CVE-2020-14058 | squid: DoS in TLS handshake | HIGH | 7.7 | Jun 30, 2020 |
Showing 1 to 19 of 19 CVEs