NetApp / Oncommand System Manager
27 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-8587 | OnCommand System Manager 9.x versions prior to 9.3P20 and 9.4 prior to 9.4P3 are susceptible to a vulnerability that could allow HTTP clients to cache sensitiv… | MEDIUM | 5.5 | Feb 8, 2021 |
| CVE-2020-17527 | Apache Tomcat: Request header mix-up between HTTP/2 streams | HIGH | 7.5 | Dec 3, 2020 |
| CVE-2020-27218 | jetty: buffer not correctly recycled in Gzip Request inflation | MEDIUM | 4.8 | Nov 28, 2020 |
| CVE-2020-13935 | tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoS | HIGH | 7.5 | Jul 14, 2020 |
| CVE-2020-13934 | tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS | HIGH | 7.5 | Jul 14, 2020 |
| CVE-2020-11996 | tomcat: specially crafted sequence of HTTP/2 requests can lead to DoS | HIGH | 7.5 | Jun 26, 2020 |
| CVE-2020-7656 | jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces | MEDIUM | 5.3 | May 19, 2020 |
| CVE-2020-11023 KEV | Potential XSS vulnerability in jQuery | MEDIUM | 6.9 | Apr 29, 2020 |
| CVE-2020-11022 | jQuery has a potential XSS vulnerability | MEDIUM | 6.9 | Apr 29, 2020 |
| CVE-2019-17276 | OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting vulnerability that could allow an authen… | MEDIUM | 5.4 | Mar 24, 2020 |
| CVE-2020-1938 KEV | tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability | CRITICAL | 9.8 | Feb 24, 2020 |
| CVE-2020-1935 | tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling | MEDIUM | 4.8 | Feb 24, 2020 |
| CVE-2019-17569 | tomcat: Regression in handling of Transfer-Encoding header allows for HTTP request smuggling | MEDIUM | 4.8 | Feb 24, 2020 |
| CVE-2013-3322 | NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to inject arbitrary commands in the Halt/Reboot interface. | HIGH | 7.2 | Jan 31, 2020 |
| CVE-2013-3321 | NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnostic" page… | HIGH | 7.5 | Jan 29, 2020 |
| CVE-2013-3320 | Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML via the '… | MEDIUM | 6.1 | Jan 29, 2020 |
| CVE-2019-12418 | tomcat: local privilege escalation | HIGH | 7.4 | Dec 23, 2019 |
| CVE-2019-17571 | log4j: deserialization of untrusted data in SocketServer | CRITICAL | 9.8 | Dec 20, 2019 |
| CVE-2019-10247 | jetty: error path information disclosure | MEDIUM | 5.3 | Apr 22, 2019 |
| CVE-2019-10246 | jetty: Directory Listing on Windows reveals Resource Base path | MEDIUM | 5.3 | Apr 22, 2019 |
| CVE-2019-11358 | jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection | MEDIUM | 6.1 | Apr 19, 2019 |
| CVE-2017-7658 | jetty: Incorrect header handling | CRITICAL | 9.8 | Jun 26, 2018 |
| CVE-2017-7657 | jetty: HTTP request smuggling | CRITICAL | 9.8 | Jun 26, 2018 |
| CVE-2018-12538 | jetty: HttpSessions access/hijack in the FileSystem's storage for the FileSessionDataStore. | HIGH | 8.8 | Jun 22, 2018 |
| CVE-2016-5045 | NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup. | HIGH | 8.1 | Jul 3, 2017 |
Showing 1 to 25 of 27 CVEs