Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Snapcenter_server
(Netapp)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 23 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-03-04 | CVE-2018-5482 | NetApp SnapCenter Server prior to 4.1 does not set the secure flag for a sensitive cookie in an HTTPS session which can allow the transmission of the cookie in plain text over an unencrypted channel. | Snapcenter_server | 5.3 | ||
2017-11-16 | CVE-2017-15516 | NetApp SnapCenter Server versions 1.1 through 2.x are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability which could be used to cause an unintended authenticated action in the user interface. | Snapcenter_server | 8.8 | ||
2019-03-04 | CVE-2017-15515 | NetApp SnapCenter Server prior to 4.0 is susceptible to cross site scripting vulnerability that could allow a privileged user to inject arbitrary scripts into the custom secondary policy label field. | Snapcenter_server | 4.8 | ||
2017-02-07 | CVE-2016-1502 | NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and delete backups via unspecified vectors. | Snapcenter_server | 7.3 | ||
2017-08-07 | CVE-2015-7887 | NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups. | Snapcenter_server | 8.1 |