Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:netapp:oncommand_system_manager:-:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2013-3322 |
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to inject arbitrary commands in the Halt/Reboot interface. Published: January 31, 2020; 9:15:10 AM -0500 |
V3.1: 7.2 HIGH V2.0: 9.0 HIGH |
CVE-2013-3321 |
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnostic" page using the SnapMirror log path parameter. Published: January 29, 2020; 5:15:11 PM -0500 |
V3.1: 7.5 HIGH V2.0: 6.0 MEDIUM |
CVE-2013-3320 |
Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML via the 'full-name' and 'comment' fields. Published: January 29, 2020; 5:15:11 PM -0500 |
V3.1: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2016-3063 |
Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users to execute arbitrary API calls via unspecified vectors. Published: February 07, 2017; 12:59:00 PM -0500 |
V3.0: 7.5 HIGH V2.0: 4.4 MEDIUM |