cbcvebase.

Netapp Oncommand System Manager vulnerabilities

27 known vulnerabilities affecting netapp/oncommand_system_manager.

Total CVEs
27
CISA KEV
2
actively exploited
Public exploits
7
Exploited in wild
4
Severity breakdown
CRITICAL4HIGH10MEDIUM13

Vulnerabilities

Page 2 of 2
CVE-2019-10247P4MEDIUMCVSS 5.3≥ 3.0, ≤ 3.1.32019-04-22
CVE-2019-10247 [MEDIUM] CWE-213 CVE-2019-10247: In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the ser In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on je
nvd
CVE-2019-10246P4MEDIUMCVSS 5.3≥ 3.0, ≤ 3.1.32019-04-22
CVE-2019-10246 [MEDIUM] CWE-213 CVE-2019-10246: In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource dire
nvd
CVE-2020-1935P4MEDIUMCVSS 4.8≥ 3.0.0, ≤ 3.1.32020-02-24
CVE-2020-1935 [MEDIUM] CWE-444 CVE-2020-1935: In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing cod In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encodi
nvd
CVE-2019-17569P4MEDIUMCVSS 4.8≥ 3.0.0, ≤ 3.1.32020-02-24
CVE-2019-17569 [MEDIUM] CWE-444 CVE-2019-17569: The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 int The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the inval
nvd
CVE-2016-5047P4MEDIUMCVSS 6.5v8.3v8.3.1+1 more2016-09-01
CVE-2016-5047 [MEDIUM] CVE-2016-5047: NetApp OnCommand System Manager 8.3.x before 8.3.2P5 allows remote authenticated users to cause a de NetApp OnCommand System Manager 8.3.x before 8.3.2P5 allows remote authenticated users to cause a denial of service via unspecified vectors.
nvd
CVE-2019-17276P4MEDIUMCVSS 5.4v9.3v9.42020-03-24
CVE-2019-17276 [MEDIUM] CWE-79 CVE-2019-17276: OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cr OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting vulnerability that could allow an authenticated attacker to inject arbitrary scripts into the SNMP Community Names label field.
nvd
CVE-2020-8587P4MEDIUMCVSS 5.5≥ 9.0, < 9.3v9.3+1 more2021-02-08
CVE-2020-8587 [MEDIUM] CVE-2020-8587: OnCommand System Manager 9.x versions prior to 9.3P20 and 9.4 prior to 9.4P3 are susceptible to a vu OnCommand System Manager 9.x versions prior to 9.3P20 and 9.4 prior to 9.4P3 are susceptible to a vulnerability that could allow HTTP clients to cache sensitive responses making them accessible to an attacker who has access to the system where the client runs.
nvd
Netapp Oncommand System Manager vulnerabilities | cvebase