Netapp Snap Creator Framework vulnerabilities

4 known vulnerabilities affecting netapp/snap_creator_framework.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2016-5710MEDIUMCVSS 4.6fixed in 4.3.12020-02-11
CVE-2016-5710 [MEDIUM] CWE-1021 CVE-2016-5710: NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
nvd
CVE-2017-7657CRITICALCVSS 9.8fixed in 4.3.32018-06-26
CVE-2017-7657 [CRITICAL] CWE-444 CVE-2017-7657: In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default confi In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body
nvd
CVE-2016-5372MEDIUMCVSS 6.3≤ 4.3.02017-02-07
CVE-2016-5372 [MEDIUM] CWE-352 CVE-2016-5372: Cross-site request forgery (CSRF) vulnerability in NetApp Snap Creator Framework before 4.3.0P1 allo Cross-site request forgery (CSRF) vulnerability in NetApp Snap Creator Framework before 4.3.0P1 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
nvd
CVE-2016-7172HIGHCVSS 7.5≤ 4.3.02016-12-21
CVE-2016-7172 [HIGH] CWE-200 CVE-2016-7172: NetApp Snap Creator Framework before 4.3.1 discloses sensitive information which could be viewed by NetApp Snap Creator Framework before 4.3.1 discloses sensitive information which could be viewed by an unauthorized user.
nvd