8.1

CVE-2022-27778

Exploit
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Haxx ≫ Curl Version 7.83.0
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Netapp ≫ Oncommand Insight Version -
Netapp ≫ Snapcenter Version -
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ Bh500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Netapp ≫ Hci Compute Node Firmware Version -
   Netapp ≫ Hci Compute Node Version -
Oracle ≫ Mysql Server Version <= 5.7.38
Oracle ≫ Mysql Server Version >= 8.0.0 <= 8.0.29
Splunk ≫ Universal Forwarder Version >= 8.2.0 < 8.2.12
Splunk ≫ Universal Forwarder Version >= 9.0.0 < 9.0.6
Splunk ≫ Universal Forwarder Version 9.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.81% 0.891
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:N/I:P/A:P
CWE-706 Use of Incorrectly-Resolved Name or Reference

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

https://www.oracle.com/security-alerts/cpujul2022.html
Patch
Third Party Advisory
https://security.netapp.com/advisory/ntap-20220729-0004/
Third Party Advisory
https://hackerone.com/reports/1553598
Third Party Advisory
Exploit
https://security.netapp.com/advisory/ntap-20220609-0009/
Third Party Advisory