Netapp

Oncommand System Manager

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.4%
  • Veröffentlicht 20.04.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:20:56

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the n...

  • EPSS 11.35%
  • Veröffentlicht 26.06.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:32:23

In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a...

  • EPSS 7.64%
  • Veröffentlicht 26.06.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:32:23

In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow...

  • EPSS 0.43%
  • Veröffentlicht 22.06.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:45:23

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatche...

  • EPSS 0.69%
  • Veröffentlicht 03.07.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup.

  • EPSS 0.52%
  • Veröffentlicht 07.02.2017 17:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users to execute arbitrary API calls via unspecified vectors.

  • EPSS 0.68%
  • Veröffentlicht 01.09.2016 10:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

NetApp OnCommand System Manager 8.3.x before 8.3.2P5 allows remote authenticated users to cause a denial of service via unspecified vectors.