Skip to main content

Vendor/product archive

netapp / oncommand_api_services CVEs

Beta · best-effort

17 CVEs tagged to netapp / oncommand_api_services8 Critical, 6 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2021-20190

Published Jan 19, 2021

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is…

CVSS 8.1 · High
evidence mentions
6
Buzz score
35.5

CVE-2020-8840

Published Feb 10, 2020

FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.

CVSS 9.8 · Critical

CVE-2017-8919

Published Jul 25, 2017

NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API, which allows remote authenticated users to obtain sensiti…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1