Skip to main content

Vendor/product archive

netapp / snapcenter_server CVEs

Beta · best-effort

22 CVEs tagged to netapp / snapcenter_server1 Critical, 5 High, 15 Medium, 1 Low, 0 Unrated.

CVE-2018-5482

Published Mar 4, 2019

NetApp SnapCenter Server prior to 4.1 does not set the secure flag for a sensitive cookie in an HTTPS session which can allow the transmission of the cookie in plain text over an…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15515

Published Mar 4, 2019

NetApp SnapCenter Server prior to 4.0 is susceptible to cross site scripting vulnerability that could allow a privileged user to inject arbitrary scripts into the custom secondary…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8014

Published May 16, 2018

The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCred…

CVSS 9.8 · Critical

CVE-2017-15519

Published Mar 6, 2018

Versions of SnapCenter 2.0 through 3.0.1 allow unauthenticated remote attackers to view and modify backup related data via the Plug-in for NAS File Services. All users are urged t…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15516

Published Nov 16, 2017

NetApp SnapCenter Server versions 1.1 through 2.x are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability which could be used to cause an unintended authenticated act…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1502

Published Feb 7, 2017

NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and delete backups via unspecified vectors.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1