Vulnerability index

Browse CVEs

192 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hci H610s Firmware MEDIUM 6.5
CVE-2020-8573

The NetApp HCI H610C, H615C and H610S Baseboard Management Controllers (BMC) are shipped with a documented default account and password that should b…

Mitigation only
Fix from $1,600 2020-06-29
Active Iq Unified Manager HIGH 8.1
CVE-2020-14195

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jn…

Fix: 2.9.10.5+
Fix from $1,950 2020-06-16
Active Iq Unified Manager HIGH 8.1
CVE-2020-14060EPSS 9%

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.…

Fix: 2.9.10.5+
Fix from $1,950 2020-06-14
Active Iq Unified Manager HIGH 8.1
CVE-2020-14061

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueC…

Fix: 2.9.10.5+
Fix from $1,950 2020-06-14
Active Iq Unified Manager HIGH 8.1
CVE-2020-14062EPSS 8%

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xal…

Fix: 2.9.10.5+
Fix from $1,950 2020-06-14
Element Healthtools HIGH 7.5
CVE-2020-8572

Element OS prior to version 12.0 and Element HealthTools prior to version 2020.04.01.04 are susceptible to a vulnerability which when successfully ex…

Fix: 12.0 / 2020.04.01.04+
Fix from $1,950 2020-05-21
Fas26x0 Firmware HIGH 7.5
CVE-2019-5500

Certain versions of the NetApp Service Processor and Baseboard Management Controller firmware allow a remote unauthenticated attacker to cause a Deni…

No fix yet
Fix from $1,950 2020-05-11
Oncommand System Manager MEDIUM 5.4
CVE-2019-17276

OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting vulnerability that could allow…

Mitigation only
Fix from $1,600 2020-03-24
Storagegrid HIGH 7.5
CVE-2020-8571

StorageGRID (formerly StorageGRID Webscale) versions 10.0.0 through 11.3 prior to 11.2.0.8 and 11.3.0.4 are susceptible to a vulnerability which allo…

Fix: 11.2.0.8 / 11.3.0.4+
Fix from $1,950 2020-03-13
Active Iq Unified Manager CRITICAL 9.8
CVE-2020-9547EPSS 18%

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engi…

Fix: 2.7.9.7 / 2.8.11.6+
Fix from $2,300 2020-03-02
Active Iq Unified Manager CRITICAL 9.8
CVE-2020-9548EPSS 18%

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.An…

Fix: 2.7.9.7 / 2.8.11.6+
Fix from $2,300 2020-03-02
Active Iq Unified Manager CRITICAL 9.8
CVE-2020-9546

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shad…

Fix: 2.7.9.7 / 2.8.11.6+
Fix from $2,300 2020-03-02
Oncommand Cloud Manager CRITICAL 9.8
CVE-2019-17275

OnCommand Cloud Manager versions prior to 3.8.0 are susceptible to arbitrary code execution by remote attackers.

Fix: 3.8.0+
Fix from $2,300 2020-02-26
Fabric Attached Storage 8700 Firmware HIGH 7.8
CVE-2019-17274

NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account en…

Fix: after 13.1
Fix from $1,950 2020-02-26
Oncommand System Manager HIGH 7.2
CVE-2013-3322

NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to inject arbitrary commands in the Halt/Reboot interface.

Fix: after 2.1
Fix from $1,950 2020-01-31
E Series Santricity Os Controller MEDIUM 6.5
CVE-2019-17273

E-Series SANtricity OS Controller Software version 11.60.0 is susceptible to a vulnerability which allows an attacker to cause a Denial of Service (D…

Fix: after 11.60.0
Fix from $1,600 2020-01-30
Oncommand System Manager HIGH 7.5
CVE-2013-3321

NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnos…

Fix: after 2.1
Fix from $1,950 2020-01-29
Oncommand System Manager MEDIUM 6.1
CVE-2013-3320

Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML…

Fix: 2.2+
Fix from $1,600 2020-01-29
Ontap Select Deploy Administration Utility CRITICAL 9.8
CVE-2019-5509

ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully e…

Fix: after 2.12.2
Fix from $2,300 2019-11-21
Ontap Select Deploy Administration Utility HIGH 7.2
CVE-2019-17272

All versions of ONTAP Select Deploy administration utility are susceptible to a vulnerability which when successfully exploited could allow an admini…

Mitigation only
Fix from $1,950 2019-11-21
Clustered Data Ontap HIGH 7.5
CVE-2019-5508

Clustered Data ONTAP versions 9.2 through 9.4 are susceptible to a vulnerability which allows an attacker to use l2ping to cause a Denial of Service …

Fix: after 9.4
Fix from $1,950 2019-10-25
Clustered Data Ontap MEDIUM 5.9
CVE-2019-5506

Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonatio…

Fix: after 9.6
Fix from $1,600 2019-10-09
Snapmanager MEDIUM 5.5
CVE-2019-5507

SnapManager for Oracle prior to version 3.4.2P1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sens…

Fix: 3.4.2+
Fix from $1,600 2019-10-09
Active Iq Unified Manager CRITICAL 9.8
CVE-2019-17267

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactio…

Fix: 2.8.11.5 / 2.9.10+
Fix from $2,300 2019-10-07
Ontap Select Deploy Administration Utility CRITICAL 9.8
CVE-2019-5504

ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote atta…

Patch available
Fix from $2,300 2019-09-24
Ontap Select Deploy Administration Utility CRITICAL 9.8
CVE-2019-5505

ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.

Fix: after 2.12.1
Fix from $2,300 2019-09-24
Oncommand Workflow Automation MEDIUM 5.3
CVE-2019-5503

OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers configured which could allow an attacker to obtain …

Mitigation only
Fix from $1,600 2019-09-10
Oncommand Insight MEDIUM 6.5
CVE-2019-5498

OnCommand Insight versions through 7.3.6 may disclose sensitive account information to an authenticated user.

Fix: after 7.3.6
Fix from $1,600 2019-08-09
Data Ontap CRITICAL 9.1
CVE-2019-5502

SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 has weak cryptography which when exploited could lead to information disclosure or ad…

Fix: 8.2.5+
Fix from $2,300 2019-08-05
Data Ontap HIGH 7.5
CVE-2019-5493

Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 are susceptible to a vulnerability which discloses information to an unauthenticated attacke…

Fix: 8.2.5+
Fix from $1,950 2019-08-02