Vulnerability index

Browse CVEs

192 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2020-8573 The NetApp HCI H610C, H615C and H610S Baseboard Management Controllers (BMC) are shipped with a documented default account and password that should b… Hci H610s Firmware Mitigation only Fix from $1,6002020-06-29 HIGH 8.1 CVE-2020-14195 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jn… Active Iq Unified Manager 2.9.10.5+ Fix from $1,9502020-06-16 HIGH 8.1 CVE-2020-14060EPSS 9% FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.… Active Iq Unified Manager 2.9.10.5+ Fix from $1,9502020-06-14 HIGH 8.1 CVE-2020-14061 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueC… Active Iq Unified Manager 2.9.10.5+ Fix from $1,9502020-06-14 HIGH 8.1 CVE-2020-14062EPSS 8% FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xal… Active Iq Unified Manager 2.9.10.5+ Fix from $1,9502020-06-14 HIGH 7.5 CVE-2020-8572 Element OS prior to version 12.0 and Element HealthTools prior to version 2020.04.01.04 are susceptible to a vulnerability which when successfully ex… Element Healthtools 12.0 / 2020.04.01.04+ Fix from $1,9502020-05-21 HIGH 7.5 CVE-2019-5500 Certain versions of the NetApp Service Processor and Baseboard Management Controller firmware allow a remote unauthenticated attacker to cause a Deni… Fas26x0 Firmware No fix yet Fix from $1,9502020-05-11 MEDIUM 5.4 CVE-2019-17276 OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting vulnerability that could allow… Oncommand System Manager Mitigation only Fix from $1,6002020-03-24 HIGH 7.5 CVE-2020-8571 StorageGRID (formerly StorageGRID Webscale) versions 10.0.0 through 11.3 prior to 11.2.0.8 and 11.3.0.4 are susceptible to a vulnerability which allo… Storagegrid 11.2.0.8 / 11.3.0.4+ Fix from $1,9502020-03-13 CRITICAL 9.8 CVE-2020-9547EPSS 18% FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engi… Active Iq Unified Manager 2.7.9.7 / 2.8.11.6+ Fix from $2,3002020-03-02 CRITICAL 9.8 CVE-2020-9548EPSS 18% FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.An… Active Iq Unified Manager 2.7.9.7 / 2.8.11.6+ Fix from $2,3002020-03-02 CRITICAL 9.8 CVE-2020-9546 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shad… Active Iq Unified Manager 2.7.9.7 / 2.8.11.6+ Fix from $2,3002020-03-02 CRITICAL 9.8 CVE-2019-17275 OnCommand Cloud Manager versions prior to 3.8.0 are susceptible to arbitrary code execution by remote attackers. Oncommand Cloud Manager 3.8.0+ Fix from $2,3002020-02-26 HIGH 7.8 CVE-2019-17274 NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account en… Fabric Attached Storage 8700 Firmware after 13.1 Fix from $1,9502020-02-26 HIGH 7.2 CVE-2013-3322 NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to inject arbitrary commands in the Halt/Reboot interface. Oncommand System Manager after 2.1 Fix from $1,9502020-01-31 MEDIUM 6.5 CVE-2019-17273 E-Series SANtricity OS Controller Software version 11.60.0 is susceptible to a vulnerability which allows an attacker to cause a Denial of Service (D… E Series Santricity Os Controller after 11.60.0 Fix from $1,6002020-01-30 HIGH 7.5 CVE-2013-3321 NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnos… Oncommand System Manager after 2.1 Fix from $1,9502020-01-29 MEDIUM 6.1 CVE-2013-3320 Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML… Oncommand System Manager 2.2+ Fix from $1,6002020-01-29 CRITICAL 9.8 CVE-2019-5509 ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully e… Ontap Select Deploy Administration Utility after 2.12.2 Fix from $2,3002019-11-21 HIGH 7.2 CVE-2019-17272 All versions of ONTAP Select Deploy administration utility are susceptible to a vulnerability which when successfully exploited could allow an admini… Ontap Select Deploy Administration Utility Mitigation only Fix from $1,9502019-11-21 HIGH 7.5 CVE-2019-5508 Clustered Data ONTAP versions 9.2 through 9.4 are susceptible to a vulnerability which allows an attacker to use l2ping to cause a Denial of Service … Clustered Data Ontap after 9.4 Fix from $1,9502019-10-25 MEDIUM 5.9 CVE-2019-5506 Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonatio… Clustered Data Ontap after 9.6 Fix from $1,6002019-10-09 MEDIUM 5.5 CVE-2019-5507 SnapManager for Oracle prior to version 3.4.2P1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sens… Snapmanager 3.4.2+ Fix from $1,6002019-10-09 CRITICAL 9.8 CVE-2019-17267 A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactio… Active Iq Unified Manager 2.8.11.5 / 2.9.10+ Fix from $2,3002019-10-07 CRITICAL 9.8 CVE-2019-5504 ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote atta… Ontap Select Deploy Administration Utility Patch available Fix from $2,3002019-09-24 CRITICAL 9.8 CVE-2019-5505 ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext. Ontap Select Deploy Administration Utility after 2.12.1 Fix from $2,3002019-09-24 MEDIUM 5.3 CVE-2019-5503 OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers configured which could allow an attacker to obtain … Oncommand Workflow Automation Mitigation only Fix from $1,6002019-09-10 MEDIUM 6.5 CVE-2019-5498 OnCommand Insight versions through 7.3.6 may disclose sensitive account information to an authenticated user. Oncommand Insight after 7.3.6 Fix from $1,6002019-08-09 CRITICAL 9.1 CVE-2019-5502 SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 has weak cryptography which when exploited could lead to information disclosure or ad… Data Ontap 8.2.5+ Fix from $2,3002019-08-05 HIGH 7.5 CVE-2019-5493 Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 are susceptible to a vulnerability which discloses information to an unauthenticated attacke… Data Ontap 8.2.5+ Fix from $1,9502019-08-02