Vulnerabilities
Vulnerable Software
NetApp SnapCenter Server prior to 4.1 does not set the secure flag for a sensitive cookie in an HTTPS session which can allow the transmission of the cookie in plain text over an unencrypted channel.
CVSS Score
5.3
EPSS Score
0.001
Published
2019-03-04
NetApp SnapCenter Server prior to 4.0 is susceptible to cross site scripting vulnerability that could allow a privileged user to inject arbitrary scripts into the custom secondary policy label field.
CVSS Score
4.8
EPSS Score
0.002
Published
2019-03-04
NetApp SnapCenter Server versions 1.1 through 2.x are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability which could be used to cause an unintended authenticated action in the user interface.
CVSS Score
8.8
EPSS Score
0.002
Published
2017-11-16


Contact Us

Shodan ® - All rights reserved