OnCommand System Manager 9.x versions prior to 9.3P20 and 9.4 prior to 9.4P3 are susceptible to a vulnerability that could allow HTTP clients to cache sensitive responses making them accessible to an attacker who has access to the system where the client runs.
2021-02-08T22:15:12.327
2024-11-21T05:39:04.850
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netapp | oncommand_system_manager | < 9.3 | Yes |
Application | netapp | oncommand_system_manager | 9.3 | Yes |
Application | netapp | oncommand_system_manager | 9.4 | Yes |