CVE Vulnerabilities

CVE-2020-8587

Published: Feb 08, 2021 | Modified: Feb 12, 2021
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

OnCommand System Manager 9.x versions prior to 9.3P20 and 9.4 prior to 9.4P3 are susceptible to a vulnerability that could allow HTTP clients to cache sensitive responses making them accessible to an attacker who has access to the system where the client runs.

Affected Software

Name Vendor Start Version End Version
Oncommand_system_manager Netapp 9.0 (including) 9.3 (excluding)
Oncommand_system_manager Netapp 9.3 (including) 9.3 (including)
Oncommand_system_manager Netapp 9.4 (including) 9.4 (including)

References