PT-2017-13226 · Netapp · Netapp Oncommand Unified Manager For Clustered Data Ontap

Publicado

2017-09-01

·

Atualizado

2017-09-06

·

CVE-2017-14053

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NetApp OnCommand Unified Manager for Clustered Data ONTAP versions prior to 7.2P1
Description The issue makes it easier for remote attackers to capture an unspecified cookie by intercepting its transmission within an HTTP session, as the secure flag is not set for the cookie in an HTTPS session.
Recommendations For versions prior to 7.2P1, update to version 7.2P1 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-14053

Produtos afetados

Netapp Oncommand Unified Manager For Clustered Data Ontap