PT-2019-8023 · Netapp · Netapp Snapcenter Server

Published

2019-03-04

·

Updated

2019-03-07

·

CVE-2017-15515

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions NetApp SnapCenter Server versions prior to 4.0
Description The issue allows a privileged user to inject arbitrary scripts into the custom secondary policy label field, potentially leading to cross-site scripting.
Recommendations For versions prior to 4.0, update to version 4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the custom secondary policy label field to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15515

Affected Products

Netapp Snapcenter Server