Netapp
Netapp Snap Creator Framework: vulnerabilidades y CVE
Netapp Snap Creator Framework tiene 42 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 11 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE42
Últimos 12 meses0
Críticas11
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-11023 | Media (6.1) | 85% | ⚠ Explotación activa | 29 abr 2020 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e.… |
| CVE-2016-8735 | Crítica (9.8) | 90% | ⚠ Explotación activa | 6 abr 2017 | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-22968 | Media (5.3) | 5.7% | — | 14 abr 2022 | In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless… |
| CVE-2020-36518 | Alta (7.5) | 4.9% | — | 11 mar 2022 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. |
| CVE-2021-42550 | Media (6.6) | 4.4% | — | 16 dic 2021 | In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers. |
| CVE-2021-22096 | Media (4.3) | 1.4% | — | 28 oct 2021 | In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. |
| CVE-2021-34429 | Media (5.3) | 99% | — | 15 jul 2021 | For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is… |
| CVE-2021-34428 | Baja (3.5) | 0.96% | — | 22 jun 2021 | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments… |
| CVE-2021-28169 | Media (5.3) | 78% | — | 9 jun 2021 | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request… |
| CVE-2020-27223 | Media (5.3) | 78% | — | 26 feb 2021 | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may… |
| CVE-2021-23901 | Crítica (9.1) | 4.4% | — | 25 ene 2021 | An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability… |
| CVE-2021-23926 | Crítica (9.1) | 6.2% | — | 14 ene 2021 | The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects… |
| CVE-2020-27218 | Media (4.8) | 8.3% | — | 28 nov 2020 | In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed… |
| CVE-2020-13954 | Media (6.1) | 41% | — | 12 nov 2020 | By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath,… |
| CVE-2020-27216 | Alta (7) | 4.4% | — | 23 oct 2020 | In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that… |
| CVE-2020-5421 | Media (6.5) | 11% | — | 19 sept 2020 | In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser… |
| CVE-2020-12723 | Alta (7.5) | 6.0% | — | 5 jun 2020 | regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls. |
| CVE-2020-10878 | Alta (8.6) | 4.9% | — | 5 jun 2020 | Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection. |
| CVE-2020-7656 | Media (6.1) | 6.3% | — | 19 may 2020 | jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in… |
| CVE-2020-10683 | Crítica (9.8) | 7.3% | — | 1 may 2020 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the… |
| CVE-2020-11022 | Media (6.1) | 99% | — | 29 abr 2020 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted… |
| CVE-2020-11023 | Media (6.1) | 85% | ⚠ Explotación activa | 29 abr 2020 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e.… |
| CVE-2016-5710 | Media (4.6) | 0.71% | — | 11 feb 2020 | NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors. |
| CVE-2019-10247 | Media (5.3) | 5.9% | — | 22 abr 2019 | In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource… |
| CVE-2019-10246 | Media (5.3) | 4.1% | — | 22 abr 2019 | In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for… |
| CVE-2018-18314 | Crítica (9.8) | 6.1% | — | 7 dic 2018 | Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations. |
| CVE-2018-18313 | Crítica (9.1) | 9.5% | — | 7 dic 2018 | Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory. |
| CVE-2018-18311 | Crítica (9.8) | 12% | — | 7 dic 2018 | Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. |
| CVE-2018-18312 | Crítica (9.8) | 12% | — | 5 dic 2018 | Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. |
| CVE-2018-11784 | Media (4.3) | 98% | — | 4 oct 2018 | When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially… |
| CVE-2018-1000632 | Alta (7.5) | 6.6% | — | 20 ago 2018 | dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection.… |
| CVE-2017-7658 | Crítica (9.8) | 19% | — | 26 jun 2018 | In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Netapp
Oncommand Insight · 971Active IQ Unified Manager · 848Oncommand Workflow Automation · 743Snapcenter · 575Cloud Backup · 349H700s Firmware · 293H300s Firmware · 292H500s Firmware · 292H410s Firmware · 292E-series Santricity OS Controller · 242H410c Firmware · 240Steelstore Cloud Integrated Storage · 211