« Volver al listado

CVE-2017-15518

Estado: ModificadaAlta (7.8)—

All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password. All users are urged to move to a fixed version. Since the affected password is changed during every upgrade/installation no further action is required.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-15518",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@netapp.com",
      "affectedData": [
        {
          "vendor": "NetApp",
          "product": "OnCommand API Services and NetApp Service Level Manager",
          "versions": [
            {
              "status": "affected",
              "version": "Versions prior to 2.1 and 1.0RC4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-02-23T23:29:00.343",
  "references": [
    {
      "url": "https://security.netapp.com/advisory/NTAP-20180223-0001/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@netapp.com"
    },
    {
      "url": "https://security.netapp.com/advisory/NTAP-20180223-0001/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password. All users are urged to move to a fixed version. Since the affected password is changed during every upgrade/installation no further action is required."
    },
    {
      "lang": "es",
      "value": "Todas las versiones de OnCommand API Services, en versiones anteriores a la 2.1 y NetApp Service Level Manager, en versiones anteriores a la 1.0RC4, registran una contraseña de cuenta de usuario de base de datos privilegiada. Se recomienda encarecidamente que todos los usuarios empleen una versión solucionada. Debido a que la contraseña afectada se cambia en cada actualización/instalación, no es necesario realizar más acciones."
    }
  ],
  "lastModified": "2026-06-17T01:07:50.340",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netapp:oncommand_api_services:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6FA0BED1-643B-4A26-8D13-42FD779C0B3D",
              "versionEndIncluding": "2.0"
            },
            {
              "criteria": "cpe:2.3:a:netapp:service_level_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8EB1BE30-F7FB-4FD8-A3B4-8D53A4EF56E9",
              "versionEndIncluding": "1.0"
            },
            {
              "criteria": "cpe:2.3:a:netapp:service_level_manager:1.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4D72396-C484-4B19-9E30-ADE3012C019C"
            },
            {
              "criteria": "cpe:2.3:a:netapp:service_level_manager:1.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80A266E2-11F0-4654-8553-0E88C3EA4188"
            },
            {
              "criteria": "cpe:2.3:a:netapp:service_level_manager:1.0:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "450C4C6E-FFCE-44A9-8556-BA52B39EC012"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@netapp.com"
}