« Volver al listado

CVE-2017-11461

Estado: ModificadaMedia (4.3)—

NetApp OnCommand Unified Manager for 7-mode (core package) versions prior to 5.2.1 are susceptible to a clickjacking or "UI redress attack" which could be used to cause a user to perform an unintended action in the user interface.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-11461",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@netapp.com",
      "affectedData": [
        {
          "vendor": "NetApp",
          "product": "OnCommand Unified Manager",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 5.2.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-11-10T02:29:16.933",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/101778",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security-alert@netapp.com"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20171107-0001/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@netapp.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/101778",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20171107-0001/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NetApp OnCommand Unified Manager for 7-mode (core package) versions prior to 5.2.1 are susceptible to a clickjacking or \"UI redress attack\" which could be used to cause a user to perform an unintended action in the user interface."
    },
    {
      "lang": "es",
      "value": "NetApp OnCommand Unified Manager para 7-mode (core package) en versiones anteriores a la 5.2.1 es susceptible al secuestro de clics o \"UI redress attack\", lo que se podría utilizar para provocar que un usuario realice una acción no planeada en la interfaz de usuario."
    }
  ],
  "lastModified": "2026-06-17T01:01:50.890",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netapp:oncommand_unified_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "368769EB-FC64-4A59-9F46-8037ED0DD5F4",
              "versionEndExcluding": "5.2.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@netapp.com"
}