First published: Tue Feb 07 2017(Updated: )
Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users to execute arbitrary API calls via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp System Manager | <=8.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3063 is classified as a medium severity vulnerability.
To remediate CVE-2016-3063, upgrade NetApp OnCommand System Manager to version 8.3.2 or later.
Attackers can exploit CVE-2016-3063 to execute arbitrary API calls as remote authenticated users.
Versions before 8.3.2, specifically up to and including 8.3.1, are affected by CVE-2016-3063.
Yes, a patch is available in the form of an upgrade to version 8.3.2 or later for CVE-2016-3063.