CVE-2017-13652: Input Validation
Published Jul 31, 2018
·Updated
NetApp OnCommand Insight version 7.3.0 and versions prior to 7.2.0 are susceptible to clickjacking attacks which could cause a user to perform an unintended action in the user interface.
Affected Software
2 affected components
NetApp OnCommand Insight<7.2.0
NetApp OnCommand Insight=7.3.0
Event History
Jul 31, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-13652?
CVE-2017-13652 is classified as a medium severity vulnerability due to its potential for clickjacking attacks.
2
How do I fix CVE-2017-13652?
To fix CVE-2017-13652, upgrade to NetApp OnCommand Insight version 7.2.0 or later.
3
What are the potential impacts of CVE-2017-13652?
The potential impacts of CVE-2017-13652 include unauthorized actions being performed by users through clickjacking.
4
Which versions of NetApp OnCommand Insight are affected by CVE-2017-13652?
NetApp OnCommand Insight versions 7.3.0 and earlier than 7.2.0 are affected by CVE-2017-13652.
5
Is there a known exploitation method for CVE-2017-13652?
Yes, CVE-2017-13652 can be exploited through clickjacking techniques, leading users to perform unintended actions.