CVE-2017-7236: SQL Injection
Published May 25, 2017
·Updated
SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
7 affected components
NetApp OnCommand Unified Manager Core Package=5.0
NetApp OnCommand Unified Manager Core Package=5.0.1
NetApp OnCommand Unified Manager Core Package=5.0.2
NetApp OnCommand Unified Manager Core Package=5.1
NetApp OnCommand Unified Manager Core Package=5.2
NetApp OnCommand Unified Manager Core Package=5.2.1
NetApp OnCommand Unified Manager Core Package=5.2.2
Remediation
Patch Available
Event History
May 25, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-7236?
CVE-2017-7236 has been classified with a high severity due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2017-7236?
To mitigate CVE-2017-7236, upgrade to NetApp OnCommand Unified Manager Core Package version 5.2.2P1 or later.
3
What software is affected by CVE-2017-7236?
CVE-2017-7236 affects versions 5.0 through 5.2.1 of the NetApp OnCommand Unified Manager Core Package.
4
What type of vulnerability is CVE-2017-7236?
CVE-2017-7236 is classified as an SQL injection vulnerability.
5
Can CVE-2017-7236 be exploited remotely?
Yes, CVE-2017-7236 allows remote attackers to exploit the vulnerability without authentication.