CVE-2019-17276: XSS
Published Mar 24, 2020
·Updated
OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting vulnerability that could allow an authenticated attacker to inject arbitrary scripts into the SNMP Community Names label field.
Affected Software
2 affected components
NetApp OnCommand System Manager=9.3
NetApp OnCommand System Manager=9.4
Event History
Mar 24, 2020
CVE Published
via MITRE·05:44 PM
Data Sourced
via MITRE·05:44 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-17276?
CVE-2019-17276 is a cross site scripting vulnerability in OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2.
2
How severe is CVE-2019-17276?
CVE-2019-17276 has a severity rating of 5.4 (medium).
3
Which systems are affected by CVE-2019-17276?
OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are affected by CVE-2019-17276.
4
What is the impact of CVE-2019-17276?
An authenticated attacker could inject arbitrary scripts into the SNMP Community Names label field.
5
How can I fix CVE-2019-17276?
Update to OnCommand System Manager version 9.3P18 or 9.4P2 to mitigate the vulnerability.