First published: Tue Mar 24 2020(Updated: )
OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting vulnerability that could allow an authenticated attacker to inject arbitrary scripts into the SNMP Community Names label field.
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp OnCommand System Manager | =9.3 | |
NetApp OnCommand System Manager | =9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17276 is a cross site scripting vulnerability in OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2.
CVE-2019-17276 has a severity rating of 5.4 (medium).
OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are affected by CVE-2019-17276.
An authenticated attacker could inject arbitrary scripts into the SNMP Community Names label field.
Update to OnCommand System Manager version 9.3P18 or 9.4P2 to mitigate the vulnerability.