CVE-2020-8587: Medium severity netapp system manager vulnerability
OnCommand System Manager 9.x versions prior to 9.3P20 and 9.4 prior to 9.4P3 are susceptible to a vulnerability that could allow HTTP clients to cache sensitive responses making them accessible to an attacker who has access to the system where the client runs.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-8587.
Which versions of OnCommand System Manager are affected by this vulnerability?
OnCommand System Manager versions prior to 9.3P20 and 9.4 prior to 9.4P3 are affected by this vulnerability.
How severe is this vulnerability?
This vulnerability has a severity rating of medium with a CVSS score of 5.5.
What is the impact of this vulnerability?
This vulnerability could allow HTTP clients to cache sensitive responses, making them accessible to an attacker who has access to the system where the client runs.
How can I fix this vulnerability?
To fix this vulnerability, upgrade OnCommand System Manager to version 9.3P20 or 9.4P3 or later.