First published: Wed Jun 01 2022(Updated: )
E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redirect users to malicious websites.
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.70.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23237 is a vulnerability that affects E-Series SANtricity OS Controller Software 11.x versions through 11.70.2.
The severity of CVE-2022-23237 is medium with a CVSS score of 6.1.
CVE-2022-23237 allows for host header injection attacks, which can redirect users to malicious websites.
E-Series SANtricity OS Controller Software versions 11.x through 11.70.2 are vulnerable.
To fix CVE-2022-23237, it is recommended to update E-Series SANtricity OS Controller Software to a version higher than 11.70.2.