NetApp Cloud Manager 3.7.3

CPE Details

NetApp Cloud Manager 3.7.3
3.7.3
2021-10-13
11h48 +00:00
2021-10-13
11h52 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:netapp:cloud_manager:3.7.3:*:*:*:*:*:*:*

Informations

Vendor

netapp

Product

cloud_manager

Version

3.7.3

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-27002 2021-10-11 14h37 +00:00 NetApp Cloud Manager versions prior to 3.9.10 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to retrieve sensitive data via the web proxy.
7.5
High
CVE-2021-26999 2021-08-06 12h20 +00:00 NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The logged information is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version.
4.3
Medium
CVE-2021-26998 2021-08-06 12h19 +00:00 NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version.
4.3
Medium
CVE-2021-28165 2021-04-01 12h20 +00:00 In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
7.5
High
CVE-2021-26990 2021-03-19 17h42 +00:00 Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files.
9.1
Critical
CVE-2021-26992 2021-03-19 17h39 +00:00 Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability which could allow a remote attacker to cause a Denial of Service (DoS).
7.5
High
CVE-2021-26991 2021-03-19 17h34 +00:00 Cloud Manager versions prior to 3.9.4 contain an insecure Cross-Origin Resource Sharing (CORS) policy which could allow a remote attacker to interact with Cloud Manager.
7.5
High