Latest CVE Feed
-
9.8
CRITICALCVE-2020-8591
eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.... Read more
Affected Products : eg_manager- Published: Feb. 03, 2020
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2020-8590
Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport bundles even when the –remove-private-data parameter is set to true.... Read more
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-8589
Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which could allow unauthorized tenant users to discover the names of other Storage Virtual Machines (SVMs) and filenames on those SVMs.... Read more
- Published: Feb. 03, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-8588
Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which could allow unauthorized tenant users to discover the existence of data on other Storage Virtual Machines (SVMs).... Read more
- Published: Feb. 03, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-8587
OnCommand System Manager 9.x versions prior to 9.3P20 and 9.4 prior to 9.4P3 are susceptible to a vulnerability that could allow HTTP clients to cache sensitive responses making them accessible to an attacker who has access to the system where the client ... Read more
Affected Products : oncommand_system_manager- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-8585
OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).... Read more
Affected Products : oncommand_unified_manager- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-8584
Element OS versions prior to 1.8P1 and 12.2 are susceptible to a vulnerability that could allow an unauthenticated remote attacker to perform arbitrary code execution.... Read more
- Published: Jan. 08, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-8583
Element Software versions prior to 12.2 and HCI versions prior to 1.8P1 are susceptible to a vulnerability which could allow an attacker to discover sensitive information by intercepting its transmission within an https session.... Read more
- Published: Nov. 13, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-8582
Element Software versions prior to 12.2 and HCI versions prior to 1.8P1 are susceptible to a vulnerability which could allow an authenticated user to view sensitive information.... Read more
- Published: Nov. 13, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-8581
Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could allow an authenticated but unauthorized attacker to overwrite arbitrary data when VMware vStorage support is enabled.... Read more
- Published: Jan. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-8580
SANtricity OS Controller Software versions 11.30 and higher are susceptible to a vulnerability which allows an unauthenticated attacker with access to the system to cause a Denial of Service (DoS).... Read more
Affected Products : e-series_santricity_os_controller- Published: Nov. 06, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-8579
Clustered Data ONTAP versions 9.7 through 9.7P7 are susceptible to a vulnerability which allows an attacker with access to an intercluster LIF to cause a Denial of Service (DoS).... Read more
- Published: Oct. 27, 2020
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2020-8578
Clustered Data ONTAP versions prior to 9.3P20 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport bundles even when the –remove-private-data parameter is set to true.... Read more
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2020-8577
SANtricity OS Controller Software versions 11.50.1 and higher are susceptible to a vulnerability which could allow an attacker to discover sensitive information by intercepting its transmission within an https session.... Read more
Affected Products : e-series_santricity_os_controller- Published: Nov. 06, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-8576
Clustered Data ONTAP versions prior to 9.3P19, 9.5P14, 9.6P9 and 9.7 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or disclosure of sensitive information.... Read more
- Published: Sep. 02, 2020
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2020-8575
Active IQ Unified Manager for VMware vSphere and Windows versions prior to 9.5 are susceptible to a vulnerability which allows administrative users to cause Denial of Service (DoS).... Read more
Affected Products : active_iq_unified_manager- Published: Aug. 03, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-8574
Active IQ Unified Manager for Linux versions prior to 9.6 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service enabled allowing unauthorized code execution to local users.... Read more
Affected Products : active_iq_unified_manager- Published: Aug. 03, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-8573
The NetApp HCI H610C, H615C and H610S Baseboard Management Controllers (BMC) are shipped with a documented default account and password that should be changed during the initial node setup. During upgrades to Element 11.8 and 12.0 or the Compute Firmware ... Read more
- Published: Jun. 29, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-8572
Element OS prior to version 12.0 and Element HealthTools prior to version 2020.04.01.04 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information.... Read more
- Published: May. 21, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-8571
StorageGRID (formerly StorageGRID Webscale) versions 10.0.0 through 11.3 prior to 11.2.0.8 and 11.3.0.4 are susceptible to a vulnerability which allows an unauthenticated remote attacker to cause a Denial of Service (DoS).... Read more
Affected Products : storagegrid- Published: Mar. 13, 2020
- Modified: Nov. 21, 2024