Vulnerabilities > Netapp > Oncommand Unified Manager FOR Clustered Data Ontap > 6.3

DATE CVE VULNERABILITY TITLE RISK
2017-09-01 CVE-2017-14053 Information Exposure vulnerability in Netapp Oncommand Unified Manager for Clustered Data Ontap 6.3/6.4/7.2
NetApp OnCommand Unified Manager for Clustered Data ONTAP before 7.2P1 does not set the secure flag for an unspecified cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
network
low complexity
netapp CWE-200
7.5
2017-02-07 CVE-2016-6667 Unspecified vulnerability in Netapp Oncommand Unified Manager for Clustered Data Ontap 6.3/6.4
NetApp OnCommand Unified Manager for Clustered Data ONTAP 6.3 through 6.4P1 contain a default privileged account, which allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
netapp
critical
9.8