Vulnerabilities > Netapp > Snapcenter Server > 1.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-03-04 | CVE-2018-5482 | Missing Encryption of Sensitive Data vulnerability in Netapp Snapcenter Server NetApp SnapCenter Server prior to 4.1 does not set the secure flag for a sensitive cookie in an HTTPS session which can allow the transmission of the cookie in plain text over an unencrypted channel. | 5.3 |
2019-03-04 | CVE-2017-15515 | Cross-site Scripting vulnerability in Netapp Snapcenter Server NetApp SnapCenter Server prior to 4.0 is susceptible to cross site scripting vulnerability that could allow a privileged user to inject arbitrary scripts into the custom secondary policy label field. | 4.8 |
2017-08-07 | CVE-2015-7887 | Improper Access Control vulnerability in Netapp Snapcenter Server 1.0 NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups. | 8.1 |
2017-02-07 | CVE-2016-1502 | Improper Authentication vulnerability in Netapp Snapcenter Server 1.0 NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and delete backups via unspecified vectors. | 7.3 |