Vulnerabilities > Netapp > Snapcenter Server > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-10-21 CVE-2020-14773 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).
network
low complexity
oracle netapp fedoraproject
4.9
2020-10-21 CVE-2020-14769 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).
network
low complexity
oracle netapp fedoraproject
6.5
2020-10-21 CVE-2020-14672 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure).
network
low complexity
oracle netapp fedoraproject
4.9
2020-04-29 CVE-2020-11023 Cross-site Scripting vulnerability in multiple products
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e.
6.1
2019-03-04 CVE-2018-5482 Missing Encryption of Sensitive Data vulnerability in Netapp Snapcenter Server
NetApp SnapCenter Server prior to 4.1 does not set the secure flag for a sensitive cookie in an HTTPS session which can allow the transmission of the cookie in plain text over an unencrypted channel.
network
low complexity
netapp CWE-311
5.0
2018-03-06 CVE-2017-15519 Improper Authentication vulnerability in Netapp Snapcenter Server 2.0/3.0/3.0.1
Versions of SnapCenter 2.0 through 3.0.1 allow unauthenticated remote attackers to view and modify backup related data via the Plug-in for NAS File Services.
network
low complexity
netapp CWE-287
6.4
2017-11-16 CVE-2017-15516 Cross-Site Request Forgery (CSRF) vulnerability in Netapp Snapcenter Server 1.1/2.0
NetApp SnapCenter Server versions 1.1 through 2.x are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability which could be used to cause an unintended authenticated action in the user interface.
network
netapp CWE-352
6.8
2017-08-07 CVE-2015-7887 Improper Access Control vulnerability in Netapp Snapcenter Server 1.0
NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups.
network
low complexity
netapp CWE-284
6.5