CVE-2016-5045
https://notcve.org/view.php?id=CVE-2016-5045
NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup. NetApp OnCommand System Manager anterior la versión 9.0 permite a un atacante remoto obtener credenciales sensibles mediante los vectores relacionados a la configuración de pares del clúster. • https://kb.netapp.com/support/s/article/ka51A00000007OTQAY/NTAP-20170323-0001 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-3063
https://notcve.org/view.php?id=CVE-2016-3063
Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users to execute arbitrary API calls via unspecified vectors. Funciones múltiples en NetApp OnCommand System Manager en versiones anteriores a 8.3.2 no escapan adecuadamente de caracteres especiales, lo que permite a usuarios remotos autenticados ejecutar llamadas API arbitrarias a través de vectores no especificados. • https://kb.netapp.com/support/s/article/cve-2016-3063-zapi-injection-vulnerability-in-oncommand-system-manager https://security.netapp.com/advisory/ntap-20160310-0004 • CWE-116: Improper Encoding or Escaping of Output •
CVE-2016-5047
https://notcve.org/view.php?id=CVE-2016-5047
NetApp OnCommand System Manager 8.3.x before 8.3.2P5 allows remote authenticated users to cause a denial of service via unspecified vectors. NetApp OnCommand System Manager 8.3.x en versiones anteriores a 8.3.2P5 permite a usuarios remotos autenticados provocar una denegación de servicio a través de vectores no especificados. • http://kb.netapp.com/support/index?page=content&id=9010100 http://www.securityfocus.com/bid/92685 https://security.netapp.com/advisory/ntap-20160830-0001 •