
CVE-2016-5045
https://notcve.org/view.php?id=CVE-2016-5045
03 Jul 2017 — NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup. NetApp OnCommand System Manager anterior la versión 9.0 permite a un atacante remoto obtener credenciales sensibles mediante los vectores relacionados a la configuración de pares del clúster. • https://kb.netapp.com/support/s/article/ka51A00000007OTQAY/NTAP-20170323-0001 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-3063
https://notcve.org/view.php?id=CVE-2016-3063
07 Feb 2017 — Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users to execute arbitrary API calls via unspecified vectors. Funciones múltiples en NetApp OnCommand System Manager en versiones anteriores a 8.3.2 no escapan adecuadamente de caracteres especiales, lo que permite a usuarios remotos autenticados ejecutar llamadas API arbitrarias a través de vectores no especificados. • https://kb.netapp.com/support/s/article/cve-2016-3063-zapi-injection-vulnerability-in-oncommand-system-manager • CWE-116: Improper Encoding or Escaping of Output •

CVE-2016-5047
https://notcve.org/view.php?id=CVE-2016-5047
01 Sep 2016 — NetApp OnCommand System Manager 8.3.x before 8.3.2P5 allows remote authenticated users to cause a denial of service via unspecified vectors. NetApp OnCommand System Manager 8.3.x en versiones anteriores a 8.3.2P5 permite a usuarios remotos autenticados provocar una denegación de servicio a través de vectores no especificados. • http://kb.netapp.com/support/index?page=content&id=9010100 •