CVE-2020-8587
https://notcve.org/view.php?id=CVE-2020-8587
OnCommand System Manager 9.x versions prior to 9.3P20 and 9.4 prior to 9.4P3 are susceptible to a vulnerability that could allow HTTP clients to cache sensitive responses making them accessible to an attacker who has access to the system where the client runs. OnCommand System Manager versiones 9.x anteriores a 9.3P20 y versiones 9.4 anteriores a 9.4P3, son susceptibles a una vulnerabilidad que podría permitir a los clientes HTTP almacenar en caché respuestas confidenciales, haciéndolas accesibles a un atacante que tenga acceso al sistema donde se ejecuta el cliente • https://security.netapp.com/advisory/NTAP-20210208-0001 •
CVE-2019-17276
https://notcve.org/view.php?id=CVE-2019-17276
OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting vulnerability that could allow an authenticated attacker to inject arbitrary scripts into the SNMP Community Names label field. OnCommand System Manager versiones 9.3 anteriores a la versión 9.3P18 y versiones 9.4 anteriores a la versión 9.4P2, son susceptibles a una vulnerabilidad de tipo cross site scripting que podría permitir a un atacante autenticado inyectar scripts arbitrarios en el campo de etiqueta Community Names SNMP. • https://security.netapp.com/advisory/ntap-20200323-0001 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •