Arbitrary File Inclusion in NetApp OnCommand System Manager
CVE-2013-3321
7.5HIGH
What is CVE-2013-3321?
NetApp OnCommand System Manager versions 2.1 and earlier are susceptible to an arbitrary file inclusion vulnerability. This can be exploited by remote attackers through crafted requests to the 'diagnostic' page, specifically manipulating the SnapMirror log path parameter. This flaw could potentially allow unauthorized access to sensitive information, posing a significant risk to system integrity and confidentiality.