Cross-Site Request Forgery Vulnerability in NetApp SnapCenter Server
CVE-2017-15516
8.8HIGH
Summary
NetApp SnapCenter Server versions 1.1 through 2.x are vulnerable to a Cross-Site Request Forgery (CSRF) attack. This vulnerability enables malicious actors to exploit authenticated sessions, potentially leading to unauthorized or unintended actions within the user interface. This could impact the integrity of operations performed by users on the system, and highlights the importance of keeping software updated to mitigate such vulnerabilities.
Affected Version(s)
SnapCenter Server Versions 1.1 through 2.x
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved