Cross-Site Request Forgery Vulnerability in NetApp SnapCenter Server
CVE-2017-15516

8.8HIGH

Key Information:

Vendor
Netapp
Vendor
CVE Published:
16 November 2017

Summary

NetApp SnapCenter Server versions 1.1 through 2.x are vulnerable to a Cross-Site Request Forgery (CSRF) attack. This vulnerability enables malicious actors to exploit authenticated sessions, potentially leading to unauthorized or unintended actions within the user interface. This could impact the integrity of operations performed by users on the system, and highlights the importance of keeping software updated to mitigate such vulnerabilities.

Affected Version(s)

SnapCenter Server Versions 1.1 through 2.x

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-15516 : Cross-Site Request Forgery Vulnerability in NetApp SnapCenter Server | SecurityVulnerability.io