HTTP Caching Vulnerability in OnCommand System Manager by NetApp
CVE-2020-8587

5.5MEDIUM

Key Information:

Vendor
Netapp
Vendor
CVE Published:
8 February 2021

Summary

OnCommand System Manager versions 9.x before 9.3P20 and 9.4 prior to 9.4P3 are affected by a vulnerability that allows HTTP clients to cache sensitive responses. This flaw can lead to potential data exposure, as attackers with access to the client system may retrieve cached data that should remain confidential. It highlights the importance of ensuring that sensitive information is not inadvertently stored in client-side caches, which could compromise security.

Affected Version(s)

OnCommand System Manager 9.x Versions 9.x prior to 9.3P20 and 9.4 prior to 9.4P3

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-8587 : HTTP Caching Vulnerability in OnCommand System Manager by NetApp | SecurityVulnerability.io