VulnerabilityModified
CVE-2016-3063
Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users to execute arbitrary API calls via unspecified vectors.
HIGH 7.5EPSS 1.18%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users to execute arbitrary API calls via unspecified vectors.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-116
- Affected
- netapp/oncommand system manager
- Source
- cve@mitre.org
References
- https://kb.netapp.com/support/s/article/cve-2016-3063-zapi-injection-vulnerability-in-oncommand-system-managerPatch, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20160310-0004/
- https://kb.netapp.com/support/s/article/cve-2016-3063-zapi-injection-vulnerability-in-oncommand-system-managerPatch, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20160310-0004/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.