CVEs (971)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Apache AzulDebian+3 more167 Mode Transition Tool Active Iq Unified ManagerCloud Insights Acquisition Unit+13 moreMay 27, 2026 Jul 19, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execut...Show more |
2Ibm Netapp3Cognos Analytics Oncommand InsightPlanning AnalyticsNov 21, 2024 Jun 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Jun 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238. |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Jun 24, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682. |
4Haxx NetappOracle+1 more14Active Iq Unified Manager Bh500s FirmwareClustered Data Ontap+11 moreNov 21, 2024 Jun 2, 2022 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`. |
2Netapp Redhat8Active Iq Unified Manager IntegrationJboss Enterprise Application Platform+5 moreNov 21, 2024 May 24, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability...Show more |
2Netapp Redhat8Active Iq Unified Manager FuseJboss Enterprise Application Platform+5 moreNov 21, 2024 May 24, 2022 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affect...Show more |
3Netapp OracleVmware4Cloud Secure Agent Financial Services Crime And Compliance Management StudioOncommand Insight+1 moreNov 21, 2024 May 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. |
3Netapp OracleVmware6Active Iq Unified Manager Brocade San NavigatorCloud Secure Agent+3 moreNov 21, 2024 May 12, 2022 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servle...Show more |
6Debian FedoraprojectNetapp+3 more35A250 Firmware A700s FirmwareActive Iq Unified Manager+32 moreAug 13, 2025 May 3, 2022 N/A· v4 7.3 HIGH· v3 10.0 HIGH· v2 The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating sys...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Apr 22, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Apr 22, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should not have access to. IBM X-Force ID: 209697. |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Apr 22, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings. IBM X-Force ID: 209693. |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Apr 22, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script i...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Apr 22, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Apr 22, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could have read access to to the 'Data Connections' page to which they don't have access. IBM X-Force ID: 20...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Apr 22, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813. |
4Azul DebianNetapp+1 more16Active Iq Unified Manager Bootstrap OsCloud Insights Acquisition Unit+13 moreNov 21, 2024 Apr 19, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle Graal...Show more |
2Netapp Oracle4Active Iq Unified Manager Mysql ClusterOncommand Insight+1 moreNov 21, 2024 Apr 19, 2022 N/A· v4 6.3 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to e...Show more |
2Netapp Oracle4Active Iq Unified Manager MysqlOncommand Insight+1 moreNov 21, 2024 Apr 19, 2022 N/A· v4 6.3 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to e...Show more |