CVEs (971)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Jun 1, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Jun 1, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume me...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Jun 1, 2021 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume me...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Jun 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Content Backup page. IBM X-Force ID: 172130. |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Jun 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Data Server Connection page. IBM X-Force ID: 172129. |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Jun 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via a stack trace due to mishandling of certain error conditions. IBM X-Force ID: 172128. |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Jun 1, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Jun 1, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for a sensitive cookie in an HTTPS session. A remote attacker could exploit t...Show more |
6Debian FedoraprojectNetapp+3 more28Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+25 moreDec 2, 2025 May 19, 2021 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of...Show more |
2Highcharts Netapp5Cloud Backup HighchartsOncommand Insight+2 moreNov 21, 2024 May 5, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Highcharts JS is a JavaScript charting library based on SVG. In Highcharts versions 8 and earlier, the chart options structure was not systematically filtered for XSS vectors. The potential impact was that content from u...Show more |
2Netapp Oracle5Active Iq Unified Manager MysqlOncommand Insight+2 moreNov 21, 2024 Apr 22, 2021 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attack...Show more |
2Netapp Oracle5Active Iq Unified Manager MysqlOncommand Insight+2 moreNov 21, 2024 Apr 22, 2021 N/A· v4 6.1 MEDIUM· v3 3.3 LOW· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows unauthenti...Show more |
2Netapp Oracle5Active Iq Unified Manager MysqlOncommand Insight+2 moreNov 21, 2024 Apr 22, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network...Show more |
2Netapp Oracle5Active Iq Unified Manager MysqlOncommand Insight+2 moreNov 21, 2024 Apr 22, 2021 N/A· v4 5.5 MEDIUM· v3 5.5 MEDIUM· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker...Show more |
2Netapp Oracle5Active Iq Unified Manager MysqlOncommand Insight+2 moreNov 21, 2024 Apr 22, 2021 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attack...Show more |
2Netapp Oracle5Active Iq Unified Manager MysqlOncommand Insight+2 moreNov 21, 2024 Apr 22, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network...Show more |
2Netapp Oracle5Active Iq Unified Manager MysqlOncommand Insight+2 moreNov 21, 2024 Apr 22, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with n...Show more |
2Netapp Oracle5Active Iq Unified Manager MysqlOncommand Insight+2 moreNov 21, 2024 Apr 22, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows low privileged attacker with ne...Show more |
2Netapp Oracle5Active Iq Unified Manager MysqlOncommand Insight+2 moreNov 21, 2024 Apr 22, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker...Show more |
2Netapp Oracle5Active Iq Unified Manager MysqlOncommand Insight+2 moreNov 21, 2024 Apr 22, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with n...Show more |