← Back

Oncommand Shift

oncommand_shift

Vendor: Netapp • 64 CVEs

CVEs (64)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Apache
Netapp
3Oncommand Insight
Oncommand ShiftTomcat
Apr 16, 2026
Mar 14, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to...Show more
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.Show less
6Canonical
DebianLittlecms+3 more
19Active Iq Unified Manager
Debian LinuxE Series Santricity Management+16 more
May 13, 2026
Feb 3, 2017
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bo...Show more
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.Show less
2Ietf
Netapp
13Clustered Data Ontap Antivirus Connector
Data Ontap EdgeHost Agent+10 more
May 6, 2026
Sep 21, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in c...Show more
The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the "Key Compromise Impersonation (KCI)" issue.Show less
8Apache
CanonicalDebian+5 more
38Cassandra
Debian LinuxE Series Santricity Management Plug Ins+35 more
Apr 22, 2026
Apr 21, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.