VYPR
Medium severity5.3NVD Advisory· Published Mar 4, 2019· Updated Jun 17, 2026

CVE-2018-5482

CVE-2018-5482

Description

NetApp SnapCenter Server prior to 4.1 does not set the secure flag for a sensitive cookie in an HTTPS session which can allow the transmission of the cookie in plain text over an unencrypted channel.

Affected products

3
  • NetApp/Snapcentercpe-rescue2 versions
    Versions prior to 4.1+ 1 more
    • (no CPE)range: Versions prior to 4.1
    • cpe:2.3:a:netapp:snapcenter_server:*:*:*:*:*:*:*:*range: <4.1
  • Range: <4.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.