VYPR
Medium severity5.4NVD Advisory· Published Mar 24, 2020· Updated Jun 17, 2026

CVE-2019-17276

CVE-2019-17276

Description

OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting vulnerability that could allow an authenticated attacker to inject arbitrary scripts into the SNMP Community Names label field.

Affected products

4
  • cpe:2.3:a:netapp:oncommand_system_manager:9.3:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:netapp:oncommand_system_manager:9.3:*:*:*:*:*:*:*
    • cpe:2.3:a:netapp:oncommand_system_manager:9.4:*:*:*:*:*:*:*
    • (no CPE)range: <9.3P18, <9.4P2
  • OnCommand/OnCommand System Managerdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.