CVE-2020-8587
MEDIUMOnCommand System Manager <9.3P20, <9.4P3 - Info Disclosure
Title source: llmDescription
OnCommand System Manager 9.x versions prior to 9.3P20 and 9.4 prior to 9.4P3 are susceptible to a vulnerability that could allow HTTP clients to cache sensitive responses making them accessible to an attacker who has access to the system where the client runs.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://security.netapp.com/advisory/NTAP-20210208-0001/
Scores
CVSS v3
5.5
EPSS
0.0018
EPSS Percentile
39.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
Status
published
Products (3)
netapp/oncommand_system_manager
9.3
netapp/oncommand_system_manager
9.4
netapp/oncommand_system_manager
9.0 - 9.3
Published
Feb 08, 2021
Tracked Since
Feb 18, 2026