CVE-2016-3063

M

ultiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users to execute arbitrary API calls via unspecified vectors.

Configurations

Configuration 1 (hide)

cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:49

Type Values Removed Values Added
References () https://kb.netapp.com/support/s/article/cve-2016-3063-zapi-injection-vulnerability-in-oncommand-system-manager - Patch, Vendor Advisory () https://kb.netapp.com/support/s/article/cve-2016-3063-zapi-injection-vulnerability-in-oncommand-system-manager - Patch, Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20160310-0004/ - () https://security.netapp.com/advisory/ntap-20160310-0004/ -

Information

Published : 2017-02-07 17:59

Updated : 2025-04-20 01:37


NVD link : CVE-2016-3063

Mitre link : CVE-2016-3063

CVE.ORG link : CVE-2016-3063


JSON object : View

Products Affected
CWE
CWE-116

Improper Encoding or Escaping of Output