CVE-2017-7236

EUVD-2017-16268
SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
Affected Products (NVD)
VendorProductVersion
netapponcommand_unified_manager_core_package
5.0
netapponcommand_unified_manager_core_package
5.0.1
netapponcommand_unified_manager_core_package
5.0.2
netapponcommand_unified_manager_core_package
5.1
netapponcommand_unified_manager_core_package
5.2
netapponcommand_unified_manager_core_package
5.2.1
netapponcommand_unified_manager_core_package
5.2.2
𝑥
= Vulnerable software versions