CVE-2017-14053
Last modified
CVE-2017-14053 is a vulnerability of currently unknown severity. NetApp OnCommand Unified Manager for Clustered Data ONTAP before 7.2P1 does not set the secure flag for an unspecified cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.. EPSS estimates a 1.85% chance of exploitation in the next 30 days.
Description
NetApp OnCommand Unified Manager for Clustered Data ONTAP before 7.2P1 does not set the secure flag for an unspecified cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netapp | Oncommand Unified Manager For Clustered Data Ontap | <= 7.2 |
References
- https://kb.netapp.com/support/s/article/NTAP-20170831-0001Vendor Advisory
- https://kb.netapp.com/support/s/article/NTAP-20170831-0001Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14053?
How severe is CVE-2017-14053?
How do I fix CVE-2017-14053?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-14042A memory allocation failure was discovered in the ReadPNMIma…
- CVE-2017-14048BlackCat CMS 1.2 allows remote authenticated users to inject…
- CVE-2017-14049In BlackCat CMS 1.2, backend/settings/ajax_save_settings.php…
- CVE-2017-1405IBM Security Identity Manager Virtual Appliance 7.0 processe…4.4
- CVE-2017-14050In BlackCat CMS 1.2, backend/addons/install.php allows remot…
- CVE-2017-14051An integer overflow in the qla2x00_sysfs_write_optrom_ctl fu…
- CVE-2017-14054In libavformat/rmdec.c in FFmpeg 3.3.3, a DoS in ivr_read_he…
- CVE-2017-14055In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_hea…
- CVE-2017-14056In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_head…
- CVE-2017-14057In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of a…
- CVE-2017-14058In FFmpeg 2.4 and 3.3.3, the read_data function in libavform…
- CVE-2017-14059In FFmpeg 3.3.3, a DoS in cine_read_header() due to lack of …
Are you affected by CVE-2017-14053?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
