NetApp SnapCenter Server prior to 4.1 does not set the secure flag for a sensitive cookie in an HTTPS session which can allow the transmission of the cookie in plain text over an unencrypted channel.
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/107274 | vdb entry third party advisory |
https://security.netapp.com/advisory/ntap-20190304-0001/ | patch vendor advisory |