CVE-2016-3063: Netapp Oncommand System Manager

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users to execute arbitrary API calls via unspecified vectors.

Affected products

  • Netapp Oncommand System Manager: up to and including 8.3.1

Published 2017-02-07. Last modified 2026-06-17.