CVE-2024-22243: Netapp Active Iq Unified Manager

High severity, CVSS 8.1. EPSS: 4% chance of exploitation in the next 30 days.

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.

Affected products

  • Netapp Active Iq Unified Manager: version 5.0 only
  • Pivotal Software Spring Framework: from 5.3.0, before 5.3.32 (fixed in 5.3.32)
  • Spring Spring Framework: from 6.0, before 6.0.17 (fixed in 6.0.17); from 6.1, before 6.1.4 (fixed in 6.1.4); from 5.3, before 5.3.32 (fixed in 5.3.32)
  • VMware Spring Framework: from 6.0.0, before 6.0.17 (fixed in 6.0.17); from 6.1.0, before 6.1.4 (fixed in 6.1.4)

Published 2024-02-23. Last modified 2026-06-17.