CVE-2024-38808: Netapp Active Iq Unified Manager

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL expressions.

Affected products

  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Oncommand Insight: affected versions not specified
  • VMware Spring Framework: from 5.3.0, before 5.3.39 (fixed in 5.3.39)

Published 2024-08-20. Last modified 2026-06-17.