CVE-2018-5486Missing Authentication for Critical Function in Oncommand Unified Manager

Severity
7.8HIGHNVD
EPSS
0.1%
top 71.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 25
Latest updateMay 13

Description

NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled which allows unauthorized local attackers to execute arbitrary code.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-8657-j78q-jmw2: NetApp OnCommand Unified Manager for Linux versions 72022-05-13
CVEList
CVE-2018-5486: NetApp OnCommand Unified Manager for Linux versions 72018-04-25
CVE-2018-5486 — Oncommand Unified Manager vulnerability | cvebase