Netapp Oncommand Unified Manager vulnerabilities
124 known vulnerabilities affecting netapp/oncommand_unified_manager.
Total CVEs
124
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH25MEDIUM74LOW7
Vulnerabilities
Page 2 of 7
CVE-2017-10086P3CRITICALCVSS 9.6≥ 7.12017-08-08
CVE-2017-10086 [CRITICAL] CVE-2017-10086: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attac
nvd
CVE-2017-10111P3CRITICALCVSS 9.6≤ 7.12017-08-08
CVE-2017-10111 [CRITICAL] CVE-2017-10111: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks requ
nvd
CVE-2018-2826P3HIGHCVSS 8.3≥ 7.3≥ 9.4+1 more2018-04-19
CVE-2018-2826 [HIGH] CVE-2018-2826: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported ve
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and whil
nvd
CVE-2017-10078P3HIGHCVSS 8.1≤ 7.12017-08-08
CVE-2017-10078 [HIGH] CVE-2017-10078: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Scripting). The supported ve
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Scripting). The supported version that is affected is Java SE: 8u131. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or
nvd
CVE-2016-9841P3CRITICALCVSS 9.8≤ 7.12017-05-23
CVE-2016-9841 [CRITICAL] CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by levera
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
nvd
CVE-2018-2825P3HIGHCVSS 8.3≥ 7.3≥ 9.4+1 more2018-04-19
CVE-2018-2825 [HIGH] CVE-2018-2825: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported ve
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and whil
nvd
CVE-2017-10116P3HIGHCVSS 8.3≤ 7.12017-08-08
CVE-2017-10116 [HIGH] CVE-2017-10116: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: S
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE,
nvd
CVE-2017-10074P3HIGHCVSS 8.3≤ 7.12017-08-08
CVE-2017-10074 [HIGH] CVE-2017-10074: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot).
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful a
nvd
CVE-2016-10708P3HIGHCVSS 7.5≥ 9.42018-01-21
CVE-2016-10708 [HIGH] CWE-476 CVE-2016-10708: sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer derefe
sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.
nvd
CVE-2017-10118P3HIGHCVSS 7.5≤ 7.12017-08-08
CVE-2017-10118 [HIGH] CVE-2017-10118: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: J
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedd
nvd
CVE-2017-10114P3HIGHCVSS 8.3≤ 7.12017-08-08
CVE-2017-10114 [HIGH] CVE-2017-10114: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u141 and 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacke
nvd
CVE-2019-18276P3HIGHCVSS 7.8≥ 9.52019-11-28
CVE-2019-18276 [HIGH] CWE-273 CVE-2019-18276: An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default
An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal to its real UID, it will drop privileges by setting its effective UID to its real UID. However, it does so incorrectly. On Linux and other systems that support "saved UID" functionality, the saved UID is
nvd
CVE-2017-10067P3HIGHCVSS 7.5≤ 7.12017-08-08
CVE-2017-10067 [HIGH] CVE-2017-10067: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported version
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than t
nvd
CVE-2017-10115P3HIGHCVSS 7.5≤ 7.12017-08-08
CVE-2017-10115 [HIGH] CVE-2017-10115: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: J
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE
nvd
CVE-2017-10388P3HIGHCVSS 7.5≤ 7.12017-10-19
CVE-2017-10388 [HIGH] CVE-2017-10388: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attac
nvd
CVE-2018-3155P3HIGHCVSS 7.7≥ 9.4≥ 7.32018-10-17
CVE-2018-3155 [HIGH] CVE-2018-3155: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supporte
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is in MySQL Server, attacks may
nvd
CVE-2019-2534P3HIGHCVSS 7.1≥ 7.3, ≤ 9.52019-01-16
CVE-2019-2534 [HIGH] CVE-2019-2534: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2019-5495P3HIGHCVSS 7.5fixed in 9.52019-05-10
CVE-2019-5495 [HIGH] CWE-254 CVE-2019-5495: OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain
OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.
nvd
CVE-2018-5486P3HIGHCVSS 7.8≥ 7.2, ≤ 7.32018-04-25
CVE-2018-5486 [HIGH] CWE-306 CVE-2018-5486: NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Pro
NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled which allows unauthorized local attackers to execute arbitrary code.
nvd
CVE-2019-5494P3HIGHCVSS 7.5fixed in 5.2.42019-05-10
CVE-2019-5494 [HIGH] CWE-319 CVE-2019-5494: OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security header
OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.
nvd