Netapp Oncommand Unified Manager vulnerabilities

124 known vulnerabilities affecting netapp/oncommand_unified_manager.

Total CVEs
124
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH25MEDIUM74LOW7

Vulnerabilities

Page 3 of 7
CVE-2018-3280MEDIUMCVSS 4.9≥ 9.4≥ 7.32018-10-17
CVE-2018-3280 [MEDIUM] CVE-2018-3280: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: JSON). Supported Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: JSON). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2018-3283MEDIUMCVSS 4.4≥ 9.4≥ 7.32018-10-17
CVE-2018-3283 [MEDIUM] CVE-2018-3283: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Logging). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Logging). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can resul
nvd
CVE-2018-3143MEDIUMCVSS 6.5≥ 9.4≥ 7.32018-10-17
CVE-2018-3143 [MEDIUM] CVE-2018-3143: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2018-3276MEDIUMCVSS 4.9≥ 9.4≥ 7.32018-10-17
CVE-2018-3276 [MEDIUM] CVE-2018-3276: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulne
nvd
CVE-2018-3145MEDIUMCVSS 6.5≥ 7.3, ≤ 9.52018-10-17
CVE-2018-3145 [MEDIUM] CVE-2018-3145: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supporte Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2018-3251MEDIUMCVSS 6.5≥ 9.4≥ 7.32018-10-17
CVE-2018-3251 [MEDIUM] CVE-2018-3251: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2018-3133MEDIUMCVSS 6.5≥ 9.42018-10-17
CVE-2018-3133 [MEDIUM] CVE-2018-3133: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supporte Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.5.61 and prior, 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks
nvd
CVE-2018-3212MEDIUMCVSS 4.9≥ 7.3, ≤ 9.52018-10-17
CVE-2018-3212 [MEDIUM] CVE-2018-3212: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Information Schem Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Information Schema). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unautho
nvd
CVE-2018-3156MEDIUMCVSS 6.5≥ 9.4≥ 7.32018-10-17
CVE-2018-3156 [MEDIUM] CVE-2018-3156: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2018-3185MEDIUMCVSS 5.5≥ 9.4≥ 7.32018-10-17
CVE-2018-3185 [MEDIUM] CVE-2018-3185: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2018-3187MEDIUMCVSS 5.5≥ 9.4≥ 7.32018-10-17
CVE-2018-3187 [MEDIUM] CVE-2018-3187: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can resul
nvd
CVE-2018-3279MEDIUMCVSS 4.9≥ 9.4≥ 7.32018-10-17
CVE-2018-3279 [MEDIUM] CVE-2018-3279: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Roles). Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Roles). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2018-15473MEDIUMCVSS 5.3PoC≥ 9.42018-08-17
CVE-2018-15473 [MEDIUM] CWE-362 CVE-2018-15473: OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
nvd
CVE-2017-7657CRITICALCVSS 9.8fixed in 5.2.42018-06-26
CVE-2017-7657 [CRITICAL] CWE-444 CVE-2017-7657: In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default confi In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body
nvd
CVE-2017-7568MEDIUMCVSS 5.3fixed in 5.2.32018-06-22
CVE-2017-7568 [MEDIUM] CWE-200 CVE-2017-7568: NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sens NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account information to authenticated users when the LDAP authentication configuration is tested via the user interface.
nvd
CVE-2018-5487CRITICALCVSS 9.8≥ 7.2, ≤ 7.32018-05-24
CVE-2018-5487 [CRITICAL] CWE-20 CVE-2018-5487: NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Ex NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service bound to the network, and are susceptible to unauthenticated remote code execution.
nvd
CVE-2018-5485HIGHCVSS 7.8≥ 7.2, ≤ 7.32018-05-24
CVE-2018-5485 [HIGH] CVE-2018-5485: NetApp OnCommand Unified Manager for Windows versions 7.2 through 7.3 are susceptible to a vulnerabi NetApp OnCommand Unified Manager for Windows versions 7.2 through 7.3 are susceptible to a vulnerability which could lead to a privilege escalation attack.
nvd
CVE-2018-8014CRITICALCVSS 9.8≥ 9.4≥ 7.32018-05-16
CVE-2018-8014 [CRITICAL] CWE-1188 CVE-2018-8014: The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5. The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default conf
nvd
CVE-2018-11212MEDIUMCVSS 6.5≥ 7.3≥ 9.42018-05-16
CVE-2018-11212 [MEDIUM] CWE-369 CVE-2018-11212: An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote a An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
nvd
CVE-2018-1258HIGHCVSS 8.8≥ 7.3≥ 9.42018-05-11
CVE-2018-1258 [HIGH] CWE-863 CVE-2018-1258: Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contain Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
nvd