Netapp Oncommand Unified Manager vulnerabilities
124 known vulnerabilities affecting netapp/oncommand_unified_manager.
Total CVEs
124
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH25MEDIUM74LOW7
Vulnerabilities
Page 3 of 7
CVE-2018-3280MEDIUMCVSS 4.9≥ 9.4≥ 7.32018-10-17
CVE-2018-3280 [MEDIUM] CVE-2018-3280: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: JSON). Supported
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: JSON). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2018-3283MEDIUMCVSS 4.4≥ 9.4≥ 7.32018-10-17
CVE-2018-3283 [MEDIUM] CVE-2018-3283: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Logging). Support
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Logging). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can resul
nvd
CVE-2018-3143MEDIUMCVSS 6.5≥ 9.4≥ 7.32018-10-17
CVE-2018-3143 [MEDIUM] CVE-2018-3143: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2018-3276MEDIUMCVSS 4.9≥ 9.4≥ 7.32018-10-17
CVE-2018-3276 [MEDIUM] CVE-2018-3276: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulne
nvd
CVE-2018-3145MEDIUMCVSS 6.5≥ 7.3, ≤ 9.52018-10-17
CVE-2018-3145 [MEDIUM] CVE-2018-3145: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supporte
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2018-3251MEDIUMCVSS 6.5≥ 9.4≥ 7.32018-10-17
CVE-2018-3251 [MEDIUM] CVE-2018-3251: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2018-3133MEDIUMCVSS 6.5≥ 9.42018-10-17
CVE-2018-3133 [MEDIUM] CVE-2018-3133: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supporte
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.5.61 and prior, 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks
nvd
CVE-2018-3212MEDIUMCVSS 4.9≥ 7.3, ≤ 9.52018-10-17
CVE-2018-3212 [MEDIUM] CVE-2018-3212: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Information Schem
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Information Schema). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unautho
nvd
CVE-2018-3156MEDIUMCVSS 6.5≥ 9.4≥ 7.32018-10-17
CVE-2018-3156 [MEDIUM] CVE-2018-3156: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2018-3185MEDIUMCVSS 5.5≥ 9.4≥ 7.32018-10-17
CVE-2018-3185 [MEDIUM] CVE-2018-3185: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2018-3187MEDIUMCVSS 5.5≥ 9.4≥ 7.32018-10-17
CVE-2018-3187 [MEDIUM] CVE-2018-3187: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can resul
nvd
CVE-2018-3279MEDIUMCVSS 4.9≥ 9.4≥ 7.32018-10-17
CVE-2018-3279 [MEDIUM] CVE-2018-3279: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Roles).
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Roles). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2018-15473MEDIUMCVSS 5.3PoC≥ 9.42018-08-17
CVE-2018-15473 [MEDIUM] CWE-362 CVE-2018-15473: OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
nvd
CVE-2017-7657CRITICALCVSS 9.8fixed in 5.2.42018-06-26
CVE-2017-7657 [CRITICAL] CWE-444 CVE-2017-7657: In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default confi
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body
nvd
CVE-2017-7568MEDIUMCVSS 5.3fixed in 5.2.32018-06-22
CVE-2017-7568 [MEDIUM] CWE-200 CVE-2017-7568: NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sens
NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account information to authenticated users when the LDAP authentication configuration is tested via the user interface.
nvd
CVE-2018-5487CRITICALCVSS 9.8≥ 7.2, ≤ 7.32018-05-24
CVE-2018-5487 [CRITICAL] CWE-20 CVE-2018-5487: NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Ex
NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service bound to the network, and are susceptible to unauthenticated remote code execution.
nvd
CVE-2018-5485HIGHCVSS 7.8≥ 7.2, ≤ 7.32018-05-24
CVE-2018-5485 [HIGH] CVE-2018-5485: NetApp OnCommand Unified Manager for Windows versions 7.2 through 7.3 are susceptible to a vulnerabi
NetApp OnCommand Unified Manager for Windows versions 7.2 through 7.3 are susceptible to a vulnerability which could lead to a privilege escalation attack.
nvd
CVE-2018-8014CRITICALCVSS 9.8≥ 9.4≥ 7.32018-05-16
CVE-2018-8014 [CRITICAL] CWE-1188 CVE-2018-8014: The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default conf
nvd
CVE-2018-11212MEDIUMCVSS 6.5≥ 7.3≥ 9.42018-05-16
CVE-2018-11212 [MEDIUM] CWE-369 CVE-2018-11212: An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote a
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
nvd
CVE-2018-1258HIGHCVSS 8.8≥ 7.3≥ 9.42018-05-11
CVE-2018-1258 [HIGH] CWE-863 CVE-2018-1258: Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contain
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
nvd