cbcvebase.

Netapp Oncommand Unified Manager vulnerabilities

124 known vulnerabilities affecting netapp/oncommand_unified_manager.

Total CVEs
124
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH25MEDIUM74LOW7

Vulnerabilities

Page 6 of 7
CVE-2018-3212P4MEDIUMCVSS 4.9≥ 7.3, ≤ 9.52018-10-17
CVE-2018-3212 [MEDIUM] CVE-2018-3212: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Information Schem Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Information Schema). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unautho
nvd
CVE-2018-3285P4MEDIUMCVSS 4.9≥ 9.4≥ 7.32018-10-17
CVE-2018-3285 [MEDIUM] CVE-2018-3285: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Windows). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Windows). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abili
nvd
CVE-2018-3186P4MEDIUMCVSS 4.9≥ 7.3≥ 9.42018-10-17
CVE-2018-3186 [MEDIUM] CVE-2018-3186: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abi
nvd
CVE-2018-3170P4MEDIUMCVSS 4.9≥ 9.4≥ 7.32018-10-17
CVE-2018-3170 [MEDIUM] CVE-2018-3170: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2018-3280P4MEDIUMCVSS 4.9≥ 9.4≥ 7.32018-10-17
CVE-2018-3280 [MEDIUM] CVE-2018-3280: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: JSON). Supported Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: JSON). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2018-3279P4MEDIUMCVSS 4.9≥ 9.4≥ 7.32018-10-17
CVE-2018-3279 [MEDIUM] CVE-2018-3279: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Roles). Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Roles). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2017-10320P4MEDIUMCVSS 4.9≤ 7.12017-10-19
CVE-2017-10320 [MEDIUM] CVE-2017-10320: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supporte Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are affected are 5.7.19 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ab
nvd
CVE-2017-10081P4MEDIUMCVSS 4.3≤ 7.12017-08-08
CVE-2017-10081 [MEDIUM] CVE-2017-10081: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful a
nvd
CVE-2017-10105P4MEDIUMCVSS 4.3≤ 7.12017-08-08
CVE-2017-10105 [MEDIUM] CVE-2017-10105: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versi Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than
nvd
CVE-2018-3286P4MEDIUMCVSS 4.3≥ 9.4≥ 7.32018-10-17
CVE-2018-3286 [MEDIUM] CVE-2018-3286: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privile Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2017-10295P4MEDIUMCVSS 4.0≤ 7.12017-10-19
CVE-2017-10295 [MEDIUM] CVE-2017-10295: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: N Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Java SE, Java SE
nvd
CVE-2017-11461P4MEDIUMCVSS 4.3fixed in 5.2.1vprior to 5.2.12017-11-10
CVE-2017-11461 [MEDIUM] CWE-20 CVE-2017-11461: NetApp OnCommand Unified Manager for 7-mode (core package) versions prior to 5.2.1 are susceptible t NetApp OnCommand Unified Manager for 7-mode (core package) versions prior to 5.2.1 are susceptible to a clickjacking or "UI redress attack" which could be used to cause a user to perform an unintended action in the user interface.
nvd
CVE-2018-3283P4MEDIUMCVSS 4.4≥ 9.4≥ 7.32018-10-17
CVE-2018-3283 [MEDIUM] CVE-2018-3283: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Logging). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Logging). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can resul
nvd
CVE-2017-10286P4MEDIUMCVSS 4.4≤ 7.12017-10-19
CVE-2017-10286 [MEDIUM] CVE-2017-10286: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supporte Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are affected are 5.6.37 and earlier and 5.7.19 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2017-10268P4MEDIUMCVSS 4.1≤ 7.12017-10-19
CVE-2017-10268 [MEDIUM] CVE-2017-10268: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Su
nvd
CVE-2019-2426P4LOWCVSS 3.7≥ 7.3≥ 9.42019-01-16
CVE-2019-2426 [LOW] CVE-2019-2426: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Networking). Supported versi Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can r
nvd
CVE-2019-2536P4MEDIUMCVSS 5.0≥ 7.3, ≤ 9.52019-01-16
CVE-2019-2536 [MEDIUM] CVE-2019-2536: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a
nvd
CVE-2019-2422P4LOWCVSS 3.1≥ 7.3≥ 9.42019-01-16
CVE-2019-2422 [LOW] CVE-2019-2422: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versio Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction fr
nvd
CVE-2017-10365P4LOWCVSS 3.8≤ 7.12017-10-19
CVE-2017-10365 [LOW] CVE-2017-10365: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supporte Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are affected are 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized updat
nvd
CVE-2017-10193P4LOWCVSS 3.1≤ 7.12017-08-08
CVE-2017-10193 [LOW] CVE-2017-10193: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
Netapp Oncommand Unified Manager vulnerabilities | cvebase