Netapp Oncommand Workflow Automation vulnerabilities
4 known vulnerabilities affecting netapp/oncommand_workflow_automation.
Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2019-5503MEDIUMCVSS 5.3v5.0vVersions prior to 5.02019-09-10
CVE-2019-5503 [MEDIUM] CWE-319 CVE-2019-5503: OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers co
OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.
cvelistv5nvd
CVE-2019-7317MEDIUMCVSS 5.3fixed in 5.12019-02-04
CVE-2019-7317 [MEDIUM] CWE-416 CVE-2019-7317: png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_fu
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
nvd
CVE-2016-1894HIGHCVSS 8.1≤ 3.12017-02-07
CVE-2016-1894 [HIGH] CWE-284 CVE-2016-1894: NetApp OnCommand Workflow Automation before 3.1P2 allows remote attackers to bypass authentication v
NetApp OnCommand Workflow Automation before 3.1P2 allows remote attackers to bypass authentication via unspecified vectors.
nvd
CVE-2015-3292CRITICALCVSS 10.0PoC≤ 2.2.1v3.02015-05-31
CVE-2015-3292 [CRITICAL] CWE-17 CVE-2015-3292: The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up th
The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.
nvd