CVE-2018-5486

NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled which allows unauthorized local attackers to execute arbitrary code.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:netapp:oncommand_unified_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:08

Type Values Removed Values Added
References () https://security.netapp.com/advisory/ntap-20180425-0001/ - Mitigation, Vendor Advisory () https://security.netapp.com/advisory/ntap-20180425-0001/ - Mitigation, Vendor Advisory

Information

Published : 2018-04-25 21:29

Updated : 2024-11-21 04:08


NVD link : CVE-2018-5486

Mitre link : CVE-2018-5486

CVE.ORG link : CVE-2018-5486


JSON object : View

Products Affected

netapp

  • oncommand_unified_manager

linux

  • linux_kernel
CWE
CWE-306

Missing Authentication for Critical Function