Netapp

Oncommand Unified Manager

169 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.61%
  • Published 18.07.2018 13:29:02
  • Last modified 21.11.2024 04:04:48

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported versions that are affected are Java SE: 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multip...

  • EPSS 0.06%
  • Published 18.07.2018 13:29:02
  • Last modified 21.11.2024 04:04:49

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171; JRockit: R28.3.18. Difficult t...

  • EPSS 7.64%
  • Published 26.06.2018 16:29:00
  • Last modified 21.11.2024 03:32:23

In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow...

  • EPSS 0.43%
  • Published 22.06.2018 19:29:00
  • Last modified 21.11.2024 03:45:23

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatche...

  • EPSS 1.45%
  • Published 22.06.2018 15:29:00
  • Last modified 21.11.2024 03:32:11

NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account information to authenticated users when the LDAP authentication configuration is tested via the user interface.

  • EPSS 0.17%
  • Published 24.05.2018 14:29:00
  • Last modified 21.11.2024 04:08:53

NetApp OnCommand Unified Manager for Windows versions 7.2 through 7.3 are susceptible to a vulnerability which could lead to a privilege escalation attack.

  • EPSS 2.49%
  • Published 24.05.2018 14:29:00
  • Last modified 21.11.2024 04:08:53

NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service bound to the network, and are susceptible to unauthenticated remote code execution.

Exploit
  • EPSS 0.73%
  • Published 16.05.2018 17:29:00
  • Last modified 21.11.2024 03:42:54

An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.

  • EPSS 53.05%
  • Published 16.05.2018 16:29:00
  • Last modified 21.11.2024 04:13:05

The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter ...

  • EPSS 0.16%
  • Published 11.05.2018 20:29:00
  • Last modified 21.11.2024 03:59:28

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted...