CVE-2018-5486

NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled which allows unauthorized local attackers to execute arbitrary code.
References
Link Resource
https://security.netapp.com/advisory/ntap-20180425-0001/ Mitigation Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:netapp:oncommand_unified_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-04-25 21:29

Updated : 2023-12-10 12:30


NVD link : CVE-2018-5486

Mitre link : CVE-2018-5486

CVE.ORG link : CVE-2018-5486


JSON object : View

Products Affected

netapp

  • oncommand_unified_manager

linux

  • linux_kernel
CWE
CWE-306

Missing Authentication for Critical Function