CVE-2018-5486

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
25/04/2018
Last modified:
03/10/2019

Description

NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled which allows unauthorized local attackers to execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netapp:oncommand_unified_manager:*:*:*:*:*:*:*:* 7.2 (including) 7.3 (including)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools