First published: Fri May 26 2017(Updated: )
NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving error messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp OnCommand Unified Manager for Windows | =5.0 | |
NetApp OnCommand Unified Manager for Windows | =5.0.1 | |
NetApp OnCommand Unified Manager for Windows | =5.0.2 | |
NetApp OnCommand Unified Manager for Windows | =5.1 | |
NetApp OnCommand Unified Manager for Windows | =5.2 | |
NetApp OnCommand Unified Manager for Windows | =5.2.1 | |
NetApp OnCommand Unified Manager for Windows | =5.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7439 is classified as a medium severity vulnerability that may allow remote attackers to access sensitive information.
To fix CVE-2017-7439, upgrade to a patched version of NetApp OnCommand Unified Manager Core Package 5.2.2P1 or later.
CVE-2017-7439 affects versions 5.0, 5.0.1, 5.0.2, 5.1, 5.2, 5.2.1, and 5.2.2 of NetApp OnCommand Unified Manager Core Package.
CVE-2017-7439 may allow attackers to obtain sensitive information through error messages returned by the application.
No, CVE-2017-7439 is not a remote code execution vulnerability; it involves information disclosure in error messages.