CVE-2018-5487: Input Validation
Published May 24, 2018
·Updated
NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service bound to the network, and are susceptible to unauthenticated remote code execution.
Affected Software
4 affected components
NetApp OnCommand Unified Manager>=7.2<=7.3
Linux Linux kernel
All of the following
NetApp OnCommand Unified Manager>=7.2<=7.3
Linux Linux kernel
Event History
May 24, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Data Sourced
via NVD·02:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5487?
CVE-2018-5487 is classified as a critical vulnerability due to the potential for unauthenticated remote code execution.
2
How do I fix CVE-2018-5487?
To mitigate CVE-2018-5487, disable the JMX RMI service or apply patches provided by NetApp for affected versions.
3
Which versions of NetApp OnCommand Unified Manager are affected by CVE-2018-5487?
CVE-2018-5487 affects NetApp OnCommand Unified Manager versions 7.2 through 7.3.
4
What type of vulnerability is CVE-2018-5487?
CVE-2018-5487 is a remote code execution vulnerability arising from a misconfigured service.
5
Can CVE-2018-5487 be exploited remotely?
Yes, CVE-2018-5487 can be exploited remotely due to the JMX RMI service being exposed on the network.