CVE-2019-5494: High severity netapp oncommand unified manager for 7-mode vulnerability
Published May 10, 2019
·Updated
OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.
Affected Software
1 affected component
NetApp Oncommand Unified Manager 7-mode<5.2.4
Event History
May 10, 2019
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-5494?
CVE-2019-5494 has a medium severity rating due to the potential for information disclosure.
2
How do I fix CVE-2019-5494?
To fix CVE-2019-5494, upgrade OnCommand Unified Manager 7-Mode to version 5.2.4 or later.
3
What specific product versions are affected by CVE-2019-5494?
CVE-2019-5494 affects OnCommand Unified Manager 7-Mode versions prior to 5.2.4.
4
What are the potential impacts of CVE-2019-5494?
The potential impacts of CVE-2019-5494 include unauthorized access to sensitive information due to inadequate HTTP Security headers.
5
Is there a workaround for CVE-2019-5494 until I can update?
There is no documented workaround for CVE-2019-5494, so it is recommended to upgrade as soon as possible.