CVE-2019-5495: High severity netapp oncommand unified manager vulnerability
OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the OnCommand Unified Manager for VMware vSphere Linux and Windows?
The vulnerability ID for the OnCommand Unified Manager for VMware vSphere Linux and Windows is CVE-2019-5495.
What is the severity level of CVE-2019-5495?
The severity level of CVE-2019-5495 is high with a score of 7.5.
How does CVE-2019-5495 impact the OnCommand Unified Manager for VMware vSphere Linux and Windows?
CVE-2019-5495 allows an attacker to obtain sensitive information via unspecified vectors by exploiting the lack of certain HTTP Security headers configured in the software.
Which version of OnCommand Unified Manager for VMware vSphere Linux and Windows is affected by CVE-2019-5495?
The versions prior to 9.5 of OnCommand Unified Manager for VMware vSphere Linux and Windows are affected by CVE-2019-5495.
How can I fix CVE-2019-5495 in OnCommand Unified Manager for VMware vSphere Linux and Windows?
To fix CVE-2019-5495 in OnCommand Unified Manager for VMware vSphere Linux and Windows, it is recommended to update to version 9.5 or later which includes the necessary HTTP Security headers configuration.