Latest netapp oncommand unified manager Vulnerabilities

OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).
Netapp Oncommand Unified Manager<5.2.5
An unspecified vulnerability in Java SE related to the Libraries component could allow an unauthenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.
debian/openjdk-11
debian/openjdk-8
IBM Cloud Pak for Automation<=20.0.3-IF002
IBM Cloud Pak for Automation<=21.0.1
Oracle JDK=1.7.0-update271
Oracle JDK=1.8.0-update261
and 21 more
An unspecified vulnerability in Java SE related to the Libraries component could allow an unauthenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unkno...
redhat/java<1.8.0-openjdk-1:1.8.0.272.b10-0.el6_10
redhat/java<11-openjdk-1:11.0.9.11-0.el7_9
redhat/java<1.8.0-openjdk-1:1.8.0.272.b10-1.el7_9
redhat/java<1.8.0-ibm-1:1.8.0.6.20-1jpp.1.el7
redhat/java<1.7.1-ibm-1:1.7.1.4.75-1jpp.1.el7
redhat/java<11-openjdk-1:11.0.9.11-0.el8_2
and 33 more
An unspecified vulnerability in Java SE related to the Libraries component could allow an unauthenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.
redhat/java<1.8.0-openjdk-1:1.8.0.272.b10-0.el6_10
redhat/java<11-openjdk-1:11.0.9.11-0.el7_9
redhat/java<1.8.0-openjdk-1:1.8.0.272.b10-1.el7_9
redhat/java<1.8.0-ibm-1:1.8.0.6.20-1jpp.1.el7
redhat/java<1.7.1-ibm-1:1.7.1.4.75-1jpp.1.el7
redhat/java<11-openjdk-1:11.0.9.11-0.el8_2
and 33 more
An unspecified vulnerability in Java SE could allow an unauthenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors.
redhat/java<1.8.0-openjdk-1:1.8.0.272.b10-0.el6_10
redhat/java<11-openjdk-1:11.0.9.11-0.el7_9
redhat/java<1.8.0-openjdk-1:1.8.0.272.b10-1.el7_9
redhat/java<1.8.0-ibm-1:1.8.0.6.25-1jpp.1.el7
redhat/java<1.7.1-ibm-1:1.7.1.4.80-1jpp.1.el7
redhat/java<11-openjdk-1:11.0.9.11-0.el8_2
and 38 more
An unspecified vulnerability in Java SE related to the Hotspot component could allow an unauthenticated attacker to cause low confidentiality impact, low integrity impact, and no availability impact.
redhat/java<1.8.0-openjdk-1:1.8.0.272.b10-0.el6_10
redhat/java<11-openjdk-1:11.0.9.11-0.el7_9
redhat/java<1.8.0-openjdk-1:1.8.0.272.b10-1.el7_9
redhat/java<11-openjdk-1:11.0.9.11-0.el8_2
redhat/java<1.8.0-openjdk-1:1.8.0.272.b10-1.el8_2
redhat/java<11-openjdk-1:11.0.9.11-0.el8_0
and 39 more
Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.
debian/putty
Putty Putty<0.71
Fedoraproject Fedora=28
Fedoraproject Fedora=29
Debian Debian Linux=8.0
Debian Debian Linux=9.0
and 2 more
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
debian/putty
Putty Putty<0.71
Fedoraproject Fedora=28
Fedoraproject Fedora=29
Debian Debian Linux=8.0
Debian Debian Linux=9.0
and 2 more
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
debian/putty
Putty Putty<0.71
Fedoraproject Fedora=28
Fedoraproject Fedora=29
Debian Debian Linux=8.0
Debian Debian Linux=9.0
and 2 more
OpenSSL could allow a remote attacker to obtain sensitive information, caused by the failure to immediately close the TCP connection after the hosts encounter a zero-length record with valid padding. ...
redhat/openssl<0:1.0.1e-58.el6_10
redhat/openssl<1:1.0.2k-19.el7
redhat/jws5-ecj<0:4.12.0-1.redhat_1.1.el6
redhat/jws5-javapackages-tools<0:3.4.1-5.15.11.el6
redhat/jws5-jboss-logging<0:3.3.2-1.Final_redhat_00001.1.el6
redhat/jws5-tomcat<0:9.0.21-10.redhat_4.1.el6
and 226 more
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to ex...
Oracle JDK=1.7.0-update201
Oracle JDK=1.8.0-update191
Oracle JDK=1.8.0-update192
Oracle JDK=11.0.1
Oracle JRE=1.7.0-update201
Oracle JRE=1.8.0-update191
and 10 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged a...
redhat/mysql<8.0.14
Oracle MySQL>=8.0.0<=8.0.13
Netapp Oncommand Unified Manager>=7.3
Microsoft Windows
NetApp OnCommand Insight
Netapp Oncommand Unified Manager Vmware Vsphere>=9.4
and 2 more
Oracle Java SE 8u201 fixes an unspecified vulnerability in the Deployment component (<a href="https://access.redhat.com/security/cve/CVE-2019-2449">CVE-2019-2449</a>). Upstream has CVSS scored this i...
redhat/java<1.8.0-ibm-1:1.8.0.5.30-1jpp.1.el6_10
redhat/java<1.8.0-ibm-1:1.8.0.5.30-1jpp.1.el7
redhat/java<1.8.0-ibm-1:1.8.0.5.35-3.el8_0
Oracle JDK=1.8.0-update192
Oracle JRE=1.8.0-update192
Redhat Satellite=5.8
and 14 more
A memory disclosure flaw was found in the FileChannelImpl class in the Libraries component of OpenJDK. An untrusted Java application or applet could use this flaw leak limited amount of Java Virtual ...
ubuntu/openjdk-7<7
ubuntu/openjdk-8<8
ubuntu/openjdk-8<8
ubuntu/openjdk-8<8
ubuntu/openjdk-8<8
ubuntu/openjdk-lts<11.0.2+9-3ubuntu1~18.04.3
and 44 more
OnCommand Unified Manager for 7-Mode (core package) prior to 5.2.4 uses cookies that lack the secure attribute in certain circumstances making it vulnerable to impersonation via man-in-the-middle (MIT...
Netapp Oncommand Unified Manager<5.2.4
A flaw was found in OpenSSL versions from 1.1.0 through 1.1.0i inclusive and version 1.1.1. The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An at...
redhat/openssl<1:1.0.2k-16.el7_6.1
redhat/openssl<1:1.1.1c-2.el8
ubuntu/openssl<1.1.0
ubuntu/openssl<1.1.1-1ubuntu2.1
ubuntu/openssl<1.1.1
ubuntu/openssl<1.1.1
and 55 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: JSON). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privil...
Oracle MySQL>=8.0.0<=8.0.12
NetApp OnCommand Insight
Netapp Oncommand Unified Manager Vmware Vsphere>=9.4
NetApp OnCommand Workflow Automation
Netapp Snapcenter
Netapp Storage Automation Store
and 2 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability al...
Oracle MySQL>=8.0.0<=8.0.12
NetApp OnCommand Insight
Netapp Oncommand Unified Manager Vmware Vsphere>=9.4
NetApp OnCommand Workflow Automation
Netapp Snapcenter
Netapp Storage Automation Store
and 2 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Windows). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high pri...
Oracle MySQL>=8.0.0<=8.0.12
NetApp OnCommand Insight
Netapp Oncommand Unified Manager Vmware Vsphere>=9.4
NetApp OnCommand Workflow Automation
Netapp Snapcenter
Netapp Storage Automation Store
and 2 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Roles). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows ...
Oracle MySQL>=8.0.0<=8.0.12
NetApp OnCommand Insight
Netapp Oncommand Unified Manager Vmware Vsphere>=9.4
NetApp OnCommand Workflow Automation
Netapp Snapcenter
Netapp Storage Automation Store
and 2 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privile...
Oracle MySQL>=8.0.0<=8.0.12
Netapp Oncommand Unified Manager>=7.3
Microsoft Windows
NetApp OnCommand Insight
Netapp Oncommand Unified Manager Vmware Vsphere>=9.4
NetApp OnCommand Workflow Automation
and 1 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileg...
Oracle MySQL>=8.0.0<=8.0.12
Netapp Oncommand Unified Manager>=7.3
Microsoft Windows
NetApp OnCommand Insight
Netapp Oncommand Unified Manager Vmware Vsphere>=9.4
NetApp OnCommand Workflow Automation
and 1 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high p...
Oracle MySQL>=8.0.0<=8.0.12
Netapp Oncommand Unified Manager>=7.3
Microsoft Windows
NetApp OnCommand Insight
Netapp Oncommand Unified Manager Vmware Vsphere>=9.4
NetApp OnCommand Workflow Automation
and 1 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privile...
Oracle MySQL>=8.0.0<=8.0.12
NetApp OnCommand Insight
Netapp Oncommand Unified Manager Vmware Vsphere>=9.4
NetApp OnCommand Workflow Automation
Netapp Snapcenter
Netapp Oncommand Unified Manager>=7.3
and 1 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low pr...
Oracle MySQL>=8.0.0<=8.0.12
NetApp OnCommand Insight
Netapp Oncommand Unified Manager Vmware Vsphere>=9.4
NetApp OnCommand Workflow Automation
Netapp Snapcenter
Netapp Storage Automation Store
and 2 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerabi...
redhat/mysql<5.7.24
redhat/mysql<8.0.13
debian/mysql-5.5
debian/mysql-5.7
ubuntu/mysql-5.7<5.7.24-0ubuntu0.18.04.1
ubuntu/mysql-5.7<5.7.24-0ubuntu0.18.10.1
and 18 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable...
debian/mariadb-10.0
debian/mysql-5.5
debian/mysql-5.7
redhat/mysql<5.6.42
redhat/mysql<5.7.24
redhat/mysql<8.0.13
and 37 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: RBR). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploi...
debian/mysql-5.5
debian/mysql-5.7
redhat/mysql<5.6.42
redhat/mysql<5.7.24
redhat/mysql<8.0.13
ubuntu/mysql-5.6<5.6.42
and 21 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Audit). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploi...
debian/mysql-5.5
debian/mysql-5.7
redhat/mysql<5.7.24
redhat/mysql<8.0.13
ubuntu/mysql-5.7<5.7.24-0ubuntu0.18.04.1
ubuntu/mysql-5.7<5.7.24-0ubuntu0.18.10.1
and 18 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable...
debian/mariadb-10.0
debian/mysql-5.5
debian/mysql-5.7
redhat/mysql<5.6.42
redhat/mysql<5.7.24
redhat/mysql<8.0.13
and 37 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability all...
debian/mysql-5.5
debian/mysql-5.7
redhat/mysql<5.7.24
redhat/mysql<8.0.13
redhat/mariadb<10.3.11
redhat/mariadb<10.2.19
and 22 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulner...
redhat/mysql<5.7.24
redhat/mysql<8.0.13
debian/mysql-5.5
debian/mysql-5.7
ubuntu/mysql-5.7<5.7.24-0ubuntu0.18.04.1
ubuntu/mysql-5.7<5.7.24-0ubuntu0.18.10.1
and 18 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Merge). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily expl...
debian/mysql-5.5
debian/mysql-5.7
redhat/mysql<5.6.42
redhat/mysql<5.7.24
redhat/mysql<8.0.13
ubuntu/mysql-5.6<5.6.42
and 21 more
A flaw was found in OpenSSL versions from 1.1.0 through 1.1.0i inclusive, from 1.0.2 through 1.0.2p inclusive and version 1.1.1. The OpenSSL DSA signature algorithm has been shown to be vulnerable to ...
redhat/jbcs-httpd24-apr<0:1.6.3-63.jbcs.el6
redhat/jbcs-httpd24-apr-util<0:1.6.1-48.jbcs.el6
redhat/jbcs-httpd24-brotli<0:1.0.6-7.jbcs.el6
redhat/jbcs-httpd24-curl<0:7.64.1-14.jbcs.el6
redhat/jbcs-httpd24-httpd<0:2.4.37-33.jbcs.el6
redhat/jbcs-httpd24-jansson<0:2.11-20.jbcs.el6
and 74 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable...
redhat/mysql<5.6.42
redhat/mysql<5.7.24
redhat/mysql<8.0.13
redhat/mariadb<10.3.11
redhat/mariadb<10.2.19
redhat/mariadb<10.1.37
and 37 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Logging). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulner...
debian/mysql-5.5
debian/mysql-5.7
redhat/mysql<5.7.24
redhat/mysql<8.0.13
ubuntu/mysql-5.7<5.7.24-0ubuntu0.18.04.1
ubuntu/mysql-5.7<5.7.24-0ubuntu0.18.10.1
and 18 more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily ...
debian/mysql-5.5
debian/mysql-5.7
redhat/mysql<5.6.42
redhat/mysql<5.7.24
redhat/mysql<8.0.13
ubuntu/mysql-5.6<5.6.42
and 21 more
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows un...
Oracle JDK=1.6.0-update191
Oracle JDK=1.7.0-update181
Oracle JDK=1.8.0-update172
Oracle JRE=1.6.0-update191
Oracle JRE=1.7.0-update181
Oracle JRE=1.8.0-update172
and 15 more
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported versions that are affected are Java SE: 7u181 and 8u172. Difficult to exploit vulnerability allows unaut...
Oracle JDK=1.7.0-update181
Oracle JDK=1.8.0-update172
Oracle JRE=1.7.0-update181
Oracle JRE=1.8.0-update172
Netapp Active Iq Unified Manager Vmware Vsphere
Netapp Active Iq Unified Manager Windows
and 13 more
Oracle Java SE 7u191, 8u181, and 10.0.2 fixes an unspecified vulnerability in the JavaFX component (<a href="https://access.redhat.com/security/cve/CVE-2018-2941">CVE-2018-2941</a>). Upstream has CVS...
redhat/java<1.7.0-oracle-1:1.7.0.191-1jpp.1.el6
redhat/java<1.8.0-oracle-1:1.8.0.181-1jpp.2.el6
redhat/java<1.8.0-oracle-1:1.8.0.181-1jpp.2.el7
redhat/java<1.7.0-oracle-1:1.7.0.191-1jpp.2.el7
Oracle JDK=1.7.0-update181
Oracle JDK=1.8.0-update172
and 19 more
Oracle Java SE 6u201, 7u191, 8u181, and 10.0.2 fixes an unspecified vulnerability in the Libraries component (<a href="https://access.redhat.com/security/cve/CVE-2018-2940">CVE-2018-2940</a>). Upstre...
redhat/java<1.7.0-oracle-1:1.7.0.191-1jpp.1.el6
redhat/java<1.8.0-oracle-1:1.8.0.181-1jpp.2.el6
redhat/java<1.6.0-sun-1:1.6.0.211-1jpp.1.el6
redhat/java<1.8.0-oracle-1:1.8.0.181-1jpp.2.el7
redhat/java<1.7.0-oracle-1:1.7.0.191-1jpp.2.el7
redhat/java<1.6.0-sun-1:1.6.0.211-1jpp.1.el7
and 37 more
Oracle Java SE 6u201, 7u191, 8u181, and 10.0.2 fixes an unspecified vulnerability in the JSSE component (<a href="https://access.redhat.com/security/cve/CVE-2018-2973">CVE-2018-2973</a>). Upstream ha...
redhat/java<1.7.0-oracle-1:1.7.0.191-1jpp.1.el6
redhat/java<1.8.0-oracle-1:1.8.0.181-1jpp.2.el6
redhat/java<1.6.0-sun-1:1.6.0.211-1jpp.1.el6
redhat/java<1.8.0-oracle-1:1.8.0.181-1jpp.2.el7
redhat/java<1.7.0-oracle-1:1.7.0.191-1jpp.2.el7
redhat/java<1.6.0-sun-1:1.6.0.211-1jpp.1.el7
and 38 more
Oracle Java SE 8u181 and 10.0.2 fixes an unspecified vulnerability in the Deployment component (<a href="https://access.redhat.com/security/cve/CVE-2018-2964">CVE-2018-2964</a>). Upstream has CVSS sc...
redhat/java<1.8.0-oracle-1:1.8.0.181-1jpp.2.el6
redhat/java<1.8.0-oracle-1:1.8.0.181-1jpp.2.el7
Oracle JDK=1.8.0-update172
Oracle JDK=10.0.1
Oracle JRE=1.8.0-update172
Oracle JRE=10.0.1
and 16 more
It was discovered that the implementation of the PatternSyntaxException class in the Concurrency component of OpenJDK failed to sufficiently validate the 'index' value (to ensure it's not greater than...
ubuntu/openjdk-7<7
ubuntu/openjdk-7<7
ubuntu/openjdk-8<8
ubuntu/openjdk-8<8
ubuntu/openjdk-8<8
ubuntu/openjdk-lts<10.0.2+13-1ubuntu0.18.04.1
and 55 more
Eclipse Jetty is vulnerable to HTTP request smuggling, caused by improper handling of Chunked Transfer-Encoding chunk size. By sending a specially-crafted request, an attacker could exploit this vulne...
debian/jetty9
IBM Cognos Command Center<=10.2.4.1
redhat/jetty<9.3.24.
redhat/jetty<9.4.11.
Eclipse Jetty<=9.2.26
Eclipse Jetty>=9.3.0<9.3.24
and 25 more
In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/...
Eclipse Jetty>=9.4.0<=9.4.8
Netapp E-series Santricity Management Plug-ins
NetApp E-Series SANtricity OS Controller>=11.0<=11.40
Netapp E-series Santricity Web Services Proxy
Netapp Element Software
Netapp Hyper Converged Infrastructure
and 6 more
NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account information to authenticated users when the LDAP authentication configuration is ...
NetApp OnCommand Unified Manager<5.2.3
NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service bound to the network, and are susceptible to unau...
Netapp Oncommand Unified Manager>=7.2<=7.3
Linux Linux kernel
NetApp OnCommand Unified Manager for Windows versions 7.2 through 7.3 are susceptible to a vulnerability which could lead to a privilege escalation attack.
Netapp Oncommand Unified Manager>=7.2<=7.3
Microsoft Windows

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203