PT-2018-16986 · Netapp · Netapp Oncommand Unified Manager For Linux

Publicado

2018-04-25

·

Atualizado

2019-10-03

·

CVE-2018-5486

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3
Description The issue allows unauthorized local attackers to execute arbitrary code due to the Java Debug Wire Protocol (JDWP) being enabled.
Recommendations For versions 7.2 through 7.3, consider disabling the Java Debug Wire Protocol (JDWP) to prevent unauthorized local attackers from executing arbitrary code.

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-5486

Produtos afetados

Netapp Oncommand Unified Manager For Linux