PT-2018-16987 · Netapp · Netapp Oncommand Unified Manager For Linux

Publicado

2018-05-24

·

Atualizado

2018-07-05

·

CVE-2018-5487

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3
Description The issue concerns the Java Management Extension Remote Method Invocation (JMX RMI) service, which is bound to the network in the affected versions, making them susceptible to unauthenticated remote code execution.
Recommendations For versions 7.2 through 7.3, consider disabling the JMX RMI service to prevent unauthenticated remote code execution until a patch is available.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-5487

Produtos afetados

Netapp Oncommand Unified Manager For Linux