PT-2018-16987 · Netapp · Netapp Oncommand Unified Manager For Linux

Published

2018-05-24

·

Updated

2018-07-05

·

CVE-2018-5487

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3
Description The issue concerns the Java Management Extension Remote Method Invocation (JMX RMI) service, which is bound to the network in the affected versions, making them susceptible to unauthenticated remote code execution.
Recommendations For versions 7.2 through 7.3, consider disabling the JMX RMI service to prevent unauthenticated remote code execution until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5487

Affected Products

Netapp Oncommand Unified Manager For Linux