CVE-2018-5486

HIGH

NetApp OnCommand Unified Manager <7.4 - RCE

Title source: llm
STIX 2.1

Description

NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled which allows unauthorized local attackers to execute arbitrary code.

References (1)

Core 1
Core References
Mitigation, Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180425-0001/

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 28.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (1)
netapp/oncommand_unified_manager 7.2 - 7.3
Published Apr 25, 2018
Tracked Since Feb 18, 2026