CVE-2018-5487

CRITICAL

NetApp OnCommand Unified Manager <7.4 - RCE

Title source: llm
STIX 2.1

Description

NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service bound to the network, and are susceptible to unauthenticated remote code execution.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180523-0001/

Scores

CVSS v3 9.8
EPSS 0.0236
EPSS Percentile 85.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
netapp/oncommand_unified_manager 7.2 - 7.3
Published May 24, 2018
Tracked Since Feb 18, 2026