CVE-2019-5503

MEDIUM

NetApp OnCommand Workflow Automation - Cleartext Transmission of Sensitive Information

Title source: llm
STIX 2.1

Description

OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190909-0001/

Scores

CVSS v3 5.3
EPSS 0.0050
EPSS Percentile 66.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-319
Status published
Products (1)
netapp/oncommand_workflow_automation 5.0
Published Sep 10, 2019
Tracked Since Feb 18, 2026