Skip to main content

Vendor/product archive

netapp / oncommand_unified_manager CVEs

Beta · best-effort

167 CVEs tagged to netapp / oncommand_unified_manager25 Critical, 46 High, 85 Medium, 11 Low, 0 Unrated.

CVE-2020-8585

Published Jan 28, 2021

OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5443

Published Jul 2, 2019

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as a…

CVSS 7.8 · High

CVE-2019-5495

Published May 10, 2019

OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5494

Published May 10, 2019

OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0217

Published Apr 8, 2019

In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-2539

Published Jan 16, 2019

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulne…

CVSS 4.9 · Medium

CVE-2019-2537

Published Jan 16, 2019

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and…

CVSS 4.9 · Medium

CVE-2019-2536

Published Jan 16, 2019

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vuln…

CVSS 5.0 · Medium

CVE-2019-2535

Published Jan 16, 2019

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vulner…

CVSS 4.1 · Medium

CVE-2019-2534

Published Jan 16, 2019

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.…

CVSS 7.1 · High

CVE-2019-2533

Published Jan 16, 2019

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Security : Privileges). Supported versions that are affected are 8.0.13 and prior. Easily explo…

CVSS 6.5 · Medium

CVE-2019-2532

Published Jan 16, 2019

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and…

CVSS 4.9 · Medium

CVE-2019-2531

Published Jan 16, 2019

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.…

CVSS 4.9 · Medium
Showing 1-25 of 167 CVEsPage 1 of 7