Oncommand Unified Manager
NetApp · 169 CVEs
OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthoriz…
Jan 28, 2021
OpenJDK: Race condition in NIO Buffer boundary checks (Libraries, 8244136)
Oct 21, 2020
OpenJDK: Missing maximum length check in WindowsNativeDispatcher.asNativeBuffer() (Libraries, 8242695)
Oct 21, 2020
OpenJDK: Incomplete check for invalid characters in URI to path conversion (Libraries, 8242685)
Oct 21, 2020
OpenJDK: Missing permission check in path to URI conversion (Libraries, 8242680)
Oct 21, 2020
OpenJDK: Integer overflow leading to out-of-bounds access (Hotspot, 8241114)
Oct 21, 2020
bash: when effective UID is not equal to its real UID the saved UID is not dropped
Nov 28, 2019
curl: heap buffer overflow in function tftp_receive_packet()
Sep 16, 2019
curl: Windows OpenSSL engine code injection
Jul 2, 2019
OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security head…
May 10, 2019
OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which…
May 10, 2019
httpd: privilege escalation from modules scripts
Apr 8, 2019
httpd: mod_auth_digest: access control bypass due to race condition
Apr 8, 2019
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
Mar 21, 2019
Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.
Mar 21, 2019
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
Mar 21, 2019
0-byte record padding oracle
Feb 27, 2019
mysql: Server: Connection unspecified vulnerability (CPU Jan 2019)
Jan 16, 2019
mysql: Server: DDL unspecified vulnerability (CPU Jan 2019)
Jan 16, 2019
mysql: Server: Packaging unspecified vulnerability (CPU Jan 2019)
Jan 16, 2019
mysql: Server: Options unspecified vulnerability (CPU Jan 2019)
Jan 16, 2019
mysql: Server: Replication unspecified vulnerability (CPU Jan 2019)
Jan 16, 2019
mysql: Server: Security: Privileges unspecified vulnerability (CPU Jan 2019)
Jan 16, 2019
mysql: Server: Security: Privileges unspecified vulnerability (CPU Jan 2019)
Jan 16, 2019
mysql: Server: Replication unspecified vulnerability (CPU Jan 2019)
Jan 16, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-8585 | OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plin… | MEDIUM | 0.41% | Jan 28, 2021 |
| CVE-2020-14803 | OpenJDK: Race condition in NIO Buffer boundary checks (Libraries, 8244136) | MEDIUM | 3.19% | Oct 21, 2020 |
| CVE-2020-14798 | OpenJDK: Missing maximum length check in WindowsNativeDispatcher.asNativeBuffer() (Libraries, 8242695) | LOW | 2.72% | Oct 21, 2020 |
| CVE-2020-14797 | OpenJDK: Incomplete check for invalid characters in URI to path conversion (Libraries, 8242685) | LOW | 2.20% | Oct 21, 2020 |
| CVE-2020-14796 | OpenJDK: Missing permission check in path to URI conversion (Libraries, 8242680) | LOW | 2.49% | Oct 21, 2020 |
| CVE-2020-14792 | OpenJDK: Integer overflow leading to out-of-bounds access (Hotspot, 8241114) | MEDIUM | 2.23% | Oct 21, 2020 |
| CVE-2019-18276 | bash: when effective UID is not equal to its real UID the saved UID is not dropped | HIGH | 2.61% | Nov 28, 2019 |
| CVE-2019-5482 | curl: heap buffer overflow in function tftp_receive_packet() | CRITICAL | 17.94% | Sep 16, 2019 |
| CVE-2019-5443 | curl: Windows OpenSSL engine code injection | HIGH | 0.69% | Jul 2, 2019 |
| CVE-2019-5495 | OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security headers configured which could allow an atta… | HIGH | 1.43% | May 10, 2019 |
| CVE-2019-5494 | OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensit… | HIGH | 0.70% | May 10, 2019 |
| CVE-2019-0211 KEV | httpd: privilege escalation from modules scripts | HIGH | 65.00% | Apr 8, 2019 |
| CVE-2019-0217 | httpd: mod_auth_digest: access control bypass due to race condition | HIGH | 17.43% | Apr 8, 2019 |
| CVE-2019-9898 | Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71. | CRITICAL | 3.94% | Mar 21, 2019 |
| CVE-2019-9897 | Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71. | HIGH | 2.94% | Mar 21, 2019 |
| CVE-2019-9894 | A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification. | HIGH | 2.45% | Mar 21, 2019 |
| CVE-2019-1559 | 0-byte record padding oracle | MEDIUM | 17.14% | Feb 27, 2019 |
| CVE-2019-2539 | mysql: Server: Connection unspecified vulnerability (CPU Jan 2019) | MEDIUM | 2.70% | Jan 16, 2019 |
| CVE-2019-2537 | mysql: Server: DDL unspecified vulnerability (CPU Jan 2019) | MEDIUM | 4.42% | Jan 16, 2019 |
| CVE-2019-2536 | mysql: Server: Packaging unspecified vulnerability (CPU Jan 2019) | MEDIUM | 0.41% | Jan 16, 2019 |
| CVE-2019-2535 | mysql: Server: Options unspecified vulnerability (CPU Jan 2019) | MEDIUM | 0.40% | Jan 16, 2019 |
| CVE-2019-2534 | mysql: Server: Replication unspecified vulnerability (CPU Jan 2019) | HIGH | 2.03% | Jan 16, 2019 |
| CVE-2019-2533 | mysql: Server: Security: Privileges unspecified vulnerability (CPU Jan 2019) | MEDIUM | 1.62% | Jan 16, 2019 |
| CVE-2019-2532 | mysql: Server: Security: Privileges unspecified vulnerability (CPU Jan 2019) | MEDIUM | 3.14% | Jan 16, 2019 |
| CVE-2019-2531 | mysql: Server: Replication unspecified vulnerability (CPU Jan 2019) | MEDIUM | 3.23% | Jan 16, 2019 |
Showing 1 to 25 of 169 CVEs