Oncommand Unified Manager Core Package
oncommand_unified_manager_core_package
Vendor: Netapp • 11 CVEs
CVEs (11)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
8Beyondtrust DebianFedoraproject+5 more24Active Iq Unified Manager Cloud BackupCommunications Performance Intelligence Center+21 moreJun 17, 2026 Jan 26, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash...Show more |
4Apache DebianNetapp+1 more7Debian Linux Middleware Common Libraries And ToolsOncommand Unified Manager Core Package+4 moreJun 17, 2026 Jan 14, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBean...Show more |
5Debian FedoraprojectNetapp+2 more197 Mode Transition Tool Active Iq Unified ManagerDebian Linux+16 moreJun 17, 2026 Oct 21, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to ex...Show more |
7Canonical DebianFedoraproject+4 more237 Mode Transition Tool Active Iq Unified ManagerCloud Backup+20 moreJun 17, 2026 Jul 15, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable v...Show more |
3Fedoraproject NetappPutty3Fedora Oncommand Unified Manager Core PackagePuttyJun 17, 2026 Jun 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the...Show more |
8Apache BroadcomCanonical+5 more14Brocade Fabric Operating System Communications Element ManagerCommunications Session Report Manager+11 moreJun 17, 2026 Apr 2, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request U...Show more |
3Netapp OpensusePutty3Leap Oncommand Unified Manager Core PackagePuttyJun 17, 2026 Oct 1, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNECT message. |
13Canonical DebianF5+10 more82A220 Firmware A320 FirmwareA800 Firmware+79 moreJun 17, 2026 Feb 27, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte r...Show more |
5Debian NetappOpenbsd+2 more21Active Iq Unified Manager Cloud BackupClustered Data Ontap+18 moreMay 28, 2026 Oct 26, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files. |
1Netapp 1Oncommand Unified Manager Core Package May 13, 2026 May 26, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving error messages. |
1Netapp 1Oncommand Unified Manager Core Package May 13, 2026 May 26, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |