Information disclosure in OnCommand Unified Manager Core Package - CVE-2017-7439

 

Information disclosure in OnCommand Unified Manager Core Package - CVE-2017-7439

Published: May 26, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38942
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7439
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving error messages.


Affected software

OnCommand Unified Manager Core Package

How to mitigate CVE-2017-7439

Install update from vendor's website.


External References

Related Security Bulletins