Impersonation Vulnerability in OnCommand Unified Manager by NetApp
CVE-2018-5481
7.4HIGH
Summary
The OnCommand Unified Manager for 7-Mode, specifically the core package versions prior to 5.2.4, suffers from a vulnerability where cookies lack the secure attribute in certain scenarios. This oversight allows attackers to potentially exploit the system through man-in-the-middle (MITM) attacks, enabling impersonation of legitimate users. It is crucial for users and administrators to understand the implications of this vulnerability and take necessary steps to mitigate risks by applying appropriate updates and configurations.
Affected Version(s)
OnCommand Unified Manager for 7-Mode (core package) Versions prior to 5.2.4
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved