← Vulnerability feed

Vulnerability record · CVE-2017-7439 · published 26 May 2017

CVE-2017-7439: Netapp oncommand unified manager core package information exposure vulnerability

NNetapp · Oncommand Unified Manager Core Package

NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving error messages.

7.5 CVSS 3.0 High EPSS 1.9% · top 21.4% CWE-200 · Information exposure
7.5CVSS 3.0 base score, v2 5.0
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving error messages.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-7439 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2021-3156Sudo off-by-one heap overflow allows root privilege escalationSudo before 1.9.5p2 contains an off-by-one error leading to a heap-based buffer overflow. Triggering it via 'sudoedit -s' with a command-line argumen…KEVEPSS 100%analysed9.1CVE-2021-23926Apache xmlbeans vulnerabilityThe XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities …EPSS 6.2%7.5CVE-2019-17069Putty use after free vulnerabilityPuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNECT messag…EPSS 2.2%7.5CVE-2017-7236Netapp oncommand unified manager core package sql injection vulnerabilitySQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL comm…EPSS 1.8%6.1CVE-2020-1927Apache HTTP Server mod_rewrite encoded newline open redirectApache HTTP Server 2.4.0 through 2.4.41 mishandles redirects configured with mod_rewrite that were meant to be self-referential; encoded newlines can…EPSS 57%analysed5.9CVE-2020-14002Putty observable discrepancy vulnerabilityPuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle atta…EPSS 3.1%5.9CVE-2019-1559Openssl observable discrepancy vulnerabilityIf an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then O…EPSS 17%5.3CVE-2020-14621Oracle openjdk vulnerabilityVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, …EPSS 4.4%

Source: NIST National Vulnerability Database (record CVE-2017-7439), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.