VYPR
High severity7.5NVD Advisory· Published May 10, 2019· Updated Jun 17, 2026

CVE-2019-5495

CVE-2019-5495

Description

OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.

Affected products

5
  • cpe:2.3:a:netapp:oncommand_unified_manager:*:*:*:*:*:linux:*:*+ 2 more
    • cpe:2.3:a:netapp:oncommand_unified_manager:*:*:*:*:*:linux:*:*range: <9.5
    • cpe:2.3:a:netapp:oncommand_unified_manager:*:*:*:*:*:vmware_vsphere:*:*range: <9.5
    • cpe:2.3:a:netapp:oncommand_unified_manager:*:*:*:*:*:windows:*:*range: <9.5
  • NetApp/OnCommand Unified Manager for VMware vSphere,Linux and Windows 7.2 and abovev5
    Range: Versions prior to 9.5

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.