CVE-2018-5481: Netapp Oncommand Unified Manager

High severity, CVSS 7.4. EPSS: 0.6% chance of exploitation in the next 30 days.

OnCommand Unified Manager for 7-Mode (core package) prior to 5.2.4 uses cookies that lack the secure attribute in certain circumstances making it vulnerable to impersonation via man-in-the-middle (MITM) attacks.

Affected products

  • Netapp Oncommand Unified Manager: before 5.2.4 (fixed in 5.2.4)

Published 2019-01-07. Last modified 2026-06-17.