CVE-2019-5494OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.
CWE-319
No public exploit
Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in 7 years.
CVSS E:U
A genuine Java vulnerability in a supported product that the agent cannot reach: a coverage gap, not an out-of-domain finding.
| Decided by | non-deployable-product : The only affected product being a sealed appliance image, where Java runs but no -javaagent can be attached |
|---|---|
| Finding | This CVE names only products the Waratek agent cannot be installed into (netapp/oncommand_unified_manager). They ship as sealed appliance images or as native code with no application JVM, so there is no start-up line to add -javaagent to. The vulnerability may well be a Java one; it is permanently out of ARMR's reach rather than outside its subject. |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
2 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.0 | 7.5 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
NVD | Primary | published |
| CVSS 2.0 | 5.0 | no band published | AV:N/AC:L/Au:N/C:P/I:N/A:N |
NVD | Primary |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | netapp | oncommand unified manager | generic | < 5.2.4 |
| URL | Tags |
|---|---|
| https://security.netapp.com/advisory/ntap-20190509-0006/ | Vendor Advisory |
| Published | 2019-05-10 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |