The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CNetapp Oncommand Workflow Automation
APPNetapp3.0≤ 2.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX
CVE-2024-28752CRITICAL9.3PL ✓same product
SSRF w Apache CXF przez Aegis DataBinding — ataki na usługi webowe
CVE-2023-38545CRITICAL9.8PL ✓same product
Heap buffer overflow w libcurl podczas handshake z proxy SOCKS5
CVE-2022-37434CRITICAL9.8PL ✓same product
Buffer overflow w zlib podczas przetwarzania nagłówka gzip (inflate)
CVE-2022-23852CRITICAL9.8PL ✓same product
Przepełnienie liczby całkowitej w Libexpat (XML_GetBuffer) — CVE-2022-23852