Oncommand Unified Manager

Vendor:

First CVE: Aug 5, 2010 · Active for 15 years

169
Total CVEs
More Total CVEs than 99% of tracked products
24.1
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
1.8%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Oncommand Unified Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 5, 2010
15 years ago
Most Recent CVE
Jan 28, 2021
2,003 days ago

CVE Severity & Scoring

Oncommand Unified Manager169 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local13 (7.7%)
Network155 (91.7%)
Unknown0 (0.0%)
Physical1 (0.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low125 (74.0%)
High44 (26.0%)
Unknown0 (0.0%)
User Interaction
None125 (74.0%)
Unknown0 (0.0%)
Required44 (26.0%)
Privileges Required
Low35 (20.7%)
High33 (19.5%)
None101 (59.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (169 CVEs).

169 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressio
Aug 5, 20108.897YESYES
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and avai
Apr 21, 20169.895YESNO
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by
Apr 8, 20197.893YESYES
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, r
Oct 17, 20189.190NOYES
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has be
Aug 17, 20185.386NOYES
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.
Aug 7, 20179.883NOYES
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between succes
Jul 13, 20179.160NONO
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input str
Jun 20, 20177.556NONO
The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 pa
Aug 7, 20176.543NOYES
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCrede
May 16, 20189.841NONO

Exploit Exposure

Signals from CVEs in this product scope (169 CVEs).

CISA KEV
3 CVEs
1.8% of CVEs· 96th percentile
Metasploit
4 CVEs
2.4% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
4.1% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (169 CVEs).

Media Mentions

Signals from CVEs in this product scope (169 CVEs).

Top CNAs Publishing CVEs For Oncommand Unified Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.328.34.6%00
7.126.22.9%00