Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P8 and 9.8 are susceptible to a vulnerability which could allow unauthorized tenant users to discover information related to converting a 7-Mode directory to Cluster-mode such as Storage Virtual Machine (SVM) names, volume names, directory paths and Job IDs.
References
Link | Resource |
---|---|
https://security.netapp.com/advisory/NTAP-20210303-0001 | Patch Vendor Advisory |
https://security.netapp.com/advisory/NTAP-20210303-0001 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:57
Type | Values Removed | Values Added |
---|---|---|
References | () https://security.netapp.com/advisory/NTAP-20210303-0001 - Patch, Vendor Advisory |
Information
Published : 2021-03-04 21:15
Updated : 2024-11-21 05:57
NVD link : CVE-2021-26988
Mitre link : CVE-2021-26988
CVE.ORG link : CVE-2021-26988
JSON object : View
Products Affected
netapp
- data_ontap
CWE
CWE-862
Missing Authorization