cbcvebase.
CVE-2021-26988
published 2021-03-04

CVE-2021-26988: Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P8 and 9.8 are susceptible to a vulnerability which could allow unauthorized tenant users to…

low3.5CVSS 3.1
AVAACLPRLUINSUCLINAN
Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P8 and 9.8 are susceptible to a vulnerability which could allow unauthorized tenant users to discover information related to converting a 7-Mode directory to Cluster-mode such as Storage Virtual Machine (SVM) names, volume names, directory paths and Job IDs.

Affected

5 ranges
VendorProductVersion rangeFixed in
netappdata_ontap
netappdata_ontap
netappdata_ontap
netappdata_ontap
netappdata_ontap
CVE-2021-26988 — Missing Authorization in Data Ontap | cvebase