CVE-2015-7886: Infoleak
Published Jan 18, 2016
·Updated
NetApp Data ONTAP before 8.2.4P1, when 7-Mode and HTTP access are enabled, allows remote attackers to obtain sensitive volume information via unspecified vectors.
Affected Software
1 affected component
NetApp Data ONTAP<=8.2.4
Remediation
Patch Available
Event History
Jan 18, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7886?
CVE-2015-7886 has been assigned a medium severity rating due to its potential to expose sensitive volume information to remote attackers.
2
How do I fix CVE-2015-7886?
To fix CVE-2015-7886, upgrade to NetApp Data ONTAP version 8.2.4P1 or later.
3
What does CVE-2015-7886 affect?
CVE-2015-7886 affects NetApp Data ONTAP versions prior to 8.2.4P1 when 7-Mode and HTTP access are enabled.
4
Can CVE-2015-7886 be exploited remotely?
Yes, CVE-2015-7886 can be remotely exploited by attackers to obtain sensitive volume information.
5
What are the consequences of CVE-2015-7886?
Exploitation of CVE-2015-7886 may lead to unauthorized disclosure of sensitive data within the affected NetApp systems.