CVE-2016-3064: Infoleak
Published Sep 1, 2016
·Updated
NetApp Clustered Data ONTAP before 8.2.4P4 and 8.3.x before 8.3.2P2 allows remote authenticated users to obtain sensitive cluster and tenant information via unspecified vectors.
Affected Software
4 affected components
NetApp Clustered Data ONTAP<=8.2.4
NetApp Clustered Data ONTAP=8.3
NetApp Clustered Data ONTAP=8.3.1
NetApp Clustered Data ONTAP=8.3.2
Remediation
Patch Available
Event History
Sep 1, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3064?
CVE-2016-3064 is classified as a medium severity vulnerability affecting NetApp Clustered Data ONTAP.
2
How do I fix CVE-2016-3064?
To fix CVE-2016-3064, upgrade to NetApp Clustered Data ONTAP versions 8.2.4P4 or 8.3.2P2 and later.
3
Who is affected by CVE-2016-3064?
CVE-2016-3064 affects remote authenticated users of NetApp Clustered Data ONTAP prior to the specified patch versions.
4
What information can be obtained due to CVE-2016-3064?
CVE-2016-3064 allows unauthorized access to sensitive cluster and tenant information.
5
What versions of NetApp are impacted by CVE-2016-3064?
CVE-2016-3064 impacts NetApp Clustered Data ONTAP versions before 8.2.4P4 and 8.3.x before 8.3.2P2.