CVE-2017-12422: Medium severity netapp storagegrid vulnerability
Published Aug 29, 2017
·Updated
NetApp StorageGRID Webscale 10.2.x before 10.2.2.3, 10.3.x before 10.3.0.4, and 10.4.x before 10.4.0.2 allow remote authenticated users to delete arbitrary objects via unspecified vectors.
Affected Software
8 affected components
NetApp StorageGRID Webscale=10.2
NetApp StorageGRID Webscale=10.2.1
NetApp StorageGRID Webscale=10.2.2
NetApp StorageGRID Webscale=10.2.2.2
NetApp StorageGRID Webscale=10.3.0
NetApp StorageGRID Webscale=10.3.0.3
NetApp StorageGRID Webscale=10.4.0
NetApp StorageGRID Webscale=10.4.0.1
Event History
Aug 29, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12422?
CVE-2017-12422 has been rated as a high severity vulnerability due to its potential impact on data availability.
2
How do I fix CVE-2017-12422?
To fix CVE-2017-12422, upgrade to NetApp StorageGRID Webscale version 10.2.2.3, 10.3.0.4, or 10.4.0.2 or later.
3
Who is affected by CVE-2017-12422?
CVE-2017-12422 affects users of NetApp StorageGRID Webscale versions prior to 10.2.2.3, 10.3.0.4, and 10.4.0.2.
4
What types of attacks does CVE-2017-12422 allow?
CVE-2017-12422 permits remote authenticated users to delete arbitrary objects, posing a risk of unauthorized data loss.
5
When was CVE-2017-12422 disclosed?
CVE-2017-12422 was disclosed on August 25, 2017.