CVE-2017-12423: High severity ibm data ontap vulnerability
Published Sep 1, 2017
·Updated
NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to read data on other Storage Virtual Machines (SVMs) via unspecified vectors.
Affected Software
4 affected components
NetApp Clustered Data ONTAP=8.3
NetApp Clustered Data ONTAP=8.3.1
NetApp Clustered Data ONTAP=8.3.2
NetApp Clustered Data ONTAP=8.3.2p11
Event History
Sep 1, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12423?
CVE-2017-12423 has a medium severity rating as it allows remote authenticated users to access unauthorized data.
2
How do I fix CVE-2017-12423?
To resolve CVE-2017-12423, upgrade your NetApp Clustered Data ONTAP to version 8.3.2P12 or later.
3
Who is affected by CVE-2017-12423?
CVE-2017-12423 affects users of NetApp Clustered Data ONTAP versions 8.3.x prior to 8.3.2P12.
4
What types of data are exposed in CVE-2017-12423?
CVE-2017-12423 allows remote authenticated users to read data residing on other Storage Virtual Machines (SVMs).
5
Is authentication required to exploit CVE-2017-12423?
Yes, exploitation of CVE-2017-12423 requires remote authenticated access to the affected system.