CVE-2017-8919: Medium severity netapp oncommand api services vulnerability
Published Jul 25, 2017
·Updated
NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API, which allows remote authenticated users to obtain sensitive password information via unspecified vectors.
Affected Software
1 affected component
NetApp OnCommand API Services<=1.2
Event History
Jul 25, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8919?
CVE-2017-8919 is considered a medium severity vulnerability due to the exposure of sensitive LDAP BIND passwords.
2
How do I fix CVE-2017-8919?
To fix CVE-2017-8919, update NetApp OnCommand API Services to version 1.2P3 or later.
3
What is the impact of CVE-2017-8919?
The impact of CVE-2017-8919 includes the potential exposure of sensitive password information to remote authenticated users.
4
Which versions of NetApp OnCommand API Services are affected by CVE-2017-8919?
CVE-2017-8919 affects all versions of NetApp OnCommand API Services prior to 1.2P3.
5
Can CVE-2017-8919 be exploited remotely?
Yes, CVE-2017-8919 can be exploited by remote authenticated users who have access to the REST API.