CVE-2018-5497: Infoleak
Published Jan 24, 2019
·Updated
Clustered Data ONTAP versions prior to 9.1P16, 9.3P10 and 9.4P5 are susceptible to a vulnerability which discloses sensitive information to an unauthorized user.
Affected Software
18 affected components
NetApp Clustered Data ONTAP<=9.1
NetApp Clustered Data ONTAP=9.1-p10
NetApp Clustered Data ONTAP=9.1-p11
NetApp Clustered Data ONTAP=9.1-p12
NetApp Clustered Data ONTAP=9.1-p13
NetApp Clustered Data ONTAP=9.1-p14
NetApp Clustered Data ONTAP=9.1-p15
NetApp Clustered Data ONTAP=9.1-p2
NetApp Clustered Data ONTAP=9.1-p3
NetApp Clustered Data ONTAP=9.1-p4
NetApp Clustered Data ONTAP=9.1-p5
NetApp Clustered Data ONTAP=9.1-p6
NetApp Clustered Data ONTAP=9.1-p7
NetApp Clustered Data ONTAP=9.1-p8
NetApp Clustered Data ONTAP=9.1-p9
NetApp Clustered Data ONTAP=9.1-rc1
NetApp Clustered Data ONTAP=9.3-p10
NetApp Clustered Data ONTAP=9.4-p5
Event History
Jan 24, 2019
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-5497?
CVE-2018-5497 has been classified with a moderate severity rating, indicating a potential risk of sensitive information disclosure.
2
How do I fix CVE-2018-5497?
To mitigate CVE-2018-5497, upgrade your Clustered Data ONTAP to versions 9.1P16, 9.3P10, or 9.4P5 or later.
3
What types of data are vulnerable in CVE-2018-5497?
CVE-2018-5497 may disclose sensitive information to unauthorized users, potentially compromising data confidentiality.
4
Which versions of Clustered Data ONTAP are affected by CVE-2018-5497?
CVE-2018-5497 affects Clustered Data ONTAP versions prior to 9.1P16, 9.3P10, and 9.4P5.
5
Is there a known exploit for CVE-2018-5497?
As of the latest updates, there are no public reports of an active exploit for CVE-2018-5497.