First published: Wed Feb 27 2019(Updated: )
Clustered Data ONTAP versions prior to 9.1P15 and 9.3 prior to 9.3P7 are susceptible to a vulnerability which discloses sensitive information to an unauthenticated user.
Credit: security-alert@netapp.com security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Data ONTAP | >=9.0<9.1 | |
IBM Data ONTAP | =9.1 | |
IBM Data ONTAP | =9.1-p1 | |
IBM Data ONTAP | =9.1-p10 | |
IBM Data ONTAP | =9.1-p11 | |
IBM Data ONTAP | =9.1-p12 | |
IBM Data ONTAP | =9.1-p13 | |
IBM Data ONTAP | =9.1-p14 | |
IBM Data ONTAP | =9.1-p2 | |
IBM Data ONTAP | =9.1-p3 | |
IBM Data ONTAP | =9.1-p4 | |
IBM Data ONTAP | =9.1-p5 | |
IBM Data ONTAP | =9.1-p6 | |
IBM Data ONTAP | =9.1-p7 | |
IBM Data ONTAP | =9.1-p8 | |
IBM Data ONTAP | =9.1-p9 | |
IBM Data ONTAP | =9.3 | |
IBM Data ONTAP | =9.3-p1 | |
IBM Data ONTAP | =9.3-p2 | |
IBM Data ONTAP | =9.3-p3 | |
IBM Data ONTAP | =9.3-p4 | |
IBM Data ONTAP | =9.3-p5 | |
IBM Data ONTAP | =9.3-p6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5491 is classified as a high severity vulnerability due to its potential to disclose sensitive information to unauthenticated users.
To fix CVE-2019-5491, upgrade to Clustered Data ONTAP version 9.1P15 or 9.3P7 or later.
CVE-2019-5491 affects Clustered Data ONTAP versions prior to 9.1P15 and 9.3 prior to 9.3P7.
Organizations using affected versions of Clustered Data ONTAP that have not implemented the recommended updates are at risk due to CVE-2019-5491.
Yes, CVE-2019-5491 can be easily exploited by an unauthenticated user, making it a significant security concern.