First published: Wed Feb 03 2021(Updated: )
Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which could allow unauthorized tenant users to discover the existence of data on other Storage Virtual Machines (SVMs).
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp Clustered Data ONTAP | <9.3 | |
NetApp Clustered Data ONTAP | >=9.4<9.5 | |
NetApp Clustered Data ONTAP | =9.3 | |
NetApp Clustered Data ONTAP | =9.3-p1 | |
NetApp Clustered Data ONTAP | =9.3-p10 | |
NetApp Clustered Data ONTAP | =9.3-p2 | |
NetApp Clustered Data ONTAP | =9.3-p3 | |
NetApp Clustered Data ONTAP | =9.3-p4 | |
NetApp Clustered Data ONTAP | =9.3-p5 | |
NetApp Clustered Data ONTAP | =9.3-p6 | |
NetApp Clustered Data ONTAP | =9.3-p7 | |
NetApp Clustered Data ONTAP | =9.3-p8 | |
NetApp Clustered Data ONTAP | =9.3-p9 | |
NetApp Clustered Data ONTAP | =9.3-rc1 | |
NetApp Clustered Data ONTAP | =9.5 | |
NetApp Clustered Data ONTAP | =9.5-p1 | |
NetApp Clustered Data ONTAP | =9.5-p6 | |
NetApp Clustered Data ONTAP | =9.5-p8 | |
NetApp Clustered Data ONTAP | =9.5-p9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8588 has a high severity rating as it may allow unauthorized access to sensitive data.
To fix CVE-2020-8588, upgrade to Clustered Data ONTAP version 9.3P20 or 9.5P15 or later.
CVE-2020-8588 affects Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15.
CVE-2020-8588 is a security vulnerability that allows unauthorized tenant users to discover data on other Storage Virtual Machines.
Organizations using affected versions of NetApp Clustered Data ONTAP may be at risk from CVE-2020-8588.