First published: Mon Mar 15 2021(Updated: )
Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCenter Server, Management Services versions prior to 2.17.56 and Management Node versions through 12.2 contain vulnerable versions of SpringBoot Framework.
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vmware Spring Boot | <1.3.2 | |
Netapp Element Plug-in For Vcenter Server | ||
Netapp Management Services For Element Software And Netapp Hci | <2.17.56 | |
IBM Cloud Pak for Business Automation | <=12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26987 is a vulnerability in the Element Plug-in for vCenter Server that incorporates the SpringBoot Framework and allows for remote code execution.
CVE-2021-26987 has a severity rating of 9.8 (Critical).
CVE-2021-26987 affects SpringBoot Framework versions prior to 1.3.2, as well as all versions of Element Plug-in for vCenter Server and Netapp Management Services.
CVE-2021-26987 can be exploited to achieve remote code execution.
More information about CVE-2021-26987 can be found at this [link](https://security.netapp.com/advisory/ntap-20210315-0001/).