CVE-2021-26988: Low severity ibm network appliance data ontap vulnerability
Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P8 and 9.8 are susceptible to a vulnerability which could allow unauthorized tenant users to discover information related to converting a 7-Mode directory to Cluster-mode such as Storage Virtual Machine (SVM) names, volume names, directory paths and Job IDs.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What versions of Clustered Data ONTAP are susceptible to CVE-2021-26988?
Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P8, and 9.8 are susceptible.
What is the severity of CVE-2021-26988?
The severity of CVE-2021-26988 is rated as low with a CVSS score of 3.5.
How can unauthorized tenant users exploit CVE-2021-26988?
Unauthorized tenant users could exploit this vulnerability to discover information related to converting a 7-Mode directory to Cluster-mode.
Is there a fix available for CVE-2021-26988?
Updating Clustered Data ONTAP to versions 9.3P21, 9.5P16, 9.6P12, 9.7P8, or 9.8 addresses this vulnerability.
Where can I find more information about CVE-2021-26988?
You can refer to the advisory provided by NetApp at the following link: https://security.netapp.com/advisory/NTAP-20210303-0001.