CVE-2021-26998: Medium severity cloud manager vulnerability
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-26998.
What is the severity of CVE-2021-26998?
The severity of CVE-2021-26998 is medium (4.3).
What is affected by CVE-2021-26998?
NetApp Cloud Manager versions prior to 3.9.9 are affected by CVE-2021-26998.
What is the recommended action for customers affected by CVE-2021-26998?
Customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version of NetApp Cloud Manager.
Where can I find more information about CVE-2021-26998?
You can find more information about CVE-2021-26998 on the NetApp Security Advisory page: [https://security.netapp.com/advisory/NTAP-20210805-0011](https://security.netapp.com/advisory/NTAP-20210805-0011)