First published: Fri Aug 06 2021(Updated: )
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version.
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp Cloud Manager | <3.9.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-26998.
The severity of CVE-2021-26998 is medium (4.3).
NetApp Cloud Manager versions prior to 3.9.9 are affected by CVE-2021-26998.
Customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version of NetApp Cloud Manager.
You can find more information about CVE-2021-26998 on the NetApp Security Advisory page: [https://security.netapp.com/advisory/NTAP-20210805-0011](https://security.netapp.com/advisory/NTAP-20210805-0011)