First published: Fri Aug 06 2021(Updated: )
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The logged information is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version.
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp Cloud Manager | <3.9.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-26999.
The title of this vulnerability is 'NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails'.
The severity of CVE-2021-26999 is medium with a severity value of 4.3.
CVE-2021-26999 affects NetApp Cloud Manager versions prior to 3.9.9.
Yes, customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled should update to version 3.9.9.
You can find more information about CVE-2021-26999 at the following link: https://security.netapp.com/advisory/NTAP-20210805-0012