CVE-2021-27001: Medium severity ibm data ontap vulnerability
Clustered Data ONTAP versions 9.x prior to 9.5P18, 9.6P16, 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which could allow an authenticated privileged local attacker to arbitrarily modify Compliance-mode WORM data prior to the end of the retention period.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27001?
The severity of CVE-2021-27001 is medium with a severity value of 5.5.
How does CVE-2021-27001 affect NetApp Clustered Data ONTAP?
CVE-2021-27001 affects Clustered Data ONTAP versions 9.x prior to 9.5P18, 9.6P16, 9.7P16, 9.8P7, and 9.9.1P2.
What is the vulnerability in CVE-2021-27001?
The vulnerability in CVE-2021-27001 allows an authenticated privileged local attacker to arbitrarily modify Compliance-mode WORM data prior to the end of the retention period.
How can an attacker exploit CVE-2021-27001?
An attacker can exploit CVE-2021-27001 by taking advantage of their authenticated privileged local access to modify Compliance-mode WORM data.
How can CVE-2021-27001 be fixed?
To fix CVE-2021-27001, upgrade to Clustered Data ONTAP versions 9.5P18, 9.6P16, 9.7P16, 9.8P7, or 9.9.1P2.