CVE-2021-27003: Medium severity ibm data ontap vulnerability
Published Oct 12, 2021
·Updated
Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Frame-Options header which could allow a clickjacking attack.
Affected Software
16 affected components
NetApp Clustered Data ONTAP<9.5
NetApp Clustered Data ONTAP=9.5
NetApp Clustered Data ONTAP=9.5-p12
NetApp Clustered Data ONTAP=9.5-p13
NetApp Clustered Data ONTAP=9.5-p6
NetApp Clustered Data ONTAP=9.5-p8
NetApp Clustered Data ONTAP=9.5-p9
NetApp Clustered Data ONTAP=9.6
NetApp Clustered Data ONTAP=9.6-p1
NetApp Clustered Data ONTAP=9.6-p3
NetApp Clustered Data ONTAP=9.6-p4
NetApp Clustered Data ONTAP=9.6-p7
NetApp Clustered Data ONTAP=9.6-p8
NetApp Clustered Data ONTAP=9.7
NetApp Clustered Data ONTAP=9.7-p12
NetApp Clustered Data ONTAP=9.8
Event History
Oct 12, 2021
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-27003?
CVE-2021-27003 is considered a medium severity vulnerability due to the potential for clickjacking attacks.
2
How do I fix CVE-2021-27003?
To address CVE-2021-27003, upgrade your Clustered Data ONTAP to versions 9.5P18, 9.6P15, 9.7P14, 9.8P5, or 9.9.1.
3
What could an attacker achieve with CVE-2021-27003?
An attacker exploiting CVE-2021-27003 could perform clickjacking attacks leading to unauthorized actions on behalf of an unsuspecting user.
4
Which versions of Clustered Data ONTAP are affected by CVE-2021-27003?
CVE-2021-27003 affects all versions of Clustered Data ONTAP prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5, and 9.9.1.
5
Is there a workaround for CVE-2021-27003?
There are no documented workarounds for CVE-2021-27003; upgrading to the patched versions is recommended.