Description
ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when the object-store profiler command is being run by an administrative user.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- NETAPP / ONTAP 99.4 – 9.8P21
- NETAPP / ONTAP 99.9.1 – 9.9.1P18
- NETAPP / ONTAP 99.10.1 – 9.10.1P16
- NETAPP / ONTAP 99.11.1 – 9.11.1P13
- NETAPP / ONTAP 99.12.1 – 9.12.1P8
- NETAPP / ONTAP 99.13.1 – 9.13.1P4
References
Updated 46m ago · 8 sources