Vulnerabilities > CVE-2021-26988 - Missing Authorization vulnerability in Netapp Data Ontap

047910
CVSS 3.5 - LOW
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
low complexity
netapp
CWE-862

Summary

Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P8 and 9.8 are susceptible to a vulnerability which could allow unauthorized tenant users to discover information related to converting a 7-Mode directory to Cluster-mode such as Storage Virtual Machine (SVM) names, volume names, directory paths and Job IDs.

Common Weakness Enumeration (CWE)