CVE-2024-21982
MEDIUMDescription
ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when the object-store profiler command is being run by an administrative user.
Is your site exposed to CVE-2024-21982?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| netapp | clustered_data_ontap |
| netapp | clustered_data_ontap |
| netapp | clustered_data_ontap |
| netapp | clustered_data_ontap |
| netapp | clustered_data_ontap |
| netapp | clustered_data_ontap |
| netapp | clustered_data_ontap |
References
Frequently Asked Questions
What is CVE-2024-21982? +
How severe is CVE-2024-21982? +
What products are affected by CVE-2024-21982? +
How do I check if I'm vulnerable to CVE-2024-21982? +
Related Vulnerabilities
SnapCenter versions prior to 6.0.1P1 and 6.1P1 are susceptible to a vulnerability which may allow an authenticated SnapCenter Server user …
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 …
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files …
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems …
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution …
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on …