Vulnerability Description
NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API, which allows remote authenticated users to obtain sensitive password information via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netapp | Oncommand Api Services | <= 1.2 |
References
- http://www.securityfocus.com/bid/99957Third Party AdvisoryVDB Entry
- https://kb.netapp.com/support/s/article/ka51A0000008Spy/NTAP-20170718-0001Vendor Advisory
- http://www.securityfocus.com/bid/99957Third Party AdvisoryVDB Entry
- https://kb.netapp.com/support/s/article/ka51A0000008Spy/NTAP-20170718-0001Vendor Advisory
FAQ
What is CVE-2017-8919?
CVE-2017-8919 is a vulnerability with a CVSS score of 6.5 (MEDIUM). NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API, which allows remote authenticated users to obtain sensitive password informati...
How severe is CVE-2017-8919?
CVE-2017-8919 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-8919?
Check the references section above for vendor advisories and patch information. Affected products include: Netapp Oncommand Api Services.