VYPR
High severity8.8NVD Advisory· Published Aug 3, 2018· Updated Jun 17, 2026

CVE-2018-5490

CVE-2018-5490

Description

Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "read-only" access from authenticated SMBv2 and SMBv3 clients. This behavior has been resolved in the GA release. Customers running prior release candidates (RCs) are requested to update their systems to the NetApp Data ONTAP 8.3 GA release.

Affected products

2
  • NetApp/Clustered Data Ontapllm-fuzzy2 versions
    = 8.3 Release Candidate+ 1 more
    • (no CPE)range: = 8.3 Release Candidate
    • (no CPE)range: 8.3 Release Candidate versions

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.