Medium severity4.8NVD Advisory· Published Jan 12, 2024· Updated Jun 17, 2026
CVE-2024-21982
CVE-2024-21982
Description
ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when the object-store profiler command is being run by an administrative user.
Affected products
9cpe:2.3:o:netapp:clustered_data_ontap:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:netapp:clustered_data_ontap:*:*:*:*:*:*:*:*range: >=9.4,<9.8
- cpe:2.3:o:netapp:clustered_data_ontap:9.8:-:*:*:*:*:*:*
- cpe:2.3:o:netapp:clustered_data_ontap:9.9.1:-:*:*:*:*:*:*
- cpe:2.3:o:netapp:clustered_data_ontap:9.10.1:-:*:*:*:*:*:*
- cpe:2.3:o:netapp:clustered_data_ontap:9.11.1:-:*:*:*:*:*:*
- cpe:2.3:o:netapp:clustered_data_ontap:9.12.1:-:*:*:*:*:*:*
- cpe:2.3:o:netapp:clustered_data_ontap:9.13.1:-:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- security.netapp.com/advisory/ntap-20240111-0001/nvdVendor Advisory
News mentions
0No linked articles in our index yet.