PT-2018-16989 · Netapp · Netapp 7-Mode Transition Tool
Published
2018-08-03
·
Updated
2019-10-03
·
CVE-2018-5489
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NetApp 7-Mode Transition Tool versions prior to 2.0
Description
The issue allows users with valid credentials to access functions and information that may have been intended for administrators or privileged users. This occurs because versions prior to 2.0 do not enforce user authorization rules on file information and status that has been previously collected.
Recommendations
For versions prior to 2.0, update to version 2.0 or later, which maintains and verifies authorization rules for file information, status, and utilities.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netapp 7-Mode Transition Tool