PT-2018-16989 · Netapp · Netapp 7-Mode Transition Tool

Published

2018-08-03

·

Updated

2019-10-03

·

CVE-2018-5489

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NetApp 7-Mode Transition Tool versions prior to 2.0
Description The issue allows users with valid credentials to access functions and information that may have been intended for administrators or privileged users. This occurs because versions prior to 2.0 do not enforce user authorization rules on file information and status that has been previously collected.
Recommendations For versions prior to 2.0, update to version 2.0 or later, which maintains and verifies authorization rules for file information, status, and utilities.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5489

Affected Products

Netapp 7-Mode Transition Tool