CVE-2017-15518

HIGH

NetApp OnCommand API Services < 2.1 & Service Level Manager < 1.0RC4 - Sensitive Info Exposure

Title source: llm
STIX 2.1

Description

All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password. All users are urged to move to a fixed version. Since the affected password is changed during every upgrade/installation no further action is required.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0016
EPSS Percentile 37.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-200
Status published
Products (3)
netapp/oncommand_api_services < 2.0
netapp/service_level_manager 1.0 rc1 (3 CPE variants)
netapp/service_level_manager < 1.0
Published Feb 23, 2018
Tracked Since Feb 18, 2026