CVE-2017-8919
MEDIUMNetApp OnCommand API Services <1.2P3 - Info Disclosure
Title source: llmDescription
NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API, which allows remote authenticated users to obtain sensitive password information via unspecified vectors.
Scores
CVSS v3
6.5
EPSS
0.0021
EPSS Percentile
43.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
Status
published
Products (2)
netapp/oncommand_api_services
< 1.2
n/a/n/a
Published
Jul 25, 2017
Tracked Since
Feb 18, 2026