CVE-2021-26999

MEDIUM

NetApp Cloud Manager < 3.9.9 - Authenticated Sensitive Information Exposure via Active Directory Connection Failure Logs

Title source: llm
STIX 2.1

Description

NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The logged information is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0065
EPSS Percentile 46.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-532
Status published
Products (1)
netapp/cloud_manager < 3.9.9
Published Aug 06, 2021
Tracked Since Feb 18, 2026