CVE-2021-26999

MEDIUM

Netapp Cloud Manager < 3.9.9 - Log Information Exposure

Title source: rule
STIX 2.1

Description

NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The logged information is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0023
EPSS Percentile 45.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-532
Status published
Products (1)
netapp/cloud_manager < 3.9.9
Published Aug 06, 2021
Tracked Since Feb 18, 2026