CVE Vulnerabilities

CVE-2017-12422

Improper Privilege Management

Published: Aug 29, 2017 | Modified: Apr 20, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

NetApp StorageGRID Webscale 10.2.x before 10.2.2.3, 10.3.x before 10.3.0.4, and 10.4.x before 10.4.0.2 allow remote authenticated users to delete arbitrary objects via unspecified vectors.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Storagegrid_webscaleNetapp10.2 (including)10.2 (including)
Storagegrid_webscaleNetapp10.2.1 (including)10.2.1 (including)
Storagegrid_webscaleNetapp10.2.2 (including)10.2.2 (including)
Storagegrid_webscaleNetapp10.2.2.2 (including)10.2.2.2 (including)
Storagegrid_webscaleNetapp10.3.0 (including)10.3.0 (including)
Storagegrid_webscaleNetapp10.3.0.3 (including)10.3.0.3 (including)
Storagegrid_webscaleNetapp10.4.0 (including)10.4.0 (including)
Storagegrid_webscaleNetapp10.4.0.1 (including)10.4.0.1 (including)

Potential Mitigations

References