NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API, which allows remote authenticated users to obtain sensitive password information via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Oncommand_api_services | Netapp | * | 1.2 (including) |