CVE Vulnerabilities

CVE-2022-23241

Published: Oct 19, 2022 | Modified: Oct 21, 2022
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerability which could allow an authenticated remote attacker to arbitrarily modify or delete WORM data prior to the end of the retention period.

Affected Software

Name Vendor Start Version End Version
Clustered_data_ontap Netapp 9.11.1 (including) 9.11.1 (including)
Clustered_data_ontap Netapp 9.11.1-p2 (including) 9.11.1-p2 (including)
Clustered_data_ontap Netapp 9.11.1-rc1 (including) 9.11.1-rc1 (including)

References