QID 376641
Date Published: 2022-06-06
QID 376641: NetApp Clustered Data Open Network Technology for Appliance Products (ONTAP) X-Frame-Options Header Vulnerability (NTAP-20211012-0001)
NetApp Data ONTAP is a data management software which allows unifying storage infrastructures across flash, disk and cloud.
CVE-2021-27003: Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Frame-Options header which could allow a clickjacking attack.
Affected Versions:
NetApp Clustered Data ONTAP versions prior to 9.5P18
NetApp Clustered Data ONTAP versions prior to 9.6P15
NetApp Clustered Data ONTAP versions prior to 9.7P14
NetApp Clustered Data ONTAP versions prior to 9.8P5
NetApp Clustered Data ONTAP versions prior to 9.9.1
QID Detection Logic (Authenticated):
This authenticated QID detects vulnerable NetApp OS command 'version'
Successful exploitation of this vulnerability could allow a clickjacking attack.
Customers are advised to refer to NTAP-20211012-0001 for more information about patching this vulnerability.
- NTAP-20211012-0001 -
security.netapp.com/advisory/ntap-20211012-0001/
CVEs related to QID 376641
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| NTAP-20211012-0001 |
|