Database/Control plane, storage & DevOps
NetApp ONTAP Select Deploy administration utility (privilege escalation): An administrative user of the Deploy utility
CVE-2019-17272Control plane, storage & DevOpscurated
Impact
An administrative user of the Deploy utility escalates beyond their assigned role, collapsing any separation between a limited storage operator and full control of the deployment tooling.
Who can reach it
An existing administrative account on any version of ONTAP Select Deploy, reachable over the network.
What to do
Upgrade Deploy to a fixed release. Do not rely on role separation inside Deploy as a security boundary on affected versions - treat every Deploy admin as fully privileged until patched.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.