Database/Control plane, storage & DevOps
NetApp Clustered Data ONTAP Storage Virtual Machine boundary: A user in one SVM determines whether data exists on a
CVSS 3.5CVE-2020-8588Control plane, storage & DevOpscurated
Impact
A user in one SVM determines whether data exists on a different SVM. The SVM is the tenant boundary in ONTAP, so this leaks the shape of another customer's namespace across it.
Who can reach it
An authenticated user on an adjacent network with access to any SVM on a Clustered Data ONTAP system earlier than 9.3P20 or 9.5P15.
What to do
Upgrade to 9.3P20 / 9.5P15 or later. If SVMs are being used as a hard tenant boundary, treat namespace metadata as having been observable until the upgrade lands.
References
Related entries
- NetApp Clustered Data ONTAP Storage Virtual Machine boundary: A user in one SVM enumerates the names of other SVMs andCVE-2020-8589 · NetApp Clustered Data ONTAP Storage Virtual Machine boundaryLow
- FlyteAdmin (list endpoints, SQL injection through list filters): FlyteAdmin's list endpoints interpolate filterCVE-2023-41891 · FlyteAdmin (list endpoints, SQL injection through list filters)Low
- GitLab EE: reporter-role author of a merge request can reset its approval rulesCVE-2026-7487 · GitLab EE (merge request approval rules, authorization check)Low
- Jenkins: Overall/Manage holders can change Appearance configuration reserved for administratorsCVE-2026-84653 · Jenkins core (Appearance configuration page permission checks)Low
- IBM Spectrum Scale Local Read Only Cache (LROC): With LROC enabled, a read of one file can silently return the contentsCVE-2018-1993 · IBM Spectrum Scale Local Read Only Cache (LROC)Low
- DDR3 and DDR4 DRAM, including ECC modules; tracked by Intel as a partial-physical-address disclosure issue: TurnsCVE-2019-0174 · DDR3 and DDR4 DRAM, including ECC modules; tracked by Intel as a partial-physical-address disclosure issueLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.