Database/Control plane, storage & DevOps
NetApp Clustered Data ONTAP Storage Virtual Machine boundary: A user in one SVM enumerates the names of other SVMs and
CVE-2020-8589Control plane, storage & DevOpscurated
Impact
A user in one SVM enumerates the names of other SVMs and the filenames inside them. Dataset and checkpoint names alone tell a competitor what another tenant is training.
Who can reach it
An authenticated user on an adjacent network with access to any SVM on a Clustered Data ONTAP system earlier than 9.3P20 or 9.5P15.
What to do
Upgrade to 9.3P20 / 9.5P15 or later. Where SVM naming itself is sensitive, rename after patching, since the old names are already exposed.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.