imPC@ndo IT

Tracker / CVE-2021-26987

CVE-2021-26987

Critical 9.8

Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCenter Server, Management Services versions prior to 2.17.56 and Management Node versions through 12.2 contain vulnerable versions of SpringBoot Framework.

Affected products and versions

netapp element_plug-in_for_vcenter_server
netapp management_services_for_element_software_and_netapp_hci · … → 2.17.56
netapp solidfire_\&_hci_management_node · … → 12.2
vmware spring_boot · … → 1.3.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References