CVE-2017-8919: Netapp Oncommand API Services

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API, which allows remote authenticated users to obtain sensitive password information via unspecified vectors.

Affected products

  • Netapp Oncommand API Services: up to and including 1.2

Published 2017-07-25. Last modified 2026-06-17.