CVE-2021-26987

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/03/2021
Last modified:
07/04/2022

Description

Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCenter Server, Management Services versions prior to 2.17.56 and Management Node versions through 12.2 contain vulnerable versions of SpringBoot Framework.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:* 1.3.2 (excluding)
cpe:2.3:a:netapp:element_plug-in_for_vcenter_server:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:*:*:*:*:*:*:*:* 2.17.56 (excluding)
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:*:*:*:*:*:*:*:* 12.2 (including)


References to Advisories, Solutions, and Tools