Home / Security / Advisories / NTAP-20141023-0001
NTAP-20141023-0001 — October 2014 Java Runtime Environment (JRE) Vulnerabilities in Multiple NetApp Products
Published 2014-10-23 · Updated 2017-03-22 · Status: Final · Exploitation: Public · Severity: not scored · ONTAP affected: Yes
Official advisory: NTAP-20141023-0001 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.
Product family: Other NetApp products · NetApp Console / BlueXP · ONTAP · OnCommand family · SnapManager / Snap utilities | ONTAP-relevant
CVEs in this advisory
- CVE-2014-6513 · site index
- CVE-2014-6532 · site index
- CVE-2014-6503 · site index
- CVE-2014-6456 · site index
- CVE-2014-6562 · site index
- CVE-2014-6485 · site index
- CVE-2014-6492 · site index
- CVE-2014-6493 · site index
- CVE-2014-4288 · site index
- CVE-2014-6466 · site index
- CVE-2014-6458 · site index
- CVE-2014-6468 · site index
- CVE-2014-6506 · site index
- CVE-2014-6511 · site index
- CVE-2014-6476 · site index
- CVE-2014-6515 · site index
- CVE-2014-6504 · site index
- CVE-2014-6519 · site index
- CVE-2014-6517 · site index
- CVE-2014-6531 · site index
- CVE-2014-6512 · site index
- CVE-2014-6457 · site index
- CVE-2014-6527 · site index
- CVE-2014-6502 · site index
- CVE-2014-6558 · site index
Impact
Exploitation of this vulnerability may lead to unauthenticated network attacks, unauthorized update, insert or delete access to some Java SE, Java SE Embedded accessible data, or unauthenticated Operating System takeover including arbitrary code execution.
Affected products
- 7-Mode Transition Tool
- Cloud Manager
- MetroCluster Plug-in for vSphere
- NetApp VASA Provider for Clustered Data ONTAP 9.7 and above
- NetApp VASA Provider for Data ONTAP operating in 7-Mode
- OnCommand Balance
- OnCommand Insight
- OnCommand Report
- OnCommand Unified Manager Core Package
- OnCommand Unified Manager Host Package
- OnCommand Workflow Automation
- SnapManager for Oracle
Official fixes
- OnCommand Unified Manager Core Package — vendor fix ↗
- OnCommand Unified Manager Core Package — vendor fix ↗
- SnapManager for Oracle — vendor fix ↗
- SnapManager for Oracle — vendor fix ↗
- Virtual Storage Console for VMware vSphere 9.7 and above — vendor fix ↗
- NetApp VASA Provider for Clustered Data ONTAP 9.7 and above — vendor fix ↗
- Cloud Manager — vendor fix ↗
- OnCommand Insight — vendor fix ↗
- OnCommand Balance — vendor fix ↗
- 7-Mode Transition Tool — vendor fix ↗
- OnCommand Workflow Automation — vendor fix ↗
- SnapManager for SAP — vendor fix ↗
References
- https://support.oracle.com/epmos/faces/DocumentDisplay?id=1931846.1&_adf.ctrl-state=u4wgyjryo_11 ↗
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html#AppendixJAVA ↗
- http://www.oracle.com/technetwork/java/javase/8u25-relnotes-2296185.html ↗
- http://www.oracle.com/technetwork/java/javase/7u71-relnotes-2296187.html ↗
- http://www.oracle.com/technetwork/java/javase/7u72-relnotes-2296190.html ↗
- http://www.oracle.com/technetwork/java/javase/documentation/overview-156328.html ↗
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2014