Home / Security / Advisories / NTAP-20171019-0002
NTAP-20171019-0002 — October 2017 MySQL Vulnerabilities in NetApp Products
Published 2017-10-19 · Updated 2019-03-14 · Status: Final · Exploitation: Public · Severity: not scored · ONTAP affected: No — other NetApp product
Official advisory: NTAP-20171019-0002 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.
Product family: Active IQ Unified Manager · OnCommand family · SnapCenter | other NetApp product
CVEs in this advisory
- CVE-2017-10155 · site index
- CVE-2017-10165 · site index
- CVE-2017-10167 · site index
- CVE-2017-10203 · site index
- CVE-2017-10227 · site index
- CVE-2017-10268 · site index
- CVE-2017-10276 · site index
- CVE-2017-10277 · site index
- CVE-2017-10279 · site index
- CVE-2017-10283 · site index
- CVE-2017-10284 · site index
- CVE-2017-10286 · site index
- CVE-2017-10294 · site index
- CVE-2017-10296 · site index
- CVE-2017-10311 · site index
- CVE-2017-10313 · site index
- CVE-2017-10314 · site index
- CVE-2017-10320 · site index
- CVE-2017-10365 · site index
- CVE-2017-10378 · site index
- CVE-2017-10379 · site index
- CVE-2017-10384 · site index
- CVE-2017-10424 · site index
- CVE-2017-3731 · site index
- CVE-2017-5664 · site index
Impact
Successful exploitation of these vulnerabilities could lead to a partial or complete denial of service (DoS), or the unauthorized reading or modification of a subset or all of the MySQL accessible data.
Affected products
- Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above
- Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above
- OnCommand Balance
- OnCommand Insight
- OnCommand Performance Manager for VMware vSphere
- OnCommand Unified Manager for VMware vSphere for 7.1 and below
- OnCommand Unified Manager for Windows for 7.1 and below
- OnCommand Workflow Automation
- SnapCenter
Official fixes
- OnCommand Performance Manager for VMware vSphere — vendor fix ↗
- OnCommand Insight — vendor fix ↗
- OnCommand Insight — vendor fix ↗
- SnapCenter — vendor fix ↗
- OnCommand Unified Manager for VMware vSphere for 7.1 and below — vendor fix ↗
- OnCommand Workflow Automation — vendor fix ↗
- Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above — vendor fix ↗
- Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above — vendor fix ↗
- OnCommand Unified Manager for Windows for 7.1 and below — vendor fix ↗
References
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html ↗
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017verbose-3236627.html#MSQL ↗
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html#AppendixMSQL ↗
What to do
- Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
- Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
- Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
- Track follow-ups in the site CVE index and the security RSS feed.
Related reading
- Site CVE index — every CVE we track, split by year
- Security hub — recent NetApp advisories and what changed
- Security hardening baseline — applies to NetApp management planes generally
- Every NetApp advisory published in 2017