Home / Security / Advisories / NTAP-20190423-0002
NTAP-20190423-0002 — April 2019 MySQL Vulnerabilities in NetApp Products
Published 2019-04-23 · Updated 2021-01-18 · Status: Final · Exploitation: Public · Severity: MEDIUM 5.9 · ONTAP affected: No — other NetApp product
Product family: Active IQ Unified Manager · OnCommand family · SnapCenter | other NetApp product | highest CVSS: 5.9
CVEs in this advisory
- CVE-2019-2632 · site index
- CVE-2019-2693 · site index
- CVE-2019-2694 · site index
- CVE-2019-2695 · site index
- CVE-2019-2692 · site index
- CVE-2019-1559 — MEDIUM · CVSS 5.9 · site index
- CVE-2019-1559 — MEDIUM · CVSS 5.9 · site index
- CVE-2018-3123 · site index
- CVE-2019-2623 · site index
- CVE-2018-0734 — MEDIUM · CVSS 5.9 · site index
- CVE-2019-2634 · site index
- CVE-2019-2580 · site index
- CVE-2019-2585 · site index
- CVE-2019-2593 · site index
- CVE-2019-2624 · site index
- CVE-2019-2628 · site index
- CVE-2019-2566 · site index
- CVE-2019-2626 · site index
- CVE-2019-2644 · site index
- CVE-2019-2631 · site index
- CVE-2019-2581 · site index
- CVE-2019-2596 · site index
- CVE-2019-2607 · site index
- CVE-2019-2625 · site index
- CVE-2019-2681 · site index
- CVE-2019-2685 · site index
- CVE-2019-2686 · site index
- CVE-2019-2687 · site index
- CVE-2019-2688 · site index
- CVE-2019-2689 · site index
- CVE-2019-2683 · site index
- CVE-2019-2592 · site index
- CVE-2019-2587 · site index
- CVE-2019-2635 · site index
- CVE-2019-2584 · site index
- CVE-2019-2589 · site index
- CVE-2019-2606 · site index
- CVE-2019-2620 · site index
- CVE-2019-2627 · site index
- CVE-2019-2691 · site index
- CVE-2019-2636 · site index
- CVE-2019-2614 · site index
- CVE-2019-2617 · site index
- CVE-2019-2630 · site index
- CVE-2019-1559 — MEDIUM · CVSS 5.9 · site index
What the CVE records say
CVE-2019-1559 — If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).
CVE-2019-1559 — If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).
CVE-2018-0734 — The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
CVE-2019-1559 — If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).
Impact
Successful exploitation of these vulnerabilities may lead to unauthorized takeover of MySQL Server, unauthorized read or modification access to a subset or all MySQL Server accessible data, or to a hang or frequently repeatable crash (partial or complete DoS) of MySQL Server.
Affected products
- Active IQ Unified Manager for Microsoft Windows
- Active IQ Unified Manager for VMware vSphere
- OnCommand Insight
- OnCommand Workflow Automation
- SnapCenter
Official fixes
- OnCommand Insight — vendor fix ↗
- SnapCenter — vendor fix ↗
- Active IQ Unified Manager for VMware vSphere — vendor fix ↗
- OnCommand Workflow Automation — vendor fix ↗
- Active IQ Unified Manager for Microsoft Windows — vendor fix ↗
References
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html ↗
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html#AppendixMSQL ↗
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019verbose-5072824.html#MSQL ↗
What to do
- Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
- Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
- Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
- Track follow-ups in the site CVE index and the security RSS feed.
Related reading
- Site CVE index — every CVE we track, split by year
- Security hub — recent NetApp advisories and what changed
- Security hardening baseline — applies to NetApp management planes generally
- Every NetApp advisory published in 2019