Home / Security / Advisories / NTAP-20201023-0003
NTAP-20201023-0003 — October 2020 MySQL Vulnerabilities in NetApp Products
Published 2020-10-23 · Updated 2022-01-21 · Status: Final · Exploitation: Public · Severity: not scored · ONTAP affected: No — other NetApp product
Official advisory: NTAP-20201023-0003 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.
Product family: Active IQ Unified Manager · OnCommand family · SnapCenter | other NetApp product
CVEs in this advisory
- CVE-2020-8174 · site index
- CVE-2020-14672 · site index
- CVE-2020-14760 · site index
- CVE-2020-14765 · site index
- CVE-2020-14769 · site index
- CVE-2020-14771 · site index
- CVE-2020-14773 · site index
- CVE-2020-14775 · site index
- CVE-2020-14776 · site index
- CVE-2020-14777 · site index
- CVE-2020-14785 · site index
- CVE-2020-14786 · site index
- CVE-2020-14789 · site index
- CVE-2020-14790 · site index
- CVE-2020-14791 · site index
- CVE-2020-14793 · site index
- CVE-2020-14794 · site index
- CVE-2020-14799 · site index
- CVE-2020-14800 · site index
- CVE-2020-14804 · site index
- CVE-2020-14809 · site index
- CVE-2020-14812 · site index
- CVE-2020-14814 · site index
- CVE-2020-14821 · site index
- CVE-2020-14827 · site index
- CVE-2020-14828 · site index
- CVE-2020-14829 · site index
- CVE-2020-14830 · site index
- CVE-2020-14836 · site index
- CVE-2020-14837 · site index
- CVE-2020-14838 · site index
- CVE-2020-14839 · site index
- CVE-2020-14844 · site index
- CVE-2020-14845 · site index
- CVE-2020-14846 · site index
- CVE-2020-14848 · site index
- CVE-2020-14852 · site index
- CVE-2020-14853 · site index
- CVE-2020-14860 · site index
- CVE-2020-14861 · site index
- CVE-2020-14866 · site index
- CVE-2020-14867 · site index
- CVE-2020-14868 · site index
- CVE-2020-14869 · site index
- CVE-2020-14870 · site index
- CVE-2020-14873 · site index
- CVE-2020-14878 · site index
- CVE-2020-14888 · site index
- CVE-2020-14891 · site index
- CVE-2020-14893 · site index
- CVE-2020-4051 · site index
Impact
Successful exploitation of these vulnerabilities may lead to unauthorized takeover of MySQL Server, unauthorized read or modification access to a subset or all of the MySQL Server accessible data, or to a hang or frequently repeatable crash (partial or complete DoS) of MySQL Server.
Affected products
- Active IQ Unified Manager for Microsoft Windows
- Active IQ Unified Manager for VMware vSphere
- OnCommand Insight
- OnCommand Workflow Automation
- SnapCenter
Official fixes
- OnCommand Workflow Automation — vendor fix ↗
- SnapCenter — vendor fix ↗
- Active IQ Unified Manager for Microsoft Windows — vendor fix ↗
- Active IQ Unified Manager for VMware vSphere — vendor fix ↗
- OnCommand Insight — vendor fix ↗
References
- https://www.oracle.com/security-alerts/ ↗
- https://www.oracle.com/security-alerts/cpuoct2020verbose.html#MSQL ↗
- https://www.oracle.com/security-alerts/cpuoct2020.html#AppendixMSQL ↗
What to do
- Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
- Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
- Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
- Track follow-ups in the site CVE index and the security RSS feed.
Related reading
- Site CVE index — every CVE we track, split by year
- Security hub — recent NetApp advisories and what changed
- Security hardening baseline — applies to NetApp management planes generally
- Every NetApp advisory published in 2020