Home / Security / Advisories / NTAP-20210702-0001
NTAP-20210702-0001 — June 2021 Apache HTTP Server Vulnerabilities in NetApp Products
Published 2021-07-02 · Updated 2022-01-06 · Status: Final · Exploitation: Public · Severity: not scored · ONTAP affected: No — other NetApp product
Official advisory: NTAP-20210702-0001 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.
Product family: Cloud Backup / AltaVault / SteelStore | other NetApp product
CVEs in this advisory
- CVE-2019-17567 · site index
- CVE-2020-13938 · site index
- CVE-2020-13950 · site index
- CVE-2020-35452 · site index
- CVE-2021-26690 · site index
- CVE-2021-26691 · site index
- CVE-2021-30641 · site index
Impact
Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).
Affected products
- NetApp Cloud Backup (formerly AltaVault)
References
- https://httpd.apache.org/security/vulnerabilities_24.html ↗
- https://lists.apache.org/thread.html/r7f2b70b621651548f4b6f027552f1dd91705d7111bb5d15cda0a68dd@%3Cde ↗
- https://lists.apache.org/thread.html/re026d3da9d7824bd93b9f871c0fdda978d960c7e62d8c43cba8d0bf3%40%3C ↗
What to do
- Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
- Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
- Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
- Track follow-ups in the site CVE index and the security RSS feed.
Related reading
- Site CVE index — every CVE we track, split by year
- Security hub — recent NetApp advisories and what changed
- Security hardening baseline — applies to NetApp management planes generally
- Every NetApp advisory published in 2021