Home / Security / Advisories / NTAP-20210819-0007
NTAP-20210819-0007 — July 2021 Apache Ant Vulnerabilities in NetApp Products
Published 2021-08-19 · Updated 2022-08-03 · Status: Final · Exploitation: Public · Severity: not scored · ONTAP affected: No — other NetApp product
Official advisory: NTAP-20210819-0007 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.
Product family: Active IQ Unified Manager · Cloud Backup / AltaVault / SteelStore · SolidFire / NetApp HCI | other NetApp product
CVEs in this advisory
Impact
Successful exploitation of these vulnerabilities could lead to Denial of Service (DoS).
Affected products
- Active IQ Unified Manager for Linux
- Active IQ Unified Manager for Microsoft Windows
- NetApp Cloud Backup (formerly AltaVault)
- NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S
Official fixes
- Active IQ Unified Manager for Linux — vendor fix ↗
- Active IQ Unified Manager for Microsoft Windows — vendor fix ↗
References
- https://ant.apache.org/security.html ↗
- https://lists.apache.org/thread.html/r27919fd4db07c487239c1d9771f480d89ce5ee2750aa9447309b709a@%3Cco ↗
- https://lists.apache.org/thread.html/r544c9e8487431768465b8b2d13982c75123109bd816acf839d46010d@%3Cco ↗
What to do
- Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
- Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
- Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
- Track follow-ups in the site CVE index and the security RSS feed.
Related reading
- Site CVE index — every CVE we track, split by year
- Security hub — recent NetApp advisories and what changed
- Security hardening baseline — applies to NetApp management planes generally
- Every NetApp advisory published in 2021