Home / Security / Advisories / NTAP-20211210-0007
NTAP-20211210-0007 — CVE-2021-44228 Apache Log4j Vulnerability in NetApp Products
Published 2021-12-10 · Updated 2022-06-21 · Status: Final · Exploitation: Public · Severity: CRITICAL 10.0 · ONTAP affected: Yes
Product family: Active IQ Unified Manager · Brocade SAN firmware · NetApp Console / BlueXP · SolidFire / NetApp HCI · ONTAP · OnCommand family · SnapCenter | ONTAP-relevant | highest CVSS: 10.0
CVEs in this advisory
- CVE-2021-44228 — CRITICAL · CVSS 10.0 · site index
What the CVE records say
CVE-2021-44228 — Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Impact
Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). <br><br> SnapCenter evaluation included its bundled plugins: <br> SnapCenter for Oracle, SnapCenter for HANA, SnapCenter for SCC, SnapCenter for Windows, SnapCenter for SQL and SnapCenter for Exchange <br><br> NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software) is affected only when the “Virtual Volumes (vVols)” feature is enabled on the cluster. <br><br> Virtual Storage Console for VMware vSphere version 9.7.1 is no longer under Full Support but is Affected. The available options are to either upgrade to a Full Support and fixed version of the software or follow the ONTAP Tools for VMware vSphere Workaround. Versions of Virtual Storage Console for VMware prior to 9.7.1 include Apache Log4j version 1.x and are therefore Not Affected.
Affected products
- Active IQ Unified Manager for Linux
- Active IQ Unified Manager for Microsoft Windows
- Active IQ Unified Manager for VMware vSphere
- Brocade SAN Navigator (SANnav)
- Cloud Insights Acquisition Unit
- Cloud Manager
- Cloud Secure Agent
- NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software)
- ONTAP tools for VMware vSphere
- OnCommand Insight
- SnapCenter Plug-in for VMware vSphere
Official fixes
- NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software) — vendor fix ↗
- NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software) — vendor fix ↗
- Active IQ Unified Manager for Linux — vendor fix ↗
- Active IQ Unified Manager for Linux — vendor fix ↗
- Active IQ Unified Manager for Linux — vendor fix ↗
- Active IQ Unified Manager for Linux — vendor fix ↗
- ONTAP tools for VMware vSphere — vendor fix ↗
- ONTAP tools for VMware vSphere — vendor fix ↗
- Active IQ Unified Manager for VMware vSphere — vendor fix ↗
- Active IQ Unified Manager for VMware vSphere — vendor fix ↗
- Active IQ Unified Manager for VMware vSphere — vendor fix ↗
- Active IQ Unified Manager for VMware vSphere — vendor fix ↗
References
- https://logging.apache.org/log4j/2.x/security.html ↗
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advis ↗
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2021