Home / Security / Advisories / NTAP-20211210-0007

NTAP-20211210-0007 — CVE-2021-44228 Apache Log4j Vulnerability in NetApp Products

Published 2021-12-10 · Updated 2022-06-21 · Status: Final · Exploitation: Public · Severity: CRITICAL 10.0 · ONTAP affected: Yes

Official advisory: NTAP-20211210-0007 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.

Product family: Active IQ Unified Manager · Brocade SAN firmware · NetApp Console / BlueXP · SolidFire / NetApp HCI · ONTAP · OnCommand family · SnapCenter  |  ONTAP-relevant  |  highest CVSS: 10.0

CVEs in this advisory

What the CVE records say

CVE-2021-44228 — Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

Impact

Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). <br><br> SnapCenter evaluation included its bundled plugins: <br> SnapCenter for Oracle, SnapCenter for HANA, SnapCenter for SCC, SnapCenter for Windows, SnapCenter for SQL and SnapCenter for Exchange <br><br> NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software) is affected only when the “Virtual Volumes (vVols)” feature is enabled on the cluster. <br><br> Virtual Storage Console for VMware vSphere version 9.7.1 is no longer under Full Support but is Affected. The available options are to either upgrade to a Full Support and fixed version of the software or follow the ONTAP Tools for VMware vSphere Workaround. Versions of Virtual Storage Console for VMware prior to 9.7.1 include Apache Log4j version 1.x and are therefore Not Affected.

Affected products

Official fixes

References

What to do

  1. Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
  2. If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
  3. If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
  4. Harden in parallel: security hardening baseline and ransomware protection on ONTAP.

Related reading

Browse all ONTAP CVEs → · Security hub