Home / Security / Advisories / NTAP-20220729-0004
NTAP-20220729-0004 — July 2022 MySQL Server Vulnerabilities in NetApp Products
Published 2022-07-29 · Updated 2024-03-11 · Status: Final · Exploitation: Public · Severity: HIGH 8.1 · ONTAP affected: No — other NetApp product
Product family: Active IQ Unified Manager · OnCommand family · SnapCenter | other NetApp product | highest CVSS: 8.1
CVEs in this advisory
- CVE-2018-25032 — HIGH · CVSS 7.5 · site index
- CVE-2022-1292 — HIGH · CVSS 7.3 · site index
- CVE-2022-21455 · site index
- CVE-2022-21509 · site index
- CVE-2022-21515 · site index
- CVE-2022-21517 · site index
- CVE-2022-21519 · site index
- CVE-2022-21522 · site index
- CVE-2022-21525 · site index
- CVE-2022-21526 · site index
- CVE-2022-21527 · site index
- CVE-2022-21528 · site index
- CVE-2022-21529 · site index
- CVE-2022-21530 · site index
- CVE-2022-21531 · site index
- CVE-2022-21534 · site index
- CVE-2022-21537 · site index
- CVE-2022-21538 · site index
- CVE-2022-21539 · site index
- CVE-2022-21547 · site index
- CVE-2022-21550 · site index
- CVE-2022-21553 · site index
- CVE-2022-21556 · site index
- CVE-2022-21569 · site index
- CVE-2022-21824 · site index
- CVE-2022-27778 — HIGH · CVSS 8.1 · site index
What the CVE records say
CVE-2018-25032 — zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
CVE-2022-1292 — The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).
CVE-2022-27778 — A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
Impact
Successful exploitation of these vulnerabilities may lead to unauthorized takeover of MySQL Server, unauthorized read or modification access to a subset or all of the MySQL Server accessible data, or to a hang or frequently repeatable crash (partial or complete DoS) of MySQL Server.
Affected products
- Active IQ Unified Manager for Microsoft Windows
- Active IQ Unified Manager for VMware vSphere
- OnCommand Insight
- OnCommand Workflow Automation
- SnapCenter
Official fixes
- Active IQ Unified Manager for Microsoft Windows — vendor fix ↗
- Active IQ Unified Manager for VMware vSphere — vendor fix ↗
- OnCommand Insight — vendor fix ↗
- OnCommand Workflow Automation — vendor fix ↗
- SnapCenter — vendor fix ↗
References
- https://www.oracle.com/security-alerts/ ↗
- https://www.oracle.com/security-alerts/cpujul2022verbose.html#MSQL ↗
- https://www.oracle.com/security-alerts/cpujul2022.html#AppendixMSQL ↗
What to do
- Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
- Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
- Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
- Track follow-ups in the site CVE index and the security RSS feed.
Related reading
- Site CVE index — every CVE we track, split by year
- Security hub — recent NetApp advisories and what changed
- Security hardening baseline — applies to NetApp management planes generally
- Every NetApp advisory published in 2022