Home / Security / Advisories / NTAP-20260123-0013
NTAP-20260123-0013 — January 2026 Java Platform Standard Edition 8u471-b50 Vulnerabilities in NetApp Products
Published 2026-01-23 · Updated 2026-08-05 · Status: Interim · Exploitation: Public · Severity: HIGH 7.8 · ONTAP affected: No — other NetApp product
Product family: SolidFire / NetApp HCI | other NetApp product | highest CVSS: 7.8
CVEs in this advisory
- CVE-2025-47219 · site index
- CVE-2026-21947 · site index
- CVE-2025-6052 · site index
- CVE-2025-7425 — HIGH · CVSS 7.8 · site index
- CVE-2025-43368 · site index
- CVE-2025-6021 — HIGH · CVSS 7.5 · site index
What the CVE records say
CVE-2025-7425 — A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
CVE-2025-6021 — A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
Impact
Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data, unauthorized read access to a subset of Oracle Java SE accessible data, unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE or a takeover of Oracle Java SE.
Affected products
- NetApp SolidFire & HCI Management Node
References
- https://www.oracle.com/security-alerts/cpujan2026.html ↗
- https://www.oracle.com/security-alerts/cpujan2026.html#AppendixJAVA ↗
- https://www.oracle.com/security-alerts/cpujan2026verbose.html#JAVA ↗
What to do
- Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
- Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
- Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
- Track follow-ups in the site CVE index and the security RSS feed.
Related reading
- Site CVE index — every CVE we track, split by year
- Security hub — recent NetApp advisories and what changed
- Security hardening baseline — applies to NetApp management planes generally
- Every NetApp advisory published in 2026