Home / Security / Advisories / NTAP-20260123-0013

NTAP-20260123-0013 — January 2026 Java Platform Standard Edition 8u471-b50 Vulnerabilities in NetApp Products

Published 2026-01-23 · Updated 2026-08-05 · Status: Interim · Exploitation: Public · Severity: HIGH 7.8 · ONTAP affected: No — other NetApp product

Official advisory: NTAP-20260123-0013 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.

Product family: SolidFire / NetApp HCI  |  other NetApp product  |  highest CVSS: 7.8

CVEs in this advisory

What the CVE records say

CVE-2025-7425 — A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.

CVE-2025-6021 — A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.

Impact

Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data, unauthorized read access to a subset of Oracle Java SE accessible data, unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE or a takeover of Oracle Java SE.

Affected products

References

What to do

  1. Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
  2. Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
  3. Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
  4. Track follow-ups in the site CVE index and the security RSS feed.

Related reading

Browse all ONTAP CVEs → · Security hub