CERT-In Vulnerability Note
CIVN-2023-0395
Multiple Vulnerabilities in NetApp Products
Original Issue Date:December 29, 2023
Severity Rating: CRITICAL
Software Affected
- Active IQ Unified Manager for Linux
- Active IQ Unified Manager for Microsoft Windows
- Active IQ Unified Manager for VMware vSphere
Overview
Multiple vulnerabilities have been reported in NetApp Products, which could allow an attacker to obtain and disclose sensitive information, add or modify data or cause Denial of Service (DoS) attack on the targeted systems.
Description
These vulnerabilities exist due to flaw in HashiCorp Vault Enterprise, Vim, Infinispan, SLF4J, Spring Web Services components of NetApp products.
Successful exploitation of these vulnerabilities may allow an attacker to obtain and disclose sensitive information, add or modify data or cause Denial of Service (DoS) attack on the targeted systems.
Solution
Apply appropriate software updates as mentioned in NetApp advisories.
https://security.netapp.com/advisory/ntap-20231227-0001/
https://security.netapp.com/advisory/ntap-20231227-0002/
https://security.netapp.com/advisory/ntap-20231227-0003/
https://security.netapp.com/advisory/ntap-20231227-0004/
https://security.netapp.com/advisory/ntap-20231227-0005/
https://security.netapp.com/advisory/ntap-20231227-0006/
https://security.netapp.com/advisory/ntap-20231227-0007/
https://security.netapp.com/advisory/ntap-20231227-0008/
https://security.netapp.com/advisory/ntap-20231227-0009/
https://security.netapp.com/advisory/ntap-20231227-0010/
https://security.netapp.com/advisory/ntap-20231227-0011/
References
https://security.netapp.com/advisory/ntap-20231227-0001/
https://security.netapp.com/advisory/ntap-20231227-0002/
https://security.netapp.com/advisory/ntap-20231227-0003/
https://security.netapp.com/advisory/ntap-20231227-0004/
https://security.netapp.com/advisory/ntap-20231227-0005/
https://security.netapp.com/advisory/ntap-20231227-0006/
https://security.netapp.com/advisory/ntap-20231227-0007/
https://security.netapp.com/advisory/ntap-20231227-0008/
https://security.netapp.com/advisory/ntap-20231227-0009/
https://security.netapp.com/advisory/ntap-20231227-0010/
https://security.netapp.com/advisory/ntap-20231227-0011/
CVE Name
CVE-2023-5954
CVE-2023-48236
CVE-2023-48233
CVE-2023-48234
CVE-2023-48237
CVE-2023-48232
CVE-2023-48235
CVE-2023-48231
CVE-2019-10158
CVE-2018-8088
CVE-2019-3773
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|