{"status":"success","advisory":{"_id":"6835471f5b16347a91c39c44","kb_acknowledgements":null,"kb_affected_list":["7-Mode Transition Tool","MetroCluster Plug-in for vSphere","NetApp VASA Provider for Clustered Data ONTAP 9.7 and above","NetApp VASA Provider for Data ONTAP operating in 7-Mode","OnCommand Balance","OnCommand Insight","OnCommand Report","OnCommand Unified Manager Core Package","OnCommand Unified Manager Host Package","OnCommand Workflow Automation","SnapManager for Oracle","SnapManager for SAP","Virtual Storage Console for VMware vSphere 9.7 and above"],"kb_bad_data":false,"kb_cve":["CVE-2013-1620","CVE-2013-1741","CVE-2013-5855","CVE-2014-2479","CVE-2014-2480","CVE-2014-2481","CVE-2014-2493","CVE-2014-4201","CVE-2014-4202","CVE-2014-4210","CVE-2014-4211","CVE-2014-4212","CVE-2014-4217","CVE-2014-4222","CVE-2014-4241","CVE-2014-4242","CVE-2014-4249","CVE-2014-4251","CVE-2014-4253","CVE-2014-4254","CVE-2014-4255","CVE-2014-4256","CVE-2014-4257","CVE-2014-4267"],"kb_exploitation":"Public","kb_fixes":[{"product":"OnCommand Unified Manager Host Package","fixes":[],"instructions":null,"wontfix":true,"eos_link":"http://library-clnt.dmz.netapp.com/info/communications/ECMP1400690.html"},{"product":"OnCommand Unified Manager Core Package","fixes":[{"link":"https://mysupport.netapp.com/NOW/download/software/occore_lin/5.2.2/","cves":[]},{"link":"https://mysupport.netapp.com/NOW/download/software/occore_win/5.2.2/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"SnapManager for Oracle","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/snapmanager_oracle_win/3.4/","cves":[]},{"link":"http://mysupport.netapp.com/NOW/download/software/snapmanager_oracle_unix/3.4/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"NetApp VASA Provider for Data ONTAP operating in 7-Mode","fixes":[],"instructions":null,"wontfix":true,"eos_link":"https://mysupport.netapp.com/info/communications/ECMLP2804177.html"},{"product":"Virtual Storage Console for VMware vSphere 9.7 and above","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/vsc_win/5.0P1/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"NetApp VASA Provider for Clustered Data ONTAP 9.7 and above","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/vasa_cdot/5.0P1/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"SnapManager for SAP","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/snapmanager_sap_win/3.4P2/","cves":[]},{"link":"http://mysupport.netapp.com/NOW/download/software/snapmanager_sap_unix/3.4P2/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"OnCommand Insight","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/sanscreen/7.0.3/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"OnCommand Balance","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/oncommand_ib/4.2.1/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"OnCommand Report","fixes":[],"instructions":null,"wontfix":true,"eos_link":"http://mysupport.netapp.com/info/communications/ECMP1397557.html"},{"product":"MetroCluster Plug-in for vSphere","fixes":[],"instructions":null,"wontfix":true,"eos_link":"http://library-clnt.dmz.netapp.com/info/communications/ECMLP2415723.html"},{"product":"7-Mode Transition Tool","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/ntap_7mtt/2.1/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"OnCommand Workflow Automation","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/ocwfa/2.2.1/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null}],"kb_impact":"Exploitation of this vulnerability may lead to unauthorized disclosure of information.","kb_internal_notes":[{"burt":"841688","jira":"","product":"7-Mode Transition Tool"},{"burt":"841680","jira":"","product":"MetroCluster Plug-in for vSphere"},{"burt":"861839","jira":"","product":"NetApp VASA Provider for Clustered Data ONTAP 9.7 and above"},{"burt":"841689","jira":"","product":"NetApp VASA Provider for Data ONTAP operating in 7-Mode"},{"burt":"841677","jira":"","product":"OnCommand Balance"},{"burt":"799136","jira":"","product":"OnCommand Balance"},{"burt":"841684","jira":"","product":"OnCommand Insight"},{"burt":"841683","jira":"","product":"OnCommand Performance Manager (Unified Manager Performance Pkg)"},{"burt":"841681","jira":"","product":"OnCommand Report"},{"burt":"841678","jira":"","product":"OnCommand Unified Manager Core Package"},{"burt":"841679","jira":"","product":"OnCommand Unified Manager Host Package"},{"burt":"841682","jira":"","product":"OnCommand Unified Manager for Clustered Data ONTAP"},{"burt":"841691","jira":"","product":"OnCommand Workflow Automation"},{"burt":"841685","jira":"","product":"SnapManager for Oracle"},{"burt":"900660","jira":"","product":"SnapManager for SAP"},{"burt":"900661","jira":"","product":"StorageGRID (formerly StorageGRID Webscale)"},{"burt":"841690","jira":"","product":"Virtual Storage Console for VMware vSphere 9.7 and above"}],"kb_investigating_list":[],"kb_num":"9010013","kb_ref":["http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html#AppendixJAVA"],"kb_rev_history":[{"comment":"Initial Public Release","date":"20141028","version":"1.0"},{"comment":"Corrected CVEID in Summary","date":"20141117","version":"2.0"},{"comment":"Updated Software Versions and Fixes","date":"20141126","version":"3.0"},{"comment":"Updated Affected Products and Software Versions and Fixes","date":"20141201","version":"4.0"},{"comment":"Updated Workarounds","date":"20141203","version":"5.0"},{"comment":"Updated Software Versions and Fixes","date":"20150202","version":"6.0"},{"comment":"Updated Affected Products, Products Not Affected, and Software Versions and Fixes, removed NetApp Management Console as it is tracked as a part of OnCommand Unified Manager Core Package (5.x)","date":"20150309","version":"7.0"},{"comment":"Updated Affected Products and Software Versions and Fixes","date":"20150327","version":"8.0"},{"comment":"Updated Software Versions and Fixes","date":"20150514","version":"9.0"},{"comment":"Updated Affected Products & Products Not Affected","date":"20150625","version":"10.0"},{"comment":"7-Mode Transition Tool & E-Series/EF-Series SANtricity Storage Manager added to Software Versions and Fixes","date":"20150916","version":"11.0"},{"comment":"MetroCluster Plug-in for vSphere removed due to EOA","date":"20160126","version":"12.0"},{"comment":"OnCommand Balance added to Software Versions and Fixes","date":"20160510","version":"13.0"},{"comment":"SnapManager for Oracle, SnapManager for SAP added to Software Versions and Fixes","date":"20160901","version":"14.0"},{"comment":"OnCommand Unified Manager Core Package 5.x added to Software Versions and Fixes, Final status","date":"20170322","version":"15.0"}],"kb_revised_list":[],"kb_scoring":{"CVE-2014-2483":"CVSS:2.0/AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C","CVE-2014-2490":"CVSS:2.0/AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C","CVE-2014-4208":"CVSS:2.0/AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C","CVE-2014-4209":"CVSS:2.0/AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:C","CVE-2014-4216":"CVSS:2.0/AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C","CVE-2014-4218":"CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:C","CVE-2014-4219":"CVSS:2.0/AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C","CVE-2014-4220":"CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:C","CVE-2014-4221":"CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C","CVE-2014-4223":"CVSS:2.0/AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C","CVE-2014-4227":"CVSS:2.0/AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C","CVE-2014-4244":"CVSS:2.0/AV:N/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:U/RC:C","CVE-2014-4247":"CVSS:2.0/AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C","CVE-2014-4252":"CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C","CVE-2014-4262":"CVSS:2.0/AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C","CVE-2014-4263":"CVSS:2.0/AV:N/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:U/RC:C","CVE-2014-4264":"CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2014-4265":"CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:C","CVE-2014-4266":"CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:C","CVE-2014-4268":"CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C"},"kb_scoring_calc":[{"cve_id":"CVE-2014-2483","range":"HIGH","score":7.9,"vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-2490","range":"HIGH","score":7.9,"vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4208","range":"HIGH","score":7.9,"vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4209","range":"LOW","score":2.2,"vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4216","range":"HIGH","score":7.9,"vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4218","range":"MEDIUM","score":4.3,"vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4219","range":"HIGH","score":7.9,"vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4220","range":"MEDIUM","score":4.3,"vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4221","range":"LOW","score":3.7,"vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4223","range":"HIGH","score":7.9,"vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4227","range":"HIGH","score":8.5,"vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4244","range":"LOW","score":3.4,"vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4247","range":"HIGH","score":7.9,"vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4252","range":"MEDIUM","score":4.3,"vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4262","range":"HIGH","score":7.9,"vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4263","range":"LOW","score":3.4,"vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4264","range":"MEDIUM","score":4.3,"vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4265","range":"MEDIUM","score":4.3,"vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4266","range":"MEDIUM","score":4.3,"vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4268","range":"MEDIUM","score":4.3,"vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C"}],"kb_status":"Final","kb_summary":"Multiple NetApp products incorporate the Java Runtime Environment (JRE) software libraries. JRE versions up to 5u65, 6u75, 7u60 and 8u5 are susceptible to multiple vulnerabilities, potentially leading to an unauthorized Operating System takeover including arbitrary code execution or to unauthorized update, insert or delete access to some Java SE accessible data. This advisory will be updated as additional information becomes available.","kb_title":"July 2014 Java Runtime Environment (JRE) vulnerabilities in Multiple NetApp Products","kb_unaffected_list":["ATTO FibreBridge - 6500N","Brocade Fabric Operating System Firmware","Cloud Manager","Clustered Data ONTAP","Clustered Data ONTAP Antivirus Connector","E-Series SANtricity Storage Manager","E-Series SANtricity Web Services (REST API) for Web Services Proxy","FAS/AFF BIOS","Host Utilities - SAN for Linux","Host Utilities - SAN for Windows","NetApp Cloud Backup (formerly AltaVault)","NetApp Manageability SDK","NetApp NFS Plug-in for VMware VAAI","NetApp SANtricity SMI-S Provider","NetApp SMI-S Provider","NetApp Storage Encryption","OnCommand Performance Manager (Unified Manager Performance Pkg)","OnCommand Unified Manager for Clustered Data ONTAP","Open Systems SnapVault Agent","Service Processor","Single Mailbox Recovery","Snap Creator Framework","SnapDrive for Unix","SnapManager for Exchange","SnapManager for Hyper-V","SnapManager for Sharepoint","Storage Services Connector","StorageGRID (formerly StorageGRID Webscale)","StorageGRID9 (9.x and prior)","System Manager 9.x"],"kb_workarounds":"<br>If a product requires JRE but does not include it, please update JRE to a fixed version that aligns with the product requirements.\r\n<ul><li>Updating the Java Runtime Environment (JRE) used by SANtricity Storage Manager 11.10 or later <a href=\"https://kb.netapp.com/support/index?page=content&amp;id=1014947\" target=\"_blank\">https://kb.netapp.com/support/index?page=content&amp;id=1014947 </a></li></ul>","ntap_advisory_id":"NTAP-20141028-0001","adv_id":"ntap-20141028-0001","published_date":"2014-10-28T00:00:00","updated_date":"2017-03-22T00:00:00","inserted_date":"2025-05-27T05:01:19.685000","modified_date":null}}