{"status":"success","advisory":{"_id":"6835471f5b16347a91c39c49","kb_acknowledgements":null,"kb_affected_list":["Cloud Manager","OnCommand Insight","OnCommand Performance Manager (Unified Manager Performance Pkg)","OnCommand Unified Manager for Clustered Data ONTAP","OnCommand Workflow Automation","StorageGRID (formerly StorageGRID Webscale)"],"kb_bad_data":false,"kb_cve":["CVE-2014-6507","CVE-2014-6491","CVE-2014-6500","CVE-2014-6469","CVE-2014-0224","CVE-2014-6530","CVE-2014-6555","CVE-2014-6489","CVE-2012-5615","CVE-2014-6559","CVE-2014-6494","CVE-2014-6496","CVE-2014-6495","CVE-2014-6478","CVE-2014-4274","CVE-2014-4287","CVE-2014-6520","CVE-2014-6484","CVE-2014-6464","CVE-2014-6564","CVE-2014-6505","CVE-2014-6474","CVE-2014-6463","CVE-2014-6551"],"kb_exploitation":"Public","kb_fixes":[{"product":"OnCommand Insight","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/sanscreen/7.0.3/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"OnCommand Unified Manager for Clustered Data ONTAP","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/oncommand_cdot_win/7.0/","cves":[]},{"link":"http://mysupport.netapp.com/NOW/download/software/oncommand_cdot_lin/7.0/","cves":[]},{"link":"http://mysupport.netapp.com/NOW/download/software/oncommand_cdot/7.0/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"StorageGRID (formerly StorageGRID Webscale)","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/storagegrid_webscale/10.1/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"OnCommand Performance Manager (Unified Manager Performance Pkg)","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/oncommand_pm/1.0R2/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"Cloud Manager","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/oncommand_cloud/1.1/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"OnCommand Workflow Automation","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/ocwfa/3.0/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null}],"kb_impact":"Exploitation of this vulnerability may lead to unauthorized takeover of MySQL Server possibly including arbitrary code execution within the MySQL Server, unauthorized ability to cause a hang or frequently repeatable crash (partial or complete DOS) of MySQL Server or the Operating System, and unauthorized read, update, insert or delete access to a subset or all MySQL Server accessible data.","kb_internal_notes":[{"burt":"861814","jira":"","product":"Cloud Manager"},{"burt":"861812","jira":"","product":"OnCommand Balance"},{"burt":"861817","jira":"","product":"OnCommand Insight"},{"burt":"861816","jira":"","product":"OnCommand Performance Manager (Unified Manager Performance Pkg)"},{"burt":"861815","jira":"","product":"OnCommand Unified Manager for Clustered Data ONTAP"},{"burt":"861820","jira":"","product":"OnCommand Workflow Automation"},{"burt":"861818","jira":"","product":"StorageGRID (formerly StorageGRID Webscale)"},{"burt":"861819","jira":"","product":"StorageGRID9 (9.x and prior)"}],"kb_investigating_list":[],"kb_num":"9010017","kb_ref":["http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html#AppendixMSQL","https://support.oracle.com/epmos/faces/DocumentDisplay?id=1926629.1&_adf.ctrl-state=u4wgyjryo_4&_afrLoop=332299117828705"],"kb_rev_history":[{"comment":"Initial Release","date":"20141119","version":"1.0"},{"comment":"Publish externally","date":"20141119","version":"2.0"},{"comment":"Formatting; updated Products Not Affected","date":"20141121","version":"3.0"},{"comment":"Updated Affected Products","date":"20141211","version":"4.0"},{"comment":"Formatting edits to align with other advisory documents; updated Affected Products","date":"20150123","version":"5.0"},{"comment":"Updated Software Versions and Fixes","date":"20150213","version":"6.0"},{"comment":"Updated Software Versions and Fixes","date":"20150326","version":"7.0"},{"comment":"Updated Software Versions and Fixes","date":"20150514","version":"8.0"},{"comment":"Updated Affected Products & Software Versions and Fixes","date":"20150625","version":"9.0"},{"comment":"StoraqeGRID moved to Products Not Affected, Final status","date":"20180731","version":"10.0"}],"kb_revised_list":[],"kb_scoring":{"CVE-2012-5615":"CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C","CVE-2014-0224":"CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:C","CVE-2014-4274":"CVSS:2.0/AV:L/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:U/RC:C","CVE-2014-4287":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2014-6463":"CVSS:2.0/AV:N/AC:L/Au:M/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2014-6464":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2014-6469":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:C/E:U/RL:U/RC:C","CVE-2014-6474":"CVSS:2.0/AV:N/AC:M/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2014-6478":"CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C","CVE-2014-6484":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2014-6489":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:P/A:P/E:U/RL:U/RC:C","CVE-2014-6491":"CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:C","CVE-2014-6494":"CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2014-6495":"CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2014-6496":"CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2014-6500":"CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:C","CVE-2014-6505":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2014-6507":"CVSS:2.0/AV:N/AC:L/Au:S/C:P/I:P/A:C/E:U/RL:U/RC:C","CVE-2014-6520":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2014-6530":"CVSS:2.0/AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:ND/RC:C","CVE-2014-6551":"CVSS:2.0/AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C","CVE-2014-6555":"CVSS:2.0/AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:U/RC:C","CVE-2014-6559":"CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C","CVE-2014-6564":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},"kb_scoring_calc":[{"cve_id":"CVE-2012-5615","range":"MEDIUM","score":4.3,"vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-0224","range":"MEDIUM","score":5.8,"vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4274","range":"LOW","score":3.5,"vector":"AV:L/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4287","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6463","range":"LOW","score":2.8,"vector":"AV:N/AC:L/Au:M/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6464","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6469","range":"MEDIUM","score":5.8,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:C/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6474","range":"LOW","score":3.0,"vector":"AV:N/AC:M/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6478","range":"MEDIUM","score":4.3,"vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6484","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6489","range":"MEDIUM","score":4.7,"vector":"AV:N/AC:L/Au:S/C:N/I:P/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6491","range":"MEDIUM","score":6.4,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6494","range":"LOW","score":3.7,"vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6495","range":"LOW","score":3.7,"vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6496","range":"LOW","score":3.7,"vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6500","range":"MEDIUM","score":6.4,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6505","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6507","range":"MEDIUM","score":6.8,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:C/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6520","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6530","range":"MEDIUM","score":5.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:ND/RC:C"},{"cve_id":"CVE-2014-6551","range":"LOW","score":1.8,"vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6555","range":"MEDIUM","score":5.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6559","range":"LOW","score":3.7,"vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-6564","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"}],"kb_status":"Final","kb_summary":"Multiple NetApp products incorporate Oracle MySQL. MySQL versions up to 5.6.20 and 5.5.39 are susceptible to multiple vulnerabilities, which are addressed in versions 5.6.21 and 5.5.40. This advisory will be updated as additional information becomes available.","kb_title":"October 2014 Oracle MySQL vulnerabilities in Multiple NetApp Products","kb_unaffected_list":["7-Mode Transition Tool","ATTO FibreBridge - 6500N","Brocade Fabric Operating System Firmware","Clustered Data ONTAP","Clustered Data ONTAP Antivirus Connector","E-Series SANtricity Storage Manager","E-Series SANtricity Web Services (REST API) for Web Services Proxy","FAS/AFF BIOS","Host Utilities - SAN for Linux","Host Utilities - SAN for Windows","NetApp Cloud Backup (formerly AltaVault)","NetApp Manageability SDK","NetApp NFS Plug-in for VMware VAAI","NetApp SANtricity SMI-S Provider","NetApp SMI-S Provider","NetApp Storage Encryption","OnCommand Balance","Open Systems SnapVault Agent","Service Processor","Single Mailbox Recovery","Snap Creator Framework","SnapDrive for Unix","SnapManager for Exchange","SnapManager for Hyper-V","SnapManager for Oracle","SnapManager for SAP","SnapManager for Sharepoint","Storage Services Connector","StorageGRID9 (9.x and prior)","System Manager 9.x"],"kb_workarounds":null,"ntap_advisory_id":"NTAP-20141119-0001","adv_id":"ntap-20141119-0001","published_date":"2014-11-19T00:00:00","updated_date":"2018-07-31T00:00:00","inserted_date":"2025-05-27T05:01:19.763000","modified_date":null}}