{"status":"success","advisory":{"_id":"6835471f5b16347a91c39c4a","kb_acknowledgements":null,"kb_affected_list":["OnCommand Balance","OnCommand Insight","OnCommand Report","OnCommand Workflow Automation"],"kb_bad_data":false,"kb_cve":["CVE-2014-2484","CVE-2014-2494","CVE-2014-4207","CVE-2014-4214","CVE-2014-4233","CVE-2014-4238","CVE-2014-4240","CVE-2014-4243","CVE-2014-4258","CVE-2014-4260"],"kb_exploitation":"Public","kb_fixes":[{"product":"OnCommand Insight","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/sanscreen/7.0.3/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"OnCommand Balance","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/oncommand_ib/4.2.1/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"OnCommand Workflow Automation","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/ocwfa/3.0/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"OnCommand Report","fixes":[],"instructions":null,"wontfix":true,"eos_link":"http://mysupport.netapp.com/info/communications/ECMP1397557.html"}],"kb_impact":"Exploitation of this vulnerability may lead to unauthorized takeover of MySQL Server possibly including arbitrary code execution within the MySQL Server, unauthorized ability to cause a hang or frequently repeatable crash (partial or complete DOS) of MySQL Server or the Operating System, and unauthorized read, update, insert or delete access to a subset or all MySQL Server accessible data.","kb_internal_notes":[{"burt":"841695","jira":"","product":"OnCommand Balance"},{"burt":"841700","jira":"","product":"OnCommand Insight"},{"burt":"841699","jira":"","product":"OnCommand Performance Manager (Unified Manager Performance Pkg)"},{"burt":"841697","jira":"","product":"OnCommand Report"},{"burt":"841698","jira":"","product":"OnCommand Unified Manager for Clustered Data ONTAP"},{"burt":"841703","jira":"","product":"OnCommand Workflow Automation"},{"burt":"841702","jira":"","product":"StorageGRID9 (9.x and prior)"}],"kb_investigating_list":[],"kb_num":"9010018","kb_ref":["http://www.oracle.com/technetwork/topics/security/cpujul2014verbose-1972958.html#MSQL"],"kb_rev_history":[{"comment":"Initial Public Release","date":"20141125","version":"1.0"},{"comment":"Updated Software Versions and Fixes","date":"20150326","version":"2.0"},{"comment":"Updated Software Versions and Fixes","date":"20150514","version":"3.0"},{"comment":"OnCommand Balance added to Software Versions and Fixes","date":"20160510","version":"4.0"},{"comment":"OnCommand Report removed due to EOS; Status changed to Final.","date":"20160823","version":"5.0"}],"kb_revised_list":[],"kb_scoring":{"CVE-2014-2484":"CVSS:2.0/AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:U/RC:C","CVE-2014-2494":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2014-4207":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2014-4214":"CVSS:2.0/AV:N/AC:L/Au:M/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2014-4233":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:ND/RC:C","CVE-2014-4238":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:ND/RC:C","CVE-2014-4240":"CVSS:2.0/AV:L/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:U/RC:C","CVE-2014-4243":"CVSS:2.0/AV:N/AC:M/Au:M/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2014-4258":"CVSS:2.0/AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:U/RC:C","CVE-2014-4260":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:P/A:P/E:U/RL:U/RC:C"},"kb_scoring_calc":[{"cve_id":"CVE-2014-2484","range":"MEDIUM","score":5.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-2494","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4207","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4214","range":"LOW","score":2.8,"vector":"AV:N/AC:L/Au:M/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4233","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:ND/RC:C"},{"cve_id":"CVE-2014-4238","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:ND/RC:C"},{"cve_id":"CVE-2014-4240","range":"LOW","score":3.1,"vector":"AV:L/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4243","range":"LOW","score":2.4,"vector":"AV:N/AC:M/Au:M/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4258","range":"MEDIUM","score":5.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2014-4260","range":"MEDIUM","score":4.7,"vector":"AV:N/AC:L/Au:S/C:N/I:P/A:P/E:U/RL:U/RC:C"}],"kb_status":"Final","kb_summary":"Multiple NetApp products incorporate Oracle MySQL. MySQL versions up to 5.6.18 and 5.5.37 are susceptible to multiple vulnerabilities, which are addressed in versions 5.6.19 and 5.5.38. This advisory will be updated as additional information becomes available.","kb_title":"July 2014 Oracle MySQL vulnerabilities in Multiple NetApp Products","kb_unaffected_list":["7-Mode Transition Tool","ATTO FibreBridge - 6500N","Brocade Fabric Operating System Firmware","Cloud Manager","Clustered Data ONTAP","Clustered Data ONTAP Antivirus Connector","E-Series SANtricity Storage Manager","E-Series SANtricity Web Services (REST API) for Web Services Proxy","FAS/AFF BIOS","Host Utilities - SAN for Linux","Host Utilities - SAN for Windows","NetApp Cloud Backup (formerly AltaVault)","NetApp Manageability SDK","NetApp NFS Plug-in for VMware VAAI","NetApp SANtricity SMI-S Provider","NetApp SMI-S Provider","NetApp Storage Encryption","OnCommand Performance Manager (Unified Manager Performance Pkg)","OnCommand Unified Manager for Clustered Data ONTAP","Open Systems SnapVault Agent","Service Processor","Single Mailbox Recovery","Snap Creator Framework","SnapDrive for Unix","SnapManager for Exchange","SnapManager for Hyper-V","SnapManager for Oracle","SnapManager for SAP","SnapManager for Sharepoint","Storage Services Connector","StorageGRID (formerly StorageGRID Webscale)","StorageGRID9 (9.x and prior)","System Manager 9.x"],"kb_workarounds":null,"ntap_advisory_id":"NTAP-20141125-0001","adv_id":"ntap-20141125-0001","published_date":"2014-11-25T00:00:00","updated_date":"2016-08-23T00:00:00","inserted_date":"2025-05-27T05:01:19.778000","modified_date":null}}