{"status":"success","advisory":{"_id":"683547205b16347a91c39c5b","kb_acknowledgements":null,"kb_affected_list":["Cloud Manager","OnCommand Insight","OnCommand Performance Manager (Unified Manager Performance Pkg)","OnCommand Unified Manager for Clustered Data ONTAP","OnCommand Workflow Automation","StorageGRID (formerly StorageGRID Webscale)"],"kb_bad_data":false,"kb_cve":["CVE-2014-3569","CVE-2015-0405","CVE-2015-0423","CVE-2015-0433","CVE-2015-0438","CVE-2015-0439","CVE-2015-0441","CVE-2015-0498","CVE-2015-0499","CVE-2015-0500","CVE-2015-0501","CVE-2015-0503","CVE-2015-0505","CVE-2015-0506","CVE-2015-0507","CVE-2015-0508","CVE-2015-0511","CVE-2015-2566","CVE-2015-2567","CVE-2015-2568","CVE-2015-2571","CVE-2015-2573"],"kb_exploitation":"Public","kb_fixes":[{"product":"OnCommand Insight","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/sanscreen/7.1.1/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"OnCommand Unified Manager for Clustered Data ONTAP","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/oncommand_cdot_lin/6.2P1/","cves":[]},{"link":"http://mysupport.netapp.com/NOW/download/software/oncommand_cdot/6.2P1/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"StorageGRID (formerly StorageGRID Webscale)","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/storagegrid_webscale/10.3.0/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"OnCommand Performance Manager (Unified Manager Performance Pkg)","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/oncommand_pm_linux/1.1P1/","cves":[]},{"link":"http://mysupport.netapp.com/NOW/download/software/oncommand_pm/1.1P1/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"Cloud Manager","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/oncommand_cloud_lin/2.1/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"OnCommand Workflow Automation","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/ocwfa/3.1/","cves":[]},{"link":"http://mysupport.netapp.com/NOW/download/software/ocwfa_linux/3.1/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null}],"kb_impact":"Exploitation of this vulnerability may lead to successful unauthenticated or authenticated network attacks via multiple protocols or the unauthorized ability to cause a hang or frequently repeatable crash (partial or complete DOS) of MySQL Server or the Operating System.","kb_internal_notes":[{"burt":"907598","jira":"","product":"Cloud Manager"},{"burt":"907635","jira":"","product":"OnCommand Balance"},{"burt":"907601","jira":"","product":"OnCommand Insight"},{"burt":"907600","jira":"","product":"OnCommand Performance Manager (Unified Manager Performance Pkg)"},{"burt":"907599","jira":"","product":"OnCommand Unified Manager for Clustered Data ONTAP"},{"burt":"907604","jira":"","product":"OnCommand Workflow Automation"},{"burt":"907603","jira":"","product":"StorageGRID (formerly StorageGRID Webscale)"},{"burt":"907602","jira":"","product":"StorageGRID9 (9.x and prior)"}],"kb_investigating_list":[],"kb_num":"9010035","kb_ref":["http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html","http://www.oracle.com/technetwork/topics/security/cpuapr2015verbose-2365613.html#MSQL"],"kb_rev_history":[{"comment":"Initial Public Release","date":"20150417","version":"1.0"},{"comment":"Updated Affected Products","date":"20150423","version":"2.0"},{"comment":"Updated Affected Products & Products Not Affected","date":"20150514","version":"3.0"},{"comment":"Corrected the score for CVE-2015-0499","date":"20150519","version":"4.0"},{"comment":"Updated Software Versions and Fixes","date":"20150526","version":"5.0"},{"comment":"Updated Software Versions and Fixes","date":"20150527","version":"6.0"},{"comment":"Added StorageGRID & StorageGRID Webscale to Affected Products","date":"20150626","version":"7.0"},{"comment":"OnCommand Insight added to Software Versions and Fixes","date":"20150828","version":"8.0"},{"comment":"OnCommand Workflow Automation added to Software Versions and Fixes","date":"20151016","version":"9.0"},{"comment":"OnCommand Cloud Manager added to Software Versions and Fixes","date":"20151203","version":"10.0"},{"comment":"Formatting","date":"20160831","version":"11.0"},{"comment":"StorageGRID Webscale added to Software Versions and Fixes","date":"20160921","version":"12.0"},{"comment":"StorageGRID moved to Products not Affected, Final status","date":"20180731","version":"13.0"}],"kb_revised_list":[],"kb_scoring":{"CVE-2014-3569":"CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-0405":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-0423":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-0433":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-0438":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-0439":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-0441":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-0498":"CVSS:2.0/AV:N/AC:H/Au:M/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-0499":"CVSS:2.0/AV:N/AC:M/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-0500":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-0501":"CVSS:2.0/AV:N/AC:M/Au:M/C:N/I:N/A:C/E:U/RL:U/RC:C","CVE-2015-0503":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-0505":"CVSS:2.0/AV:N/AC:M/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-0506":"CVSS:2.0/AV:N/AC:M/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-0507":"CVSS:2.0/AV:N/AC:M/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-0508":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-0511":"CVSS:2.0/AV:N/AC:M/Au:M/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-2566":"CVSS:2.0/AV:N/AC:M/Au:M/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-2567":"CVSS:2.0/AV:N/AC:M/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-2568":"CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-2571":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C","CVE-2015-2573":"CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},"kb_scoring_calc":[{"cve_id":"CVE-2014-3569","range":"MEDIUM","score":4.3,"vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0405","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0423","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0433","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0438","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0439","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0441","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0498","range":"LOW","score":1.4,"vector":"AV:N/AC:H/Au:M/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0499","range":"LOW","score":3.0,"vector":"AV:N/AC:M/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0500","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0501","range":"MEDIUM","score":4.8,"vector":"AV:N/AC:M/Au:M/C:N/I:N/A:C/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0503","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0505","range":"LOW","score":3.0,"vector":"AV:N/AC:M/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0506","range":"LOW","score":3.0,"vector":"AV:N/AC:M/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0507","range":"LOW","score":3.0,"vector":"AV:N/AC:M/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0508","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-0511","range":"LOW","score":2.4,"vector":"AV:N/AC:M/Au:M/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-2566","range":"LOW","score":2.4,"vector":"AV:N/AC:M/Au:M/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-2567","range":"LOW","score":3.0,"vector":"AV:N/AC:M/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-2568","range":"MEDIUM","score":4.3,"vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-2571","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"},{"cve_id":"CVE-2015-2573","range":"LOW","score":3.4,"vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:U/RC:C"}],"kb_status":"Final","kb_summary":"Multiple NetApp products incorporate Oracle MySQL. MySQL versions below 5.6.24 and 5.5.43 are susceptible to multiple vulnerabilities that could lead to the unauthorized ability to cause a hang or frequently repeatable crash (partial or complete DOS) of MySQL Server or the Operating System. This advisory will be updated as additional information becomes available.","kb_title":"April 2015 MySQL Vulnerabilities in Multiple NetApp Products","kb_unaffected_list":["7-Mode Transition Tool","ATTO FibreBridge - 6500N","Brocade Fabric Operating System Firmware","Clustered Data ONTAP","Clustered Data ONTAP Antivirus Connector","E-Series SANtricity Storage Manager","E-Series SANtricity Web Services (REST API) for Web Services Proxy","FAS/AFF BIOS","Host Utilities - SAN for Linux","Host Utilities - SAN for Windows","NetApp Cloud Backup (formerly AltaVault)","NetApp Manageability SDK","NetApp NFS Plug-in for VMware VAAI","NetApp SANtricity SMI-S Provider","NetApp SMI-S Provider","NetApp Storage Encryption","OnCommand Balance","Open Systems SnapVault Agent","Service Processor","Single Mailbox Recovery","Snap Creator Framework","SnapDrive for Unix","SnapManager for Exchange","SnapManager for Hyper-V","SnapManager for Oracle","SnapManager for SAP","SnapManager for Sharepoint","Storage Services Connector","StorageGRID9 (9.x and prior)","System Manager 9.x"],"kb_workarounds":"<p> \r\nBeginning with OnCommand Workflow Automation for Linux & Windows 4.2, OnCommand Unified Manager for Linux & Windows 7.2, SnapCenter Server 3.0, NetApp Service Level Manager 1.0, and OnCommand API Services 1.2 the MySQL software can be upgraded as specified in the product documentation. For assistance with the upgrade, please consult technical support. \r\n<br><br> \r\nOnCommand Insight 7.3.2 and higher on Linux and 7.3.9 and higher on Windows support upgrading MySQL. For assistance with the upgrade and access to the updated OnCommand Insight binaries, please consult technical support. \r\n<br><br> \r\n</p>","ntap_advisory_id":"NTAP-20150417-0002","adv_id":"ntap-20150417-0002","published_date":"2015-04-17T00:00:00","updated_date":"2018-07-31T00:00:00","inserted_date":"2025-05-27T05:01:20.053000","modified_date":null}}