{"status":"success","advisory":{"_id":"683547265b16347a91c39de8","kb_acknowledgements":null,"kb_affected_list":["Active IQ Unified Manager for VMware vSphere","Data ONTAP Edge","NetApp Manageability SDK","NetApp Plug-in for Symantec NetBackup","NetApp SMI-S Provider","ONTAP 9 (formerly Clustered Data ONTAP)","ONTAP Antivirus Connector","ONTAP Select Deploy administration utility","SnapDrive for Unix"],"kb_bad_data":false,"kb_cve":["CVE-2017-5130","CVE-2017-18258"],"kb_exploitation":"Public","kb_fixes":[{"product":"ONTAP 9 (formerly Clustered Data ONTAP)","fixes":[{"link":"https://mysupport.netapp.com/site/products/all/details/ontap9/downloads-tab/download/62286/9.1P14/","cves":[]},{"link":"https://mysupport.netapp.com/site/products/all/details/ontap9/downloads-tab/download/62286/9.3P5","cves":[]},{"link":"https://mysupport.netapp.com/site/products/all/details/ontap9/downloads-tab/download/62286/9.4/","cves":[]},{"link":"https://mysupport.netapp.com/site/products/all/details/ontap9/downloads-tab/download/62286/9.5/","cves":[]},{"link":"https://mysupport.netapp.com/site/products/all/details/ontap9/downloads-tab/download/62286/9.6/","cves":[]},{"link":"https://mysupport.netapp.com/site/products/all/details/ontap9/downloads-tab/download/62286/9.7/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"ONTAP Antivirus Connector","fixes":[{"link":"https://mysupport.netapp.com/NOW/download/software/ontap_av_connector/1.0.4/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"Data ONTAP Edge","fixes":[],"instructions":null,"wontfix":true,"eos_link":"https://mysupport.netapp.com/info/communications/ECMLP2630722.html"},{"product":"NetApp Manageability SDK","fixes":[{"link":"https://mysupport.netapp.com/NOW/download/software/nmsdk/9.4/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"NetApp Plug-in for Symantec NetBackup","fixes":[],"instructions":null,"wontfix":true,"eos_link":"https://mysupport.netapp.com/info/communications/ECMLP2875531.html"},{"product":"NetApp SMI-S Provider","fixes":[{"link":"https://mysupport.netapp.com/products/smis/5.2.5/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"Active IQ Unified Manager for VMware vSphere","fixes":[{"link":"https://mysupport.netapp.com/NOW/download/software/oncommand_um/7.3P1/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"ONTAP Select Deploy administration utility","fixes":[{"link":"https://mysupport.netapp.com/site/products/all/details/ontapselect-deploy/downloads-tab/download/62910/9.13.1","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"SnapDrive for Unix","fixes":[{"link":"https://mysupport.netapp.com/NOW/cgi-bin/license.cgi/download/software/snapdrive_redhatlinux/5.3.2/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null}],"kb_impact":"Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).","kb_internal_notes":[{"burt":"1156387","jira":"","product":"7-Mode Transition Tool"},{"burt":"1156400","jira":"","product":"Active IQ Unified Manager for Microsoft Windows"},{"burt":"1156399","jira":"","product":"Active IQ Unified Manager for VMware vSphere"},{"burt":"1156390","jira":"","product":"Data ONTAP Edge"},{"burt":"1156396","jira":"","product":"NetApp Cloud Backup (formerly AltaVault)"},{"burt":"","jira":"","product":"NetApp HCI Compute Node (Bootstrap OS)"},{"burt":"","jira":"","product":"NetApp HCI Storage Nodes"},{"burt":"1156393","jira":"","product":"NetApp Manageability SDK"},{"burt":"1156394","jira":"","product":"NetApp Plug-in for Symantec NetBackup"},{"burt":"1156391","jira":"","product":"NetApp SMI-S Provider"},{"burt":"","jira":"","product":"NetApp SolidFire & HCI Management Node"},{"burt":"","jira":"","product":"NetApp SolidFire & HCI Storage Node (Element Software)"},{"burt":"1156395","jira":"","product":"NetApp SteelStore Cloud Integrated Storage"},{"burt":"1156397","jira":"","product":"NetApp VASA Provider for Clustered Data ONTAP 9.7 and above"},{"burt":"1156389","jira":"","product":"ONTAP 9 (formerly Clustered Data ONTAP)"},{"burt":"1156388","jira":"","product":"ONTAP Antivirus Connector"},{"burt":"1156402","jira":"","product":"ONTAP Select Deploy administration utility"},{"burt":"1156398","jira":"","product":"OnCommand API Services"},{"burt":"1156403","jira":"","product":"SnapCenter"},{"burt":"1156404","jira":"","product":"SnapDrive for Unix"},{"burt":"1156405","jira":"","product":"SnapDrive for Windows"},{"burt":"1156392","jira":"","product":"Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above"},{"burt":"1156408","jira":"","product":"Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above"},{"burt":"1156407","jira":"","product":"StorageGRID (formerly StorageGRID Webscale)"},{"burt":"1156406","jira":"","product":"StorageGRID9 (9.x and prior)"},{"burt":"1156410","jira":"","product":"Virtual Storage Console for VMware vSphere 9.7 and above"}],"kb_investigating_list":[],"kb_num":"9010000","kb_ref":[],"kb_rev_history":[{"comment":"Initial Public Release","date":"20190719","version":"1.0"},{"comment":"NetApp SMI-S Provider added to Software Versions and Fixes","date":"20190724","version":"2.0"},{"comment":"Storage Services Connector moved to Products Not Affected","date":"20200331","version":"3.0"},{"comment":"NetApp Plug-in for Symantec NetBackup moved to Won't Fix status","date":"20210105","version":"4.0"},{"comment":"ONTAP Select Deploy administration utility added to Software Versions and Fixes, Final status","date":"20240425","version":"5.0"}],"kb_revised_list":[],"kb_scoring":{"CVE-2017-18258":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","CVE-2017-5130":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"kb_scoring_calc":[{"cve_id":"CVE-2017-18258","range":"MEDIUM","score":4.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"cve_id":"CVE-2017-5130","range":"HIGH","score":8.8,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"kb_status":"Final","kb_summary":"Multiple NetApp products incorporate libxml2. Versions of libxml2 prior to 2.9.6 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).","kb_title":"April 2018 Libxml2 Vulnerabilities in NetApp Products","kb_unaffected_list":["7-Mode Transition Tool","Active IQ Unified Manager for Linux","Active IQ Unified Manager for Microsoft Windows","Brocade Fabric Operating System Firmware","E-Series SANtricity OS Controller Software 11.x","E-Series SANtricity Unified Manager and Web Services Proxy","Element Plug-in for vCenter Server","FAS/AFF BIOS - 8300/8700/A400/C400","Host Utilities - SAN for Linux","Host Utilities - SAN for Windows","MetroCluster Tiebreaker for clustered Data ONTAP","NetApp BlueXP","NetApp Cloud Backup (formerly AltaVault)","NetApp Converged Systems Advisor Agent","NetApp HCI Compute Node (Bootstrap OS)","NetApp HCI Storage Nodes","NetApp NFS Plug-in for VMware VAAI","NetApp ONTAP PowerShell Toolkit (PSTK)","NetApp SolidFire & HCI Management Node","NetApp SolidFire & HCI Storage Node (Element Software)","NetApp SteelStore Cloud Integrated Storage","NetApp VASA Provider for Clustered Data ONTAP 9.7 and above","OnCommand API Services","OnCommand Insight","OnCommand Workflow Automation","Single Mailbox Recovery","Snap Creator Framework","SnapCenter","SnapDrive for Windows","SnapManager for Hyper-V","Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above","Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above","StorageGRID (formerly StorageGRID Webscale)","StorageGRID9 (9.x and prior)","System Manager 9.x","Virtual Storage Console for VMware vSphere 9.7 and above"],"kb_workarounds":"None at this time.","ntap_advisory_id":"NTAP-20190719-0001","adv_id":"ntap-20190719-0001","published_date":"2019-07-19T00:00:00","updated_date":"2024-04-25T00:00:00","inserted_date":"2025-05-27T05:01:26.414000","modified_date":null}}