{"status":"success","advisory":{"_id":"683547265b16347a91c39de9","kb_acknowledgements":null,"kb_affected_list":["Data ONTAP Edge","NetApp Plug-in for Symantec NetBackup","NetApp SMI-S Provider","ONTAP 9 (formerly Clustered Data ONTAP)","ONTAP Antivirus Connector","ONTAP Select Deploy administration utility"],"kb_bad_data":false,"kb_cve":["CVE-2018-14404"],"kb_exploitation":"Public","kb_fixes":[{"product":"ONTAP 9 (formerly Clustered Data ONTAP)","fixes":[{"link":"https://mysupport.netapp.com/products/ontap9/9.1P18/","cves":[]},{"link":"https://mysupport.netapp.com/products/ontap9/9.3P12/","cves":[]},{"link":"https://mysupport.netapp.com/products/ontap9/9.4P7/","cves":[]},{"link":"https://mysupport.netapp.com/products/ontap9/9.5P10/","cves":[]},{"link":"https://mysupport.netapp.com/products/ontap9/9.6/","cves":[]}],"instructions":"Fixed under bug 1107084.","wontfix":false,"eos_link":null},{"product":"ONTAP Antivirus Connector","fixes":[{"link":"https://mysupport.netapp.com/site/products/all/details/ontap-antivirus-connector/downloads-tab/download/63048/1.0.5/downloads","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"Data ONTAP Edge","fixes":[],"instructions":null,"wontfix":true,"eos_link":"https://mysupport.netapp.com/info/communications/ECMLP2630722.html"},{"product":"NetApp Plug-in for Symantec NetBackup","fixes":[],"instructions":null,"wontfix":true,"eos_link":"https://mysupport.netapp.com/info/communications/ECMLP2875531.html"},{"product":"NetApp SMI-S Provider","fixes":[{"link":"https://mysupport.netapp.com/products/smis/5.2.5/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"ONTAP Select Deploy administration utility","fixes":[{"link":"https://mysupport.netapp.com/site/products/all/details/ontapselect-deploy/downloads-tab/download/62910/9.14.1","cves":[]}],"instructions":"","wontfix":false,"eos_link":null}],"kb_impact":"Successful exploitation of this vulnerability could lead to Denial of Service (DoS).","kb_internal_notes":[{"burt":"1179229","jira":"","product":"7-Mode Transition Tool"},{"burt":"1179241","jira":"","product":"Active IQ Unified Manager for Microsoft Windows"},{"burt":"1179240","jira":"","product":"Active IQ Unified Manager for VMware vSphere"},{"burt":"1179232","jira":"","product":"Data ONTAP Edge"},{"burt":"1179238","jira":"","product":"NetApp Cloud Backup (formerly AltaVault)"},{"burt":"","jira":"","product":"NetApp HCI Compute Node (Bootstrap OS)"},{"burt":"","jira":"SECURITY-317","product":"NetApp HCI Storage Nodes"},{"burt":"1179235","jira":"","product":"NetApp Manageability SDK"},{"burt":"1179236","jira":"","product":"NetApp Plug-in for Symantec NetBackup"},{"burt":"1179233","jira":"","product":"NetApp SMI-S Provider"},{"burt":"","jira":"","product":"NetApp SolidFire & HCI Management Node"},{"burt":"","jira":"","product":"NetApp SolidFire & HCI Storage Node (Element Software)"},{"burt":"1179237","jira":"","product":"NetApp SteelStore Cloud Integrated Storage"},{"burt":"1179239","jira":"","product":"NetApp VASA Provider for Clustered Data ONTAP 9.7 and above"},{"burt":"1179231","jira":"","product":"ONTAP 9 (formerly Clustered Data ONTAP)"},{"burt":"1179230","jira":"","product":"ONTAP Antivirus Connector"},{"burt":"1179243","jira":"","product":"ONTAP Select Deploy administration utility"},{"burt":"1179264","jira":"","product":"OnCommand Plug-in for Microsoft"},{"burt":"1179244","jira":"","product":"SnapCenter"},{"burt":"1179245","jira":"","product":"SnapDrive for Unix"},{"burt":"1179246","jira":"","product":"SnapDrive for Windows"},{"burt":"1179234","jira":"","product":"Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above"},{"burt":"1179248","jira":"","product":"StorageGRID (formerly StorageGRID Webscale)"},{"burt":"1179247","jira":"","product":"StorageGRID9 (9.x and prior)"},{"burt":"1179263","jira":"","product":"Virtual Storage Console for VMware vSphere 9.7 and above"}],"kb_investigating_list":[],"kb_num":"9010000","kb_ref":["https://gitlab.gnome.org/GNOME/libxml2/issues/10"],"kb_rev_history":[{"comment":"Initial Public Release","date":"20190719","version":"1.0"},{"comment":"NetApp SMI-S Provider added to Software Versions and Fixes","date":"20190724","version":"2.0"},{"comment":"NetApp Cloud Backup (formerly AltaVault), NetApp SteelStore Cloud Integrated Storage moved to Products Not Affected","date":"20191001","version":"3.0"},{"comment":"After additional review, SnapDrive for Windows moved to Products Not Affected","date":"20191128","version":"4.0"},{"comment":"Clustered Data ONTAP added to Software Versions and Fixes","date":"20200219","version":"5.0"},{"comment":"Storage Services Connector moved to Products Not Affected","date":"20200331","version":"6.0"},{"comment":"NetApp Plug-in for Symantec NetBackup moved to Won't Fix status","date":"20210105","version":"7.0"},{"comment":"Clustered Data ONTAP Antivirus Connector added to Software Versions and Fixes","date":"20210315","version":"8.0"},{"comment":"ONTAP Select Deploy administration utility added to Software Versions and Fixes, Final status","date":"20240307","version":"9.0"}],"kb_revised_list":[],"kb_scoring":{"CVE-2018-14404":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},"kb_scoring_calc":[{"cve_id":"CVE-2018-14404","range":"MEDIUM","score":6.5,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}],"kb_status":"Final","kb_summary":"Multiple NetApp products incorporate libxml2. Versions of libxml2 through  2.9.8 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).","kb_title":"CVE-2018-14404 Libxml2 Vulnerability in NetApp Products","kb_unaffected_list":["7-Mode Transition Tool","Active IQ Unified Manager for Linux","Active IQ Unified Manager for Microsoft Windows","Active IQ Unified Manager for VMware vSphere","Brocade Fabric Operating System Firmware","E-Series SANtricity OS Controller Software 11.x","E-Series SANtricity Unified Manager and Web Services Proxy","Element Plug-in for vCenter Server","FAS/AFF BIOS - 8300/8700/A400/C400","FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750","Host Utilities - SAN for Linux","Host Utilities - SAN for Windows","MetroCluster Tiebreaker for clustered Data ONTAP","NetApp BlueXP","NetApp Cloud Backup (formerly AltaVault)","NetApp Converged Systems Advisor Agent","NetApp HCI Compute Node (Bootstrap OS)","NetApp HCI Compute Node BIOS","NetApp HCI Storage Nodes","NetApp Manageability SDK","NetApp NFS Plug-in for VMware VAAI","NetApp ONTAP PowerShell Toolkit (PSTK)","NetApp SolidFire & HCI Management Node","NetApp SolidFire & HCI Storage Node (Element Software)","NetApp SteelStore Cloud Integrated Storage","NetApp VASA Provider for Clustered Data ONTAP 9.7 and above","OnCommand Insight","OnCommand Plug-in for Microsoft","OnCommand Workflow Automation","Single Mailbox Recovery","Snap Creator Framework","SnapCenter","SnapDrive for Unix","SnapDrive for Windows","SnapManager for Hyper-V","Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above","StorageGRID (formerly StorageGRID Webscale)","StorageGRID Baseboard Management Controller (BMC) - SG6060/SG6160/SGF6024/SGF6112/SG100/SG110/SG1000/SG1100","StorageGRID9 (9.x and prior)","System Manager 9.x","Virtual Storage Console for VMware vSphere 9.7 and above"],"kb_workarounds":"None at this time.","ntap_advisory_id":"NTAP-20190719-0002","adv_id":"ntap-20190719-0002","published_date":"2019-07-19T00:00:00","updated_date":"2024-03-07T00:00:00","inserted_date":"2025-05-27T05:01:26.431000","modified_date":null}}