July 2017 MySQL Vulnerabilities in Multiple NetApp Products
NetApp will continue to update this advisory as additional information becomes available.
This advisory should be considered the single source of current, up-to-date, authorized and accurate information from NetApp.
Advisory ID: NTAP-20170720-0002 Version: 12.0 Last updated: 04/19/2018 Status: Interim. CVEs: CVE-2016-4436, CVE-2017-5651, CVE-2017-5647, CVE-2017-3633, CVE-2017-3634, CVE-2017-3732, CVE-2017-3732, CVE-2017-3732, CVE-2017-3635, CVE-2017-3635, CVE-2017-3636, CVE-2017-3529, CVE-2017-3637, CVE-2017-3639, CVE-2017-3640, CVE-2017-3641, CVE-2017-3643, CVE-2017-3644, CVE-2017-3638, CVE-2017-3642, CVE-2017-3645, CVE-2017-3646, CVE-2014-1912, CVE-2017-3648, CVE-2017-3647, CVE-2017-3649, CVE-2017-3651, CVE-2017-3652, CVE-2017-3650, CVE-2017-3653
Summary
Multiple NetApp products incorporate Oracle MySQL. MySQL versions below 5.5.56, 5.6.36 and 5.7.18 are susceptible to multiple vulnerabilities that could lead to the unauthorized ability to takeover MySQL Server, unauthorized read or modification access to a subset or all MySQL Server accessible data, or to a hang or frequently repeatable crash (partial or complete DoS) of MySQL Server. This advisory will be updated as additional information becomes available.
Impact
Successful exploitation of these vulnerabilities may lead to the unauthorized ability to takeover MySQL Server, unauthorized read or modification access to a subset or all MySQL Server accessible data, or to a hang or frequently repeatable crash (partial or complete DoS) of MySQL Server.
Vulnerability Scoring Details
CVE | Score | Vector |
---|---|---|
CVE-2014-1912 | 4.8 (MEDIUM) | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L |
CVE-2016-4436 | 9.8 (CRITICAL) | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVE-2017-3529 | 5.3 (MEDIUM) | CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3633 | 6.5 (MEDIUM) | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H |
CVE-2017-3634 | 6.5 (MEDIUM) | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3635 | 5.3 (MEDIUM) | CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3636 | 5.3 (MEDIUM) | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
CVE-2017-3637 | 5.3 (MEDIUM) | CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3638 | 4.9 (MEDIUM) | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3639 | 4.9 (MEDIUM) | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3640 | 4.9 (MEDIUM) | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3641 | 4.9 (MEDIUM) | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3642 | 4.9 (MEDIUM) | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3643 | 4.9 (MEDIUM) | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3644 | 4.9 (MEDIUM) | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3645 | 4.9 (MEDIUM) | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3646 | 4.9 (MEDIUM) | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3647 | 4.4 (MEDIUM) | CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3648 | 4.4 (MEDIUM) | CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3649 | 4.4 (MEDIUM) | CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H |
CVE-2017-3650 | 3.7 (LOW) | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
CVE-2017-3651 | 4.3 (MEDIUM) | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
CVE-2017-3652 | 4.2 (MEDIUM) | CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N |
CVE-2017-3653 | 3.1 (LOW) | CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N |
CVE-2017-3732 | 5.9 (MEDIUM) | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVE-2017-5647 | 7.5 (HIGH) | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVE-2017-5651 | 9.8 (CRITICAL) | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Exploitation and Public Announcements
NetApp is aware of public discussion of this vulnerability.
References
Affected Products
- OnCommand Balance
- OnCommand Cloud Manager
- OnCommand Insight
- OnCommand Performance Manager for VMware vSphere
- OnCommand Unified Manager for VMware vSphere 7.2 and above
- OnCommand Unified Manager for VMware vSphere for 7.1 and below
- OnCommand Unified Manager for Windows 7.2 and above
- OnCommand Unified Manager for Windows for 7.1 and below
- OnCommand Workflow Automation
- SnapCenter Server
Products Not Affected
- 7-Mode Transition Tool
- ATTO FibreBridge
- AutoSupport, MySupport,support.netapp.com
- Brocade Fabric Operating System Firmware
- Brocade Network Advisor Software
- Brocade Network Operating System Firmware
- Cloud Control
- Cluster Network Switch (NetApp CN1610)
- Clustered Data ONTAP
- Clustered Data ONTAP Antivirus Connector
- Data ONTAP Edge
- Data ONTAP operating in 7-Mode
- E-Series SANtricity Management Plug-ins (Microsoft SQL Server (SSMS))
- E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM))
- E-Series SANtricity Management Plug-ins (Oracle EM)
- E-Series SANtricity Management Plug-ins (VMware SRA)
- E-Series SANtricity Management Plug-ins (VMware VASA (Windows))
- E-Series SANtricity Management Plug-ins (VMware vCenter)
- E-Series SANtricity OS Controller Software 11.30 and later
- E-Series SANtricity OS Controller Software 8.x
- E-Series SANtricity Storage Manager
- E-Series SANtricity Web Services (REST API) for Web Services Proxy
- FAS/AFF System Firmware
- Host Utilities - SAN for ESX
- Host Utilities - SAN for Unix and Linux
- Host Utilities - SAN for Windows
- MetroCluster Tiebreaker for clustered Data ONTAP
- Multipath I/O (Data ONTAP DSM for Windows MPIO)
- NetApp Cloud Backup
- NetApp Cloud Backup OST Plug-in
- NetApp HCI Compute Nodes
- NetApp Host Agent
- NetApp Manageability SDK
- NetApp NFS Plug-in for VMware VAAI
- NetApp Plug-in for Symantec NetBackup
- NetApp SANtricity SMI-S Provider
- NetApp SMI-S Provider
- NetApp Service Level Manager
- NetApp Storage Encryption
- NetApp VASA Provider for Clustered Data ONTAP 7.0 and above
- ONTAP Select Deploy administration utility
- OnCommand API Services
- OnCommand Plug-in for Microsoft
- OnCommand System Manager
- OnCommand Unified Manager for 7-Mode (core package)
- OnCommand Unified Manager for Linux 7.2 and above
- Open Systems SnapVault Agent
- Perfstat
- RAID Controller CTS2600 Legacy Engenio
- Service Processor
- Single Mailbox Recovery
- Snap Creator Framework
- SnapDrive for Unix
- SnapDrive for Windows
- SnapManager for Exchange
- SnapManager for Hyper-V
- SnapManager for MS SQL
- SnapManager for Oracle
- SnapManager for SAP
- SnapManager for Sharepoint
- SnapProtect
- SolidFire Element OS
- Storage Automation Store
- Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 4.x and above
- Storage Services Connector
- StorageGRID
- StorageGRID Webscale
- System Setup
- Virtual Storage Console for VMware vSphere 7.0 and above
Software Versions and Fixes
NetApp's currently available patches are listed below.
Product | First Fixed in Release |
---|---|
OnCommand Balance |
OnCommand Balance has no plans to address this vulnerability. See the EOA announcement for more information. |
OnCommand Unified Manager for Windows 7.2 and above |
https://mysupport.netapp.com/NOW/download/software/oncommand_um/7.2P1/ |
OnCommand Unified Manager for VMware vSphere for 7.1 and below |
http://mysupport.netapp.com/NOW/download/software/oncommand_cdot/7.1/ |
OnCommand Performance Manager for VMware vSphere |
http://mysupport.netapp.com/NOW/download/software/oncommand_pm/7.1/ |
OnCommand Workflow Automation |
https://mysupport.netapp.com/NOW/download/software/ocwfa/4.2/ https://mysupport.netapp.com/NOW/download/software/ocwfa_linux/4.2/ |
OnCommand Unified Manager for VMware vSphere 7.2 and above |
https://mysupport.netapp.com/NOW/download/software/oncommand_um/7.2P1/ |
OnCommand Unified Manager for Windows for 7.1 and below |
http://mysupport.netapp.com/NOW/download/software/oncommand_cdot_win/7.1/ |
Workarounds
Beginning with OnCommand Workflow Automation for Linux & Windows 4.2, OnCommand Unified Manager for Linux & Windows 7.2, NetApp Service Level Manager 1.0, and OnCommand API Services 1.2 the MySQL software can be upgraded as specified in the product documentation. For assistance with the upgrade, please consult technical support.
Obtaining Software Fixes
Software fixes will be made available through the NetApp Support website in the Software Download section.
https://mysupport.netapp.com/NOW/cgi-bin/software/
Customers who do not have access to the Support website should contact Technical Support at the number below to obtain the patches.
Contact Information
Check http://mysupport.netapp.com for further updates.
For questions, contact NetApp at:
Technical Support
mysupport.netapp.com
1 888 4 NETAPP (1 888 463 8277) (U.S. and Canada)
+00 800 44 638277 (EMEA/Europe)
+800 800 80 800 (Asia/Pacific)
Status of This Notice
Interim.
NetApp will continue to update this advisory as additional information becomes available.
This advisory should be considered the single source of current, up-to-date, authorized and accurate information from NetApp.
This advisory is posted at the following link:
https://security.netapp.com/advisory/NTAP-20170720-0002
Revision History
Revision # | Date | Comments |
---|---|---|
1.0 | 20170720 | Initial Public Release |
2.0 | 20170721 | OnCommand Workflow Automation moved to Affected Products |
3.0 | 20170725 | OnCommand Performance Manager for VMware vSphere, OnCommand Unified Manager for VMware vSphere for 7.1 and below, and OnCommand Unified Manager for VMware vSphere for 7.2 and above moved to Affected Products, Storage Automation Store, StorageGRID Webscale and StorageGRID moved to Products Not Affected |
4.0 | 20170808 | OnCommand Unified Manager for Windows for 7.2 and above and OnCommand Unified Manager for Windows for 7.1 and below moved to Affected Products |
5.0 | 20170815 | OnCommand Cloud Manager moved to Affected Products |
6.0 | 20170824 | OnCommand Insight moved to Affected Products |
7.0 | 20170829 | OnCommand Unified Manager for VMware vSphere for 7.2 and above and OnCommand Unified Manager for Windows for 7.2 and above added to Software Versions and Fixes |
8.0 | 20171011 | SnapCenter Server moved from Products Not Affected to Products Under Investigation |
9.0 | 20171020 | SnapCenter Server moved to Affected Products |
10.0 | 20180119 | OnCommand Balance moved to Won't Fix status |
11.0 | 20180209 | OnCommand Performance Manager for VMware vSphere, OnCommand Unified Manager for Windows for 7.1 and below and OnCommand Unified Manager for VMware vSphere for 7.1 and below added to Software Versions and Fixes |
12.0 | 20180419 | Updated Workarounds, OnCommand Workflow Automation added to Software Versions and Fixes |
This document is provided solely for informational purposes. All information is based upon NetApp’s current knowledge and understanding of the hardware and software products tested by NetApp, and the methodology and assumptions used by NetApp. NetApp is not responsible for any errors or omissions that may be contained herein, and no warranty, representation, or other legal commitment or obligation is being provided by NetApp. © 2017 NetApp, Inc. All rights reserved. No portions of this document may be reproduced without prior written consent of NetApp, Inc.