NetApp Alert
3242Warning Date
Severity Level
Warning Number
Target Sector
11 December, 2022
● High
2022-5386
All
NetApp has released security updates to address multiple vulnerabilities in the following products:
- Clustered Data ONTAP
- Active IQ Unified Manager for Microsoft Windows
- Active IQ Unified Manager for VMware vSphere
- Management Services for Element Software and NetApp HCI
- NetApp E-Series Performance Analyzer
- NetApp HCI Compute Node (Bootstrap OS)
- NetApp SolidFire & HCI Storage Node (Element Software)
- ONTAP Select Deploy administration utility
- OnCommand Workflow Automation
- Clustered Data ONTAP Antivirus Connector
- NetApp Manageability SDK
An attacker could exploit these vulnerabilities to achieve the following:
- Denial of Service (DoS)
- Sensitive Information Disclosure
The CERT team encourages users to update the affected products and review NetApp security advisory:
- https://security.netapp.com/advisory/ntap-20221209-0001/
- https://security.netapp.com/advisory/ntap-20221209-0003/
- https://security.netapp.com/advisory/ntap-20221209-0005/
- https://security.netapp.com/advisory/ntap-20221209-0007/
- https://security.netapp.com/advisory/ntap-20221209-0008/
- https://security.netapp.com/advisory/ntap-20221209-0009/