First published: Mon Apr 10 2017(Updated: )
NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7.1P1 improperly bind the Java Management Extension Remote Method Invocation (aka JMX RMI) service to the network, which allows remote attackers to obtain sensitive information via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Data ONTAP | <=7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7345 is rated as a high severity vulnerability due to its potential to expose sensitive information to remote attackers.
To fix CVE-2017-7345, users should upgrade to NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP version 7.1P1 or later.
The impact of CVE-2017-7345 allows remote attackers to obtain sensitive information by exploiting improper binding of the JMX RMI service.
CVE-2017-7345 affects versions of NetApp Clustered Data ONTAP prior to version 7.1P1.
There are no documented workarounds for CVE-2017-7345; upgrading to the secure version is recommended.