CVE-2017-7345: Infoleak
NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7.1P1 improperly bind the Java Management Extension Remote Method Invocation (aka JMX RMI) service to the network, which allows remote attackers to obtain sensitive information via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7345?
CVE-2017-7345 is rated as a high severity vulnerability due to its potential to expose sensitive information to remote attackers.
How do I fix CVE-2017-7345?
To fix CVE-2017-7345, users should upgrade to NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP version 7.1P1 or later.
What is the impact of CVE-2017-7345?
The impact of CVE-2017-7345 allows remote attackers to obtain sensitive information by exploiting improper binding of the JMX RMI service.
What systems are affected by CVE-2017-7345?
CVE-2017-7345 affects versions of NetApp Clustered Data ONTAP prior to version 7.1P1.
Are there any workarounds for CVE-2017-7345?
There are no documented workarounds for CVE-2017-7345; upgrading to the secure version is recommended.