Skip to content
VulniPulse
Medium5.3NetApp

Medium [CVE-2023-21971] MySQL Connector/J Vulnerability in NetApp Products

This medium-severity NetApp advisory covers CVE-2023-21971 affecting Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere.

NTAP-20230427-0010 Published Apr 27, 2023Updated by vendor Aug 5, 2026
Affected products & platforms
NetAppActive IQ Unified ManagerOnCommand / Data Infrastructure Insights
Open vendor advisory

Android app · Google Play

Monitor future NetApp CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Multiple NetApp products incorporate Oracle MySQL Connectors. Certain MySQL versions are susceptible to a vulnerability that could allow high privileged attacker with network access via multiple protocols to compromise MySQL Connectors.

Successful attacks require human interaction from a person other than the attacker.

Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized read access to a subset of MySQL Connectors accessible data.

Refer to “Oracle Critical Patch Update Advisory - April 2023” for specific version details. Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, OnCommand Insight.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 2 hours ago·verify at source

Fixed versions
  • Active IQ Unified Manager for Linux: 9.14
  • Active IQ Unified Manager for Microsoft Windows: 9.16P2
  • Active IQ Unified Manager for VMware vSphere: 9.14
  • OnCommand Insight: 7.3.15

Official advisory · high-confidence parse· fetched 2 hours ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Update affected NetApp products to a fixed release: Active IQ Unified Manager for Linux: 9.14, Active IQ Unified Manager for Microsoft Windows: 9.16P2, Active IQ Unified Manager for VMware vSphere: 9.14, OnCommand Insight: 7.3.15.

Official advisory · high-confidence parse· fetched 2 hours ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.