CVE-2025-50059 Java Platform Standard Edition Vulnerability in NetApp Products
Summary
Multiple NetApp products incorporate Oracle Java Platform, Standard Edition (Java SE). Java SE versions 8u451-perf, 11.0.27, 17.0.15, 21.0.7, and 24.0.1 are susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Refer to “Oracle Critical Patch Update Advisory - July 2025” for additional details. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE. Affected products: Active IQ Unified Manager for VMware vSphere, Brocade SAN Navigator (SANnav). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
What this means
In plain English
Multiple NetApp products incorporate Oracle Java Platform, Standard Edition (Java SE). Java SE versions 8u451-perf, 11.0.27, 17.0.15, 21.0.7, and 24.0.1 are susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Refer to “Oracle Critical Patch Update Advisory - July 2025” for additional details. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE. Affected products: Active IQ Unified Manager for VMware vSphere, Brocade SAN Navigator (SANnav). The official description indicates that exploitation does not require prior authentication.
Vulnerable items
- Active IQ Unified Manager for VMware vSphere — Active IQ Unified Manager for VMware vSphere is a NetApp management component used to administer connected systems or services.
- Brocade SAN Navigator (SANnav)
Recommended action
Primary action: update to a vendor-listed fixed release: Active IQ Unified Manager for VMware vSphere: 9.18P2, Brocade SAN Navigator (SANnav): 3.0. Vendor mitigation: Update affected NetApp products to a fixed release: Active IQ Unified Manager for VMware vSphere: 9.18P2, Brocade SAN Navigator (SANnav): 3.0. Brocade SAN Navigator (SANnav): Fixed in SANnav 3.0.
Rewritten locally from the scraped official advisory data above; no generative API is used. The vendor advisory is authoritative.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
- Active IQ Unified Manager for VMware vSphere: 9.18P2
- Brocade SAN Navigator (SANnav): 3.0
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Mitigation checklist
- Update affected NetApp products to a fixed release: Active IQ Unified Manager for VMware vSphere: 9.18P2, Brocade SAN Navigator (SANnav): 3.0.
- Brocade SAN Navigator (SANnav): Fixed in SANnav 3.0.
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.