<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Patch: Status of NTAP-20160303-0001 in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Security-Patch-Status-of-NTAP-20160303-0001/m-p/135378#M29724</link>
    <description>&lt;P&gt;&lt;A href="https://security.netapp.com/advisory/ntap-20160519-0001/" target="_blank"&gt;https://security.netapp.com/advisory/ntap-20160519-0001/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The security advisory shows clustered ONTAP as fixed for those OpenSSH CVEs.&lt;/P&gt;</description>
    <pubDate>Wed, 18 Oct 2017 14:21:38 GMT</pubDate>
    <dc:creator>kryan</dc:creator>
    <dc:date>2017-10-18T14:21:38Z</dc:date>
    <item>
      <title>Security Patch: Status of NTAP-20160303-0001</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Security-Patch-Status-of-NTAP-20160303-0001/m-p/135362#M29717</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I am reading this correctly there is still no published fixed for the Cluster ONTAP.&amp;nbsp; The dates are getting pretty close and our companiesclus security&lt;/P&gt;&lt;P&gt;compliance team are expecting this patched by end of Nov 2017&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/support/s/article/march-2016-openssl-vulnerabilities-in-multiple-netapp-products?language=en_US" target="_blank"&gt;https://kb.netapp.com/support/s/article/march-2016-openssl-vulnerabilities-in-multiple-netapp-products?language=en_US&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have I missed an advisory update ?&amp;nbsp; or is that document correct and there is still no update available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds Andy&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 14:28:37 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Security-Patch-Status-of-NTAP-20160303-0001/m-p/135362#M29717</guid>
      <dc:creator>parkea2</dc:creator>
      <dc:date>2025-06-04T14:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: Security Patch: Status of NTAP-20160303-0001</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Security-Patch-Status-of-NTAP-20160303-0001/m-p/135372#M29721</link>
      <description>&lt;P&gt;That security advisory will be updated today.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 13:16:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Security-Patch-Status-of-NTAP-20160303-0001/m-p/135372#M29721</guid>
      <dc:creator>kryan</dc:creator>
      <dc:date>2017-10-18T13:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: Security Patch: Status of NTAP-20160303-0001</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Security-Patch-Status-of-NTAP-20160303-0001/m-p/135373#M29722</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to burt 992754, which covers the&amp;nbsp;&lt;SPAN&gt;March 2016 OpenSSL Vulnerabilities in Clustered Data ONTAP these CVEs were&amp;nbsp;first fixed in ONTAP 9.0 (these are not fixed in cDOT 8.3.2).&amp;nbsp;&lt;/SPAN&gt;However, as you state the KB article does not reflect this info.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Since there are other OpenSSH CVEs applicable to ONTAP, do your Security Team have any specific CVE number(s) they need fixed?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;FYI burt 1008362, which covers the May 2016 OpenSSH Vulnerabilities: OpenSSH vulnerability in Clustered Data ONTAP are first fixed in ONTAP 9.1 (&lt;A href="https://kb.netapp.com/support/s/article/may-2016-openssh-vulnerabilities-in-multiple-netapp-products?language=en_US" target="_blank"&gt;https://kb.netapp.com/support/s/article/may-2016-openssh-vulnerabilities-in-multiple-netapp-products?language=en_US&lt;/A&gt;).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Grant.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 15:09:59 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Security-Patch-Status-of-NTAP-20160303-0001/m-p/135373#M29722</guid>
      <dc:creator>sgrant</dc:creator>
      <dc:date>2017-10-19T15:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: Security Patch: Status of NTAP-20160303-0001</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Security-Patch-Status-of-NTAP-20160303-0001/m-p/135377#M29723</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;The advisory ID number is below, I suspect this is a internal number only:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Advisory ID: MSS-OAR-E01-2017:0111.3&lt;/P&gt;&lt;P&gt;Description:&amp;nbsp; NetApp: March 2016 OpenSSL Vulnerabilities in Multiple NetApp Products&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is mapped to a NETAPP advisory and CVE below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;NetApp Advisory Number

   NTAP-20160303-0001

  CVE

   &lt;A href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0703" target="_blank"&gt;CVE-2016-0703&lt;/A&gt;, &lt;A href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0704" target="_blank"&gt;CVE-2016-0704&lt;/A&gt;, &lt;A href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0797" target="_blank"&gt;CVE-2016-0797&lt;/A&gt;, &lt;A href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0798" target="_blank"&gt;CVE-2016-0798&lt;/A&gt;, &lt;A href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0799" target="_blank"&gt;CVE-2016-0799&lt;/A&gt;,
   &lt;A href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0702" target="_blank"&gt;CVE-2016-0702&lt;/A&gt;, &lt;A href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0705" target="_blank"&gt;CVE-2016-0705&lt;/A&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the NETAPP advisory will be updates soon, then I am more then happy and I can response / patch as needed once I know at what ONTAP level I need to be at.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 14:20:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Security-Patch-Status-of-NTAP-20160303-0001/m-p/135377#M29723</guid>
      <dc:creator>parkea2</dc:creator>
      <dc:date>2017-10-18T14:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Security Patch: Status of NTAP-20160303-0001</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Security-Patch-Status-of-NTAP-20160303-0001/m-p/135378#M29724</link>
      <description>&lt;P&gt;&lt;A href="https://security.netapp.com/advisory/ntap-20160519-0001/" target="_blank"&gt;https://security.netapp.com/advisory/ntap-20160519-0001/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The security advisory shows clustered ONTAP as fixed for those OpenSSH CVEs.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 14:21:38 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Security-Patch-Status-of-NTAP-20160303-0001/m-p/135378#M29724</guid>
      <dc:creator>kryan</dc:creator>
      <dc:date>2017-10-18T14:21:38Z</dc:date>
    </item>
  </channel>
</rss>

