<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MySQL Cluster Vulnerability in NetApp Products (CVE-2024-20965) in Active IQ Unified Manager Discussions</title>
    <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/MySQL-Cluster-Vulnerability-in-NetApp-Products-CVE-2024-20965/m-p/451186#M28558</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/118152"&gt;@wolfkiler&lt;/a&gt; - products listed as Affected will have a link added to the Remediation tab once a fix has been posted for use.&lt;/P&gt;</description>
    <pubDate>Mon, 04 Mar 2024 20:07:06 GMT</pubDate>
    <dc:creator>kryan</dc:creator>
    <dc:date>2024-03-04T20:07:06Z</dc:date>
    <item>
      <title>MySQL Cluster Vulnerability in NetApp Products (CVE-2024-20965)</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/MySQL-Cluster-Vulnerability-in-NetApp-Products-CVE-2024-20965/m-p/451090#M28554</link>
      <description>&lt;P&gt;hi Communty, i&amp;nbsp; am starting to work in netapp, that meas&amp;nbsp; i dont have at the moment much&amp;nbsp;&lt;SPAN&gt;knowledge on it, but right&amp;nbsp; now i neet to fix a Vulneravility&amp;nbsp; of the Mysql version (8.0.35) that ar usin the&amp;nbsp; IQ manager.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could someone share the link with me to donwload&amp;nbsp; the path to fix the&amp;nbsp;CVE-2024-20965 Vulnerability?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Thanks in Advance and nice day!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:40:43 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/MySQL-Cluster-Vulnerability-in-NetApp-Products-CVE-2024-20965/m-p/451090#M28554</guid>
      <dc:creator>wolfkiler</dc:creator>
      <dc:date>2025-06-04T09:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: MySQL Cluster Vulnerability in NetApp Products (CVE-2024-20965)</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/MySQL-Cluster-Vulnerability-in-NetApp-Products-CVE-2024-20965/m-p/451097#M28555</link>
      <description>&lt;P&gt;Hello wolfkiler,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I supose you are talking about Active IQ Unified Manager,right? I checked on product security advisory and this product is not affected. You can check it at&amp;nbsp;&lt;A href="https://security.netapp.com/advisory/ntap-20240201-0006/" target="_blank" rel="noopener"&gt;https://security.netapp.com/advisory/ntap-20240201-0006/.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Albert&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 14:20:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/MySQL-Cluster-Vulnerability-in-NetApp-Products-CVE-2024-20965/m-p/451097#M28555</guid>
      <dc:creator>Abeltran</dc:creator>
      <dc:date>2024-02-29T14:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: MySQL Cluster Vulnerability in NetApp Products (CVE-2024-20965)</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/MySQL-Cluster-Vulnerability-in-NetApp-Products-CVE-2024-20965/m-p/451111#M28556</link>
      <description>&lt;P&gt;Oracle assigned CVE-2024-20965 to two products:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.oracle.com/security-alerts/cpujan2024verbose.html#MSQL" target="_blank"&gt;https://www.oracle.com/security-alerts/cpujan2024verbose.html#MSQL&lt;/A&gt;&lt;/P&gt;
&lt;TABLE class="otable-tech-basic otable-w2"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;&lt;A id="CVE-2024-20965" style="color: black;" target="_blank"&gt;&lt;/A&gt;CVE-2024-20965&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Vulnerability in the &lt;STRONG&gt;MySQL Cluster product of Oracle MySQL (component: Cluster: General).&lt;/STRONG&gt; Supported versions that are affected are 7.5.32 and prior, 7.6.28 and prior, 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster.&lt;BR /&gt;&lt;BR /&gt;CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). (&lt;A href="https://www.first.org/cvss/specification-document#i2" target="_blank" rel="noopener"&gt;legend&lt;/A&gt;) [&lt;A href="https://www.oracle.com/security-alerts/cpujan2024.html" target="_blank" rel="noopener"&gt;Advisory&lt;/A&gt;]&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;&lt;A id="CVE-2024-20965" style="color: black;" target="_blank"&gt;&lt;/A&gt;CVE-2024-20965&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Vulnerability in the &lt;STRONG&gt;MySQL Server product of Oracle MySQL (component: Server: Optimizer)&lt;/STRONG&gt;. Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.&lt;BR /&gt;&lt;BR /&gt;CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). (&lt;A href="https://www.first.org/cvss/specification-document#i2" target="_blank" rel="noopener"&gt;legend&lt;/A&gt;) [&lt;A href="https://www.oracle.com/security-alerts/cpujan2024.html" target="_blank" rel="noopener"&gt;Advisory&lt;/A&gt;]&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So there are two security advisories that reference this CVE ID.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The MySQL Cluster advisory as mentioned by &lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/44623"&gt;@Abeltran&lt;/a&gt; :&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;A href="https://security.netapp.com/advisory/ntap-20240201-0006" target="_blank"&gt;https://security.netapp.com/advisory/ntap-20240201-0006&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;And the MySQL Server advisory:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://security.netapp.com/advisory/NTAP-20240201-0003" target="_blank"&gt;https://security.netapp.com/advisory/NTAP-20240201-0003&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Review and monitor them as needed - fixes are added when they are posted for use.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 17:03:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/MySQL-Cluster-Vulnerability-in-NetApp-Products-CVE-2024-20965/m-p/451111#M28556</guid>
      <dc:creator>kryan</dc:creator>
      <dc:date>2024-02-29T17:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: MySQL Cluster Vulnerability in NetApp Products (CVE-2024-20965)</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/MySQL-Cluster-Vulnerability-in-NetApp-Products-CVE-2024-20965/m-p/451142#M28557</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/44623"&gt;@Abeltran&lt;/a&gt;&amp;nbsp; and &lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/3176"&gt;@kryan&lt;/a&gt;&amp;nbsp;, first of all, thank you very much for answering me, I saw those documents, but the big problem or lack of knowledge I have is ¿ how can I get the patch ? If I check those documents and go to the remediation tap, there I can see that the solution is to go to the Netapp download page, but I can't find a way to get the patch there :-(, it might be possible, give me a hand&amp;nbsp;To find the right way to get this patch? Thanks in advance!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;have a nice day&amp;nbsp; Guys.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 10:47:56 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/MySQL-Cluster-Vulnerability-in-NetApp-Products-CVE-2024-20965/m-p/451142#M28557</guid>
      <dc:creator>wolfkiler</dc:creator>
      <dc:date>2024-03-01T10:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: MySQL Cluster Vulnerability in NetApp Products (CVE-2024-20965)</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/MySQL-Cluster-Vulnerability-in-NetApp-Products-CVE-2024-20965/m-p/451186#M28558</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/118152"&gt;@wolfkiler&lt;/a&gt; - products listed as Affected will have a link added to the Remediation tab once a fix has been posted for use.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 20:07:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/MySQL-Cluster-Vulnerability-in-NetApp-Products-CVE-2024-20965/m-p/451186#M28558</guid>
      <dc:creator>kryan</dc:creator>
      <dc:date>2024-03-04T20:07:06Z</dc:date>
    </item>
  </channel>
</rss>

