Database/Control plane, storage & DevOps
NetApp ONTAP SnapLock on FlexGroup volumes: An authenticated remote user modifies or deletes WORM-locked data before
CVE-2022-23241Control plane, storage & DevOpscurated
Impact
An authenticated remote user modifies or deletes WORM-locked data before its retention expires. The immutability guarantee that backups and compliance copies of training data rely on is simply not there.
Who can reach it
Any authenticated remote account on a Clustered Data ONTAP 9.11.1 through 9.11.1P2 system with SnapLock-configured FlexGroups.
What to do
Upgrade to 9.11.1P3 or later. Then re-verify the retention state of every SnapLock FlexGroup - the fix stops new tampering but does not restore anything already deleted.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.