Database/Control plane, storage & DevOps
NetApp ONTAP SnapLock on FlexGroup volumes: An authenticated remote user modifies or deletes WORM-locked data before
CVSS 8.1CVE-2022-23241Control plane, storage & DevOpscurated
Impact
An authenticated remote user modifies or deletes WORM-locked data before its retention expires. The immutability guarantee that backups and compliance copies of training data rely on is simply not there.
Who can reach it
Any authenticated remote account on a Clustered Data ONTAP 9.11.1 through 9.11.1P2 system with SnapLock-configured FlexGroups.
What to do
Upgrade to 9.11.1P3 or later. Then re-verify the retention state of every SnapLock FlexGroup - the fix stops new tampering but does not restore anything already deleted.
References
Related entries
- Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - Device File Transfer settings: MissingCVE-2023-25552 · Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - Device File Transfer settingsHigh
- Brocade SANnav Management Portal web interface, before v2.3.0 and v2.2.2a: Remote unauthenticated users can bypass webCVE-2023-31424 · Brocade SANnav Management Portal web interface, before v2.3.0 and v2.2.2aHigh
- OpenPMIx (PMIx library used by Slurm and Open MPI for job launch): A race in PMIx library code that executes with UID 0CVE-2023-41915 · OpenPMIx (PMIx library used by Slurm and Open MPI for job launch)High
- Ceph RADOS Gateway (RGW): RGW accepts a JWT whose header declares alg "none" and never checks the signature, so anyoneCVE-2024-48916 · Ceph RADOS Gateway (RGW)High
- HPE Insight Remote Support (Java deserialization): Java deserialization letting an unauthenticated attacker executeCVE-2024-53673 · HPE Insight Remote Support (Java deserialization)High
- PostgreSQL (libpq): Improper quoting in PQescape*CVE-2025-1094 · PostgreSQL (libpq)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.