Vulnerability scanners and Active IQ Unified Manager 9.13 and above
Applies to
- Active IQ Unified Manager (AIQUM) 9.13+
- RHEL/OVA/Windows
- CVE-2023-3223 &
- CVE-2023-1108
Issue
- AIQUM is vulnerable to :
CVE-2023-3223
CVE-2023-1108
which causes the memory and CPU usage to continually increase after being scanned by vulnerability scanners like Qualys/crowdstrike - As a side effect, inventory and performance collections start skipping due to previous collections becoming stuck and still considered running
- TCP sessions are not cleared towards the application / server from vulnerability scanners.
Data source is already performing a poll of netappstorageperformance. Therefore this poll is skipped.
-
Failed to obtain reconciliation-processing lock for 0:10:00.000 for datasource
-
Timeout occurred while waiting on collection completion listener ClusterSparesEventDetector..EnhancerBySpringCGLIB..abbaf0ec. Cancelling it so that others can continue
Note: Even in environments where vulnerability scanners are not used, similar access patterns can cause this issue. Therefore, the absence of vulnerability scanners does not mean the environment is unaffected by this issue.