Research archive · continuously indexed

Content Library

Every source gathered for NetApp Black Box, in one dense, filterable archive. Browse the evidence behind the news, product intelligence, advisories, and technical guides.

5056+items scraped and indexed

Showing all 5056 items

Product

Fastest Storage Array 2026: AI Storage Leaders and Audited Results

Source: StorageReview.com

StorageReview's roundup of the fastest storage arrays of 2026 focuses on AI storage leaders and audited benchmark results (SPC/MLPerf-style audited numbers), with NetApp's all-flash ONTAP platforms (AFF/AFX + AI Data Engine) featured among the top performers for AI training/inference throughput. Reinforces NetApp's position against VAST, Pure, and DDN in the audited-performance arms race for AI data platforms.

Open source
News

NTAP stock watch — earnings-eve micro-flows and breakout levels (Aug 26–27)

Source: Traders Union — https://news.google.com/rss/articles/CBMijAFBVV95cUxNSXZxbkZjUmtOM2FEbDNReU9fRmlfRExxUlhnY3FLQkxOYS1SaHNZcWdiajFKaWtzZ0tuQmpYNVFOYVY1SkV2LVRqb3diS1NKeWdqbHk2T2s4eXY1c29HOHBrQ2E3YzJtS19lSjcwZ1ppV1FQcFI0NXFGVHZaa3lmalc2ZkhINjZnN3hSRA?oc=5

Consolidated catch-all for remaining earnings-eve noise after JPMorgan's $195 PT and the Aug 25–26 institutional roundup were already logged. New micro-flows via MarketBeat: Meiji Yasuda Asset Management bought 5,472 shares; Northwestern Mutual Wealth Management added 8,892 shares; Manning & Napier Advisors and Globeflex Capital opened positions — routine filer churn alongside the bigger prints already covered. Traders Union published a technical "resistance test" piece watching breakout levels into Wednesday-after-close fiscal Q1 FY2027 results; Ad-hoc-news notes the stock trading near its 12-month high on AI-driven guidance optimism. Nothing operationally relevant to ONTAP estates — kept so the market-watch stream stays complete through earnings night.

Open source
News

JPMorgan Adjusts Price Target on NetApp to $195 From $175

Source: MarketScreener / JPMorgan Analyst Note — https://www.marketscreener.com/quote/stock/NETAPP-INC-13842/news/JPMorgan-Adjusts-Price-Target-on-NetApp-to-195-From-175-47683921/

JPMorgan upgraded its price target for NetApp (NASDAQ: NTAP) from $175 to $195 while maintaining an Overweight rating ahead of Q1 FY2027 earnings. The bank pointed to accelerated customer adoption of all-flash enterprise storage arrays (AFF A-Series and C-Series), growing pipeline for NVIDIA-certified AIPod systems, and resilience in public cloud first-party storage services (AWS FSx for ONTAP, Azure NetApp Files, Google Cloud NetApp Volumes) despite broader enterprise IT hardware budget scrutiny.

Open source
AI

How Nutanix's ChronoScale AI Alliance Could Reshape Its GPU Strategy

Source: Simply Wall St — https://simplywall.st/stocks/us/software/nasdaq-ntnx/nutanix/news

Simply Wall St analyzes how Nutanix's ChronoScale AI alliance could reshape its GPU strategy and what it means for NTNX investors — a direct competitor move in the AI data infrastructure race. Relevant context for NetApp positioning: Nutanix is also a founding member of NVIDIA's Open Secure AI Alliance, so the AI-storage competitive field (NetApp AFX/AI Data Engine vs Nutanix-led alliances) continues to tighten heading into earnings season.

Open source
Product

Cisco to offer AI racks for trillion-parameter model training

Source: Stock Titan (via Google News) — https://news.google.com/rss/search?q=Cisco+AI+racks+trillion-parameter

Cisco announced it will offer integrated AI racks aimed at trillion-parameter model training, deepening its push into full-stack AI infrastructure. Notable for NetApp watchers: Cisco is NetApp's FlexPod AI and ONTAP AI partner, so Cisco's rack-scale AI ambitions cut both ways — expanding the joint go-to-market while raising the possibility of Cisco favoring in-house storage alternatives at the very top end of the training market.

Open source
AI

StorageGRID a Leader in Forrester Object Storage Wave Q2 2026

Source: Blocks & Files — https://www.blocksandfiles.com/object/2026/08/24/forresters-object-storage-wave-leaves-out-cloudian-minio-and-many-others/5291578

Blocks & Files breaks down The Forrester Wave: Object Storage Solutions, Q2 2026: four Leaders — NetApp (StorageGRID), Everpure, Nutanix and VAST Data — six Strong Performers (Dell, Scality, AWS, Hitachi Vantara, HPE, Huawei) and two Contenders (DDN, Alibaba Cloud); IBM and Oracle were rejected (no single object offering / public-cloud-only). Analyst Brent Ellis frames the shift storage admins should internalize: object storage is moving from "cheap and deep" cold tier to an active primary platform for serverless/Kubernetes workloads and is becoming "the de facto storage platform for AI" — with decisions now hinging on operating-model fit, AI ambitions, and governance rather than raw durability claims. Follows June's GigaOm Radar (27 suppliers), where Forrester's $100M+ revenue bar made its list far tighter.

Open source
Advisory

Community: Active IQ Unified Manager 9.18P2 Python and MySQL CVE Remediation

Source: NetApp Community Forums — https://community.netapp.com/t5/ONTAP-SAN-Discussions/bd-p/san-and-nas

Discussions emerged on NetApp Community regarding Active IQ Unified Manager (AIQUM) version 9.18P2 patch rollout, specifically addressing internal Python 3.11 runtime and bundled MySQL Community Server vulnerability remediations. Enterprise storage administrators confirmed that 9.18P2 resolves several medium-severity CVEs related to bundled open-source dependencies without requiring schema migration or database rebuilds when upgrading from 9.18P1 or 9.17 appliances.

Open source
Community

Community: ONTAP Tools for VMware vSphere 10.6 Enterprise Deployment Insights

Source: NetApp Community Tech Blogs — https://community.netapp.com/t5/Tech-ONTAP-Blogs/bg-p/tech-ontap-blogs

The NetApp technical community published deep-dive guidance on migrating from legacy ONTAP Tools 9.x (OTV) virtual appliances to the microservices-based ONTAP Tools for VMware vSphere 10.6 architecture. The 10.6 release delivers enhanced multi-vCenter scalability, automated VASA Provider high availability, improved VVols replication performance on ONTAP 9.15.1+, and streamlined role-based access control (RBAC) synchronization across hybrid cloud VMware Cloud Foundation (VCF) environments.

Open source
Docs

What's new for ONTAP Select 9.19.1

Source: https://docs.netapp.com/us-en/ontap-select/reference_new_ots.html

ONTAP Select 9.19.1 ships two headline features for software-defined ONTAP: (1) Support for external key management via KMIP — ONTAP Select now supports an external KMIP key manager (e.g., SafeNet, Thales, Vormetric) for NVE encryption keys. Cloud key managers (AWS KMS, Azure Key Vault, GCP KMS) are explicitly NOT supported — only on-prem KMIP. Enable post-deploy via the management GUI or REST API; existing 9.19.1 clusters gain the option after upgrade. (2) Support for AMD processors on both KVM and ESXi hypervisor hosts — previously Intel-only. The KVM hypervisor path is now viable on AMD EPYC servers (important for modern server fleets that have largely moved off Intel Xeon SP). Both features have been requested heavily by SMB customers running ONTAP Select on commodity hardware and by orgs standardising on AMD for sustainability/perf reasons. Prior major releases: 9.18.1 simplified product downloads to two artifacts (ONTAP Select Deploy + ONTAP Select Image, replacing the legacy 4-image matrix), 9.17.1 added NVMe-oF support on KVM, 9.16.1 brought 100GbE support. Reference for any ONTAP Select capacity planner / hardware refresh conversation.

Open source
Community

StorageGRID: Uncertified drive detected error

Source: https://community.netapp.com/community/discussion/468372/uncertified-drive-detected

After replacing a failed HDD in a StorageGRID SG5700/SG5800-series (HPE-manufactured) appliance node with a used-but-functional drive, the appliance began logging "Uncertified drive detected" in the grid log. The likely root cause: StorageGRID (and E-Series SANtricity) maintain a drive allow-list keyed to firmware revision, model, and capacity. A drive pulled from a peer with newer drive firmware than the running SANtricity release is treated as out-of-list even though the part number matches. Resolution path: (1) confirm the replacement drive is on the NetApp/HPE interoperability matrix for that controller firmware, (2) if the drive is supported but firmware differs, upgrade SANtricity (controller firmware bundle in StorageGRID Appliance Installer) so the drive's revision is recognised, or (3) swap for a drive shipped at the supported firmware revision. Drive is functional; the alert is a compatibility guardrail — it does not mean data loss or impaired operation, but it should be cleared so future drive events are correctly attributed. Reference thread for StorageGRID hardware troubleshooting.

Open source
Docs

ONTAP base immutability features on FAS2820

Source: https://community.netapp.com/community/discussion/468362/ontap-base-immutabilty-features

Question asked on NetApp Community about whether the standard ONTAP base (FAS2820) includes any immutability feature by default, or if ONTAP ONE is required for WORM + SnapLock licensing. The accepted answer confirms the FAS2820 entry-tier system runs ONTAP 9.x and supports the same WORM (SnapLock) immutability primitives as larger AFF/FAS once ONTAP ONE (or legacy SnapLock license) is enabled. Plain ONTAP 9 (no SnapLock entitlement) does NOT give compliance-mode WORM; only SnapMirror lock-style retention is possible via SnapLock Compliance or SnapLock Enterprise modes. Practical answer for any size: SnapLock Compliance = strict WORM, no admin override even by root; SnapLock Enterprise = WORM with privileged delete; both require the SnapLock license, which is bundled in ONTAP ONE on FAS2820 going forward. If only NetApp Snapshot copies are in play, immutable snapshots (introduced ONTAP 9.12.1) provide append-only retention against ransomware without SnapLock — the SnapLock license is for regulatory compliance retention, not snapshots. Reference for FAQ / hardening guide.

Open source
Community

ONTAP 9.12.1 VSIM download request

Source: https://community.netapp.com/community/discussion/468366/i-would-need-a-download-link-for-9-12-1-vsim

User asked for a 9.12.1 ONTAP Simulator (VSIM/ONTAP Select VM) image — at the time of writing the NetApp Support Site ▶ Downloads ▶ ONTAP 9 Software ▶ Simulator page had pruned older branches and only listed the latest two releases. Workarounds used by others in the thread: (1) check the ONTAP Select VM depot (downloads.netapp.com → ONTAP Select → archive), where earlier VSIM/OVF builds are kept; (2) request via the NetApp Community's ONTAP simulator peer-share, which is the standard method when the support site no longer exposes older binaries directly; (3) for 9.12.1.x specifically, the GA build is also reachable from the legacy `mysupport.netapp.com` simulator index. Note: any VSIM older than 9.14.1 lacks the modern REST API endpoints and won't talk to current BlueXP/Console — useful only for restoring older lab environments or running legacy CLI workflows. Reference for ONTAP simulator availability.

Open source
Community

NetApp Shift Toolkit DRO snapshot cleanup

Source: https://community.netapp.com/community/discussion/468357/dro-snapshots-created-by-shift-toolkit

VM migration using the NetApp Shift Toolkit (VMware → Proxmox conversions) leaves Disaster Recovery Orchestrator (DRO) snapshots on each volume that was processed. The snapshots are intentional: Shift creates a volume Snapshot before disk conversion, then a FlexClone off that snapshot to convert `.vmdk` → `.qcow2` while the source VM continues running. The leftover DRO snapshot is the rollback anchor for the migration. If a Shift blueprint fails midway, the snapshot is preserved instead of being pruned — that's why a few test migrations accumulated ~18 TB of DRO snapshots on flash. To safely delete orphaned DRO snapshots after confirming the migration succeeded: `volume snapshot show -vserver <svm> -volume * -snapshot dro_*` to list, then `volume snapshot delete -vserver <svm> -volume <vol> -snapshot <name> -foreground false` per snapshot. Best practice for any Shift operator: gate snapshot deletion on a job-success flag in the Shift workflow, or run `volume snapshot show -snapshot dro_* -fields create-time` and only delete snapshots older than 7 days. Reference thread for Shift migration hygiene.

Open source
Community

NetApp Data Classification: CIFS export-policy error

Source: https://community.netapp.com/community/discussion/468371/netapp-data-classification-giving-export-policy-error

When running NetApp Data Classification (formerly Cloud Data Sense / BlueXP Classification) against CIFS/SMB-only ONTAP volumes, the scanner reports "Access denied. Ensure the ONTAP export policy allows access from the classification instance" even though CIFS uses share-level ACLs, not NFS export policies. The root cause: Data Classification reads `volume export-policy` as a connectivity probe during discovery on every protocol, including SMB — and an empty or restrictive export policy looks like an access denial. Fix: on the SVM (or per-volume), create an export policy rule that allows the classification instance's IP/subnet on NFS (even if NFS is disabled at the SVM level, the policy must still be queryable). Example: `vserver export-policy rule create -vserver <svm> -policyname default -clientmatch <classifier_ip> -rorule any -rwrule none -protocol nfs -superuser none`. Common pattern for any Data Classification deployment with mixed SMB/NFS SVMs — also seen with FSx for ONTAP and Azure NetApp Files deployments.

Open source
Community

Google NetApp Volumes visibility gap in NetApp Console

Source: https://community.netapp.com/community/discussion/468355/visibility-of-volumes-from-google-netapp-in-netapp-console

A Console user with on-prem ONTAP working alongside a Google Cloud NetApp Volumes (formerly Google Cloud NetApp Files) deployment reported that the Google agent tile shows a data-capacity summary icon but no drill-down to individual volumes — only on-prem ONTAP volumes render in the Console inventory. The expected behaviour from NetApp's Console/BlueXP documentation: Google NetApp Volumes IS supported in Console for inventory but the volume list lives in the Google Cloud NetApp Volumes tile inside Google Cloud Console, while the NetApp Console gives a top-line capacity/health view of the agent only. Workaround for full volume-level visibility: open the Google Cloud Console → NetApp Volumes → Volumes for the project, or call the NetApp Volumes API (`google.cloud.netapp.v1`) directly. As of mid-2026 NetApp is shipping a deeper Console inventory integration, so check the release notes before assuming this is still the case. Useful for hybrid customers planning Console as a single pane of glass.

Open source
Community

Flex Unified comes to Google Cluster Toolkit

Source: https://community.netapp.com/community/discussion/468354/flex-unified-comes-to-google-cluster-toolkit

Google Cloud NetApp Volumes Flex Unified is now a first-class citizen in Google Cluster Toolkit starting with release v1.102.0. The `netapp-storage-pool` and `netapp-volume` modules provision Flex Unified pools and volumes directly from a blueprint — including zonal and regional pools, large capacity (scale-out) pools, custom performance, and auto-tiering. Useful for EDA, HPC, and AI/ML workloads where Standard/Premium/Extreme service levels (which tie throughput to provisioned capacity at 16/64/128 KiB/s per KiB) force overprovisioning. Flex Unified breaks that link: pool capacity, throughput, and IOPS scale independently, plus features like zonal-or-regional pools, large capacity pools, auto-tiering with hot/cold split, sub-millisecond read latency, and broad regional footprint. Configurable pool knobs: `service_level: FLEX`, `scale_type: SCALE_TYPE_SCALEOUT`, `total_throughput_mibps` (1 MiB/s increments, default 64 MiB/s+1024 IOPS, scaling to 5 GiB/s+160k IOPS), `allow_auto_tiering: true`, `hot_tier_size_gib`, `enable_hot_tier_auto_resize`, `replica_zone` for regional pools. Volume module inherits from pool via `use: [netapp_pool]` (never set region/zone on volume). Large-capacity volumes use `large_capacity_config.constituent_count` (typically 48) with min 4800 GiB. Note: Flex pool names accept lowercase letters/numbers/underscores only — no hyphens. Standard/Premium/Extreme now require ≥15 TiB. Deletion policy: `PREVENT` to block Terraform deletion, `ABUNDANCE` for state-only removal. The post is the first end-to-end blueprint reference for Cloud NetApp Volumes Flex Unified; pairs well with EDA/HPC team onboarding.

Open source
Docs

FAS70 to DS212C shelf connectivity clarification

Source: https://community.netapp.com/community/discussion/468369/need-clarity-on-on-fas70-to-ds212c-shelf-connectivity

A field engineer asked which cabling diagram to follow when connecting a FAS70 controller to two DS212C shelves, citing the FAS70/90 install-cable doc (https://docs.netapp.com/us-en/ontap-systems/fas-70-90/install-cable.html) which shows DS460C connectivity and the SAS3 cabling rules (https://docs.netapp.com/us-en/ontap-systems/sas3/install-cabling-rules.html) for platforms without internal storage. The point that often confuses new installers: the FAS70/90 install-cable page references DS460C as the example topology because that's the recommended high-density shelf, but the port-pair rules for SAS3 multipath HA are identical for DS212C (12Gb SAS, IOM12C). The official answer in the thread confirms that for an HA-pair FAS70 with 2× DS212C: use both controllers' ports 0a/0b and 0c/0d (4 SAS lanes per controller) with multi-path HA cabling — each shelf IOM connects to both controllers in a square so any single IOM, HBA, or cable failure doesn't drop the shelf. Reference for FAS/DS212C installation how-to.

Open source
Docs

Cable the FAS70 or FAS90 hardware for network and storage connectivity

Source: https://docs.netapp.com/us-en/ontap-systems/fas-70-90/install-cable.html

Canonical NetApp doc for cabling a FAS70 or FAS90 HA pair (new 2025-2026 generation FAS entry/mid-tier). Step 1: connect the storage controllers to your data network — each FAS70/FAS90 controller ships with onboard 100GbE ports (e0a/e0b on a dedicated NIC) plus optional PCIe NIC slots; standard practice is one LACP bond pair for data and a separate management L2. Step 2: cable host-network connections (iSCSI, NFS, SMB client traffic) — use dedicated NICs/slots, never share with intercluster or NDU. Step 3: cable management-network connections to the service-processor/management switch — the FAS70/90 nodes expose a dedicated 1GbE management port plus the RJ-45 SP. Step 4: cable the shelf connections — SAS3 (12 Gb/s) multipath HA to supported DS212C/DS224C/DS460C shelves using IOM12C modules. The doc emphasises the multipath square: each controller's ports 0a/0b/0c/0d connect to both shelves' IOM-A and IOM-B, so any single IOM, HBA, cable, or controller failure doesn't drop the shelf. This is the exact topology a field engineer was confused about in community thread 468369 — the FAS70/90 example shows DS460C, but the rules are identical for DS212C and DS224C; only port counts and lane counts differ. Useful install reference for any 2026 FAS deployment.

Open source
AI

2026-09-07-unlocking-enterprise-ai-potential-with-netapp-aipod-mini-wit

Source: https://news.google.com/rss/articles/CBMiugFBVV95cUxNZmI2Ty1iOVFRU21xbHVxU090TlliSkxRdVpxdUY2V296b2VEdkpHNG9iMnJSY0dMWnpuNE1SWDFBS1F3ZkZlYUtmRWZFdEdRaWVMeUF0SS14WXpMb0JkcnNCRlJjUW92MDExcndmeXhpb1RIemRaamRMSUc2UFUtRURCTE1HQndIeUNmNlA5cVRtNE5JWlhVcUt1YlBrQXJDcnJNck82elUwS05obzcyYkIxVU82MXFvcVE?oc=5

NetApp-related ai item collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-07-unleashing-genai-on-ontap-first-e2e-ai-data-engine-customer

Source: https://news.google.com/rss/articles/CBMisgFBVV95cUxQblFLUkh3Q25BYW1BSlMtVXdFdGxzazBmbFRYSDdwZG50ME9sNUlYU01BaHJVZG15YzFKR2NpQm85WHY1amZKWERpMmI2VmpHY1puUjNSQ2hVN3AwVDdHdVd6YjZSbVZobTg5MzJobWdkeDVudXE4UkptSTZsMjRHdUxtdVFVR0JodWVGMnVpVnRpbkx5cFJpajUyX1NPVGJLRnhweHlQSi1jYzl2b1poLU93?oc=5

NetApp-related ai item collected from Google News / Reddit / RSS feeds.

Open source
News

2026-09-07-only-netapp-s-own-enterprise-cloud-storage-is-certified-acro

Source: https://news.google.com/rss/articles/CBMivwFBVV95cUxNWU5zQk03b21uTFhzTzIyVGVabzE2U0dkbkxuNTRsbDU2TlRDTGRKRTRfby1VRExSZzNiLXl0WnV6Sl9fSXE0OE5RcHhibE1wQS14cDBMTjB0NjdmLVp2MmNyb084MTA4UjNPdUN5TXRJY3c4RjVRVjRPQXpnc3pLazBlVTNYM0I0WDREdnVOWEpSdXFVanhNelhGdzIzU3JTS3Z0VFBuSWxaaUp4RlBVYktGMDF2T1FLQWhBMmRucw?oc=5

NetApp-related news item collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-07-nvidia-gtc-storage-news-roundup-blocks-files

Source: https://news.google.com/rss/articles/CBMikAFBVV95cUxOWW9mQ19DN2kxNVprNzRoblpkei01VVZwekpucWpaNXZKQldCV1NldXhBaTNrMkstUW1PVWIzdWw4dzV4RWpuZWFCeVc1RDhYX1pFMzFSVUZuY3BmQ3B0Q1VUb1ZwMV8xQWNnd2RWczBJZFVueU90MVMzbTVmQlZkTExIQVVnaDZOWTFHY29uTFk?oc=5

NetApp-related ai item collected from Google News / Reddit / RSS feeds.

Open source
News

2026-09-07-new-cisco-netapp-flexpod-aims-to-simplify-secure-ai-for-ente

Source: https://news.google.com/rss/articles/CBMingFBVV95cUxQeElidEdtZTVXcHdqdzY5SDh5YzhCcGlaTkQtdHpGd2xfYUNicy05dzRmNjhZbUthZjV4alRBRW1tNTI4ZWN4blIwTXdkWkhWLUc0RGp0cFl2TWR2Nk9MZFoxbVNfZlBMbzBkQzBkVm1RR3JzR2V1RFJRSnpZTGxGdkpZMDJFU0hXRVhkUHEycXUwa2lUYTc3WlNQOWJCUQ?oc=5

NetApp-related news item collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-07-netapp-inc-q1-2027-earnings-call-summary-yahoo-finance

Source: https://news.google.com/rss/articles/CBMilwFBVV95cUxNSk1vNkNLdXNRQnlOTXNobmZCWnpJZ1JlRVhfQTkxV2RQZEVjVFdPajhRQXhBVDdXbTFXNzJ0ZFRhZFVXUFZNLWdiS09KM3VacGcyZXVoSlZreVlKV3IzbkpzRFlUdjNzcmd0TDZ6dnFOa2d6cldkYk5RT2R2UzF3dmdEMnk4d2dSYWVxLW5iTzQ2VEhKaUY0?oc=5

NetApp-related ai item collected from Google News / Reddit / RSS feeds.

Open source
News

2026-09-07-netapp-expands-aws-transform-support-to-accelerate-enterpris

Source: https://news.google.com/rss/articles/CBMiogFBVV95cUxOOHZ1X1JidTFyRUt4NEdQZm9Gd25oc0lhX3dEZzRaUWVfaGU4alNVenBqa3o5Wkg2Ump1LTRLRVRLc2VVQ0ZoLUxFN2lYSU41cUpRdFVZX0RVX2FJbEN3TTVBeXE4eVlRMmFRSXBXQThkRnhWdEpSVlBKUXVtZ0Y5eUJzdDhvaFJiX3JESklZVHJYU2NqTkhSZ1VmVURSb1hRNkE?oc=5

NetApp-related news item collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-07-netapp-embraces-lustre-as-ai-pushes-storage-limits-hpcwire

Source: https://news.google.com/rss/articles/CBMijwFBVV95cUxNS2tseDhUazFEN2tHNndGcUxnUGNSVXMzS191UERDTngwNlR6ZFJlZ3h6T0lRaUdyZmFBZ0ZzNTlxMW5NaktUSS0wekMwRlUwMEpzUU52Z3k5Vl9wQ2FSRVM3bnVCTG5YYm1DeXlqMnV3bEZiZHhIV2JpMm9NdFBGb0FVdWhyX2xNcGNDelZYcw?oc=5

NetApp-related ai item collected from Google News / Reddit / RSS feeds.

Open source
News

2026-09-07-netapp-cisco-expand-flexpod-to-support-ai-deployments-techno

Source: https://news.google.com/rss/articles/CBMiwAFBVV95cUxORmp0OVp6dmFZZERCXzhiVHlrXzJ5aGlDTEk3NzkyMXNteWd3MlZNSC0wbW5WUjNZQ3JacDJ6bnNXeFpiVVNXVWtVa3dWeHlYZXNmczFUalNxTHV0VnBFLXhXUWhJN0JLSzZqbDZqTS0yMmw2aHBKU0ZOM3lnaG9pc3ZNZDdwLWNJQUt4cEd0MXU4MWUtclp1M0NqSVgzS1ZHQi1lb2dpRzhPSTVzV1M5Y2lxYWVGOXA3ZHhrMy1iWVQ?oc=5

NetApp-related news item collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-07-netapp-and-cisco-expand-flexpod-with-validated-ai-architectu

Source: https://news.google.com/rss/articles/CBMiywFBVV95cUxPdjBEcEs0R3VjM09iSWhDYlkyZzZtVTBfa1BnSTE1OVloOVNNUTBWSHE4UmxQbjNBMFd5OXIwcUtnRU1NVkZ2RWlXRTM2V2hsLWdhU2MtZ2xuR2JDOUp0QUFsSFA0dzF6T1F3NU9Ic1R5WjNaSmFWVEd6ckNNNHE2ZXhtNk4zdEFyeHhnUHhOWm00ZmNTRWt1ZW91SkRMZnZDMW1VcnRSS0pnWkNvb2NucTBGUTJha193UFFITHlXcTRLV0xtZ2UtbUt1ONIB0AFBVV95cUxQTHFKZnRCZTQ3amdId09mYmxwYUxpUjlUUElvelE2WWl6SFJrWExWd1VjLXBtOTh0SktTaGpVaGM5dXRCb0pyVU1EdGIxNXI3cTNWNm9GeUFxWFhyNUswb1AyT2FvY2FzUWN4U2VMenJtX0J4a2tMS0VNUTBnT1pvbHNlX2JNM2s5VWdMTVhiQjdZT2R1TG1PS3pjcGpHWjNXUkdDNVNDZUgyem5nUV8zOHU0QzdTbWh4emFDTTkzUHl2d2R6OUtHUXRiSzBuU1hf?oc=5

NetApp-related ai item collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-07-netapp-and-cisco-expand-flexpod-for-enterprise-ai-infrastruc

Source: https://news.google.com/rss/articles/CBMingFBVV95cUxNQ3ZXaVdhQnRQQ3cwVVRPdDBMYzZCRU1PRW5SejdscU1XNUtQUUFtNlR1YWR5TXlGVzJ6RGw5MUlka0RfVXR0SXlneVZEUHp0U1ZXLTRDSVRsQ290ODJ5Rl9PSExCNFBmejBENDB0RVhOd2hTRGlaMV9VSlllTDlwTmJLR2RIZ3BPSnJNUVpjOW1vOFBWUUNkVmRoOVZiZw?oc=5

NetApp-related ai item collected from Google News / Reddit / RSS feeds.

Open source
News

2026-09-07-netapp-and-cisco-expand-flexpod-for-ai-workloads-investing-c

Source: https://news.google.com/rss/articles/CBMiqAFBVV95cUxQVmluTlZoMUlaNkZrb1IxWEpvdHdaSXNhWFluOVlqMlNLQ3Bad2M4RWt1WXdiWUxaWV9xejU4b1M1blNwSC1vbjFKMnpWWlhqOU5iUV9qUjJOTTlWR2pVd3ZFQzBrSXZhWnN6U3dsZDFYSmpBME94SGNwRWN6dDRsNDg3MkU1MnAxaVljNElLRzAwcl9tMFdjejZ5YjVFUjZoZklkWWc3cGo?oc=5

NetApp-related news item collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-07-netapp-aipod-with-lenovo-for-nvidia-ovx-netapp

Source: https://news.google.com/rss/articles/CBMikAFBVV95cUxNNTVvN3JVQ1gxaGxrVDV2QU1jMlpuN1lMbWt4Z0loZ0lZbVNhWXZGZUFDaDFrMkpkRlBGRXMzVDFGSFFqZk1rYTBJNW1QeGZxTzdzbnR2LTdoS2R6LVhTc3N2a04xRzdDVXlMRnBtMk1RVzFuVjZUbkJXVFpwWkFzMVF0ZFhkVHZRUENNdVdETzk?oc=5

NetApp-related ai item collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-07-netapp-acquires-datapelago-making-data-ai-ready-at-the-infra

Source: https://news.google.com/rss/articles/CBMipAFBVV95cUxOMTJiUGNjZGFJMFBkNUZOOXBNTDBOeDZDS0xnMDMxOXNGZ3lmNUJlUnVaXzlDdTM0N1ZsOXpaSWtSX3p4NjJPS3VXamFWNzVIUEFXNTgyV2VrYmJJd3BZSXc3Y1o5aXNuSkdBMEkxczF3ajFaeFU3WEFUYUVrNFhCM2NyUjhtY1h3NWMySnNrdTBUZ3FJU2hlY0RmdWo0aWVFRHdxWA?oc=5

NetApp-related ai item collected from Google News / Reddit / RSS feeds.

Open source
News

2026-09-07-migrate-vmware-storage-to-amazon-fsx-for-netapp-ontap-using-1

Source: https://news.google.com/rss/articles/CBMisAFBVV95cUxPc3d2MGYtV28xSlBESDVfbzdNTmE4TTktYlBkeG8zaVBET3kwdzJYV3NOR3lHZUMtRVBubXRyTHFocUg0b3FPeENvOUR4MXhPZDN6ZEJWZ0ZLcGkxbnBnXy1FUkQ3MGxMLUd0emVTNG9NUTFoVkJMX05kN01xRGF4Y0FrX0xIUWdYWlo5elNYbG5URENfa2Q4eW5TekxlTm1MR3BqSzhtN3JPWGpLejVsYg?oc=5

NetApp-related news item collected from Google News / Reddit / RSS feeds.

Open source
News

2026-09-07-migrate-vmware-storage-to-amazon-fsx-for-netapp-ontap-using

Source: https://news.google.com/rss/articles/CBMisAFBVV95cUxPc3d2MGYtV28xSlBESDVfbzdNTmE4TTktYlBkeG8zaVBET3kwdzJYV3NOR3lHZUMtRVBubXRyTHFocUg0b3FPeENvOUR4MXhPZDN6ZEJWZ0ZLcGkxbnBnXy1FUkQ3MGxMLUd0emVTNG9NUTFoVkJMX05kN01xRGF4Y0FrX0xIUWdYWlo5elNYbG5URENfa2Q4eW5TekxlTm1MR3BqSzhtN3JPWGpLejVsYg?oc=5

NetApp-related news item collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-07-memory-cost-surge-squeezes-margins-at-nvidia-b-pluang

Source: https://news.google.com/rss/articles/CBMihAFBVV95cUxOckJCT00taTk5czFvaU9Md1E2S0NmZHJPTVUwZ0hXM2hNY0NBR3lzLWYwbDBOc0x1aC1hMzBvamN2dzdEUjRwQndJUmxTYUtnbjJhbnU5N1hKWDhFb0w3TzNQbDR5MFFIT0NqWHZRU2VWaHc1LUc3MnA0VnNVRDN5ZXhYZDc?oc=5

NetApp-related ai item collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-07-jensen-huang-george-kurian-nvidia-netapp-revolutionary-ai-pr

Source: https://news.google.com/rss/articles/CBMisAFBVV95cUxOai1DVHV2VGVvUl9LMWlZY3RqQnFlUk9yVHRpd1hEb2lKTXVoMF9KV281VjdSb3lYMkx4MnJVT0lkMl9ZNzZiQzhQUGtpQ0xXdHZKYll1TTFpOUltY1dIZFJQaXdfVm9RalR3TUJMdHIzdm5nMGdyR19DeU0xYzlYXzlUbmJiSWh2SWNyLW1OcDBjS1hqVGpyUFVxdUljQ25iY0I2Z3E0RW5zdTdkOWNVcw?oc=5

NetApp-related ai item collected from Google News / Reddit / RSS feeds.

Open source
News

2026-09-07-flexpod-security-and-ransomware-protection-using-netapp-clou

Source: https://news.google.com/rss/articles/CBMitgFBVV95cUxQUFR1dTdUeVVYbGRhMFdjMTNsd1pUTFp6OVFhV2tyZFVQZUJmWS0yUDB3czhFejdHaU9qNDMzLVNsRUxJUndtckFxMmNITEptYnBvODNiMEVCMU8zTWtjbmRsX0dWeVY4MHhKOEFfSi04LXBHVDNXSDZUalA2QU5CYlhzVFBFamNSeW8wNm9admtuRTFGN1o2UnVWSW1ubDFJT3RYY2RVY1dPYkRNdXprRHBRdmhOZw?oc=5

NetApp-related news item collected from Google News / Reddit / RSS feeds.

Open source
News

2026-09-07-flexpod-inside-the-partnership-that-powers-cisco-live-netapp

Source: https://news.google.com/rss/articles/CBMimwFBVV95cUxQQ1ZuOWNTd3lGRTFJSG9sZnBGTGZhUWhxeHEyeU9VTUtMQXNHYU5scmQwd1NHbkYxMl9jeF9NLVN2aDgyTU5DRjRZTmdtd1ZhVjJJaDdvQl9MNVJrQ0dDNk5QakxnZER5dXkza3BOeE01RUUxdUg2Nm5idXBQR0txSXZFQ3BJVjUyM2RFeE4xUnVXdUxWaWdFV2JDaw?oc=5

NetApp-related news item collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-07-enabling-ai-powered-analytics-on-enterprise-file-data-config

Source: https://news.google.com/rss/articles/CBMihAJBVV95cUxNQ1NQSXhIaWtKRUZITTBZdEdhdHhZcmZTTzZNQUhtV01mRzBmaXJCendSd2NaOFdjWWlYUGxmYlA0eElXNHFxVmZWRDVhRnIzWkw0RkJzUndwdmNCS09iT1ZIaUJ4SDRaallCOGJMS3NGZkpnVDFjWmVkaTZyMU5QaEVGTlFEZzZBY0hyTWJQQ0t0N1hLMzlCU1hfTDBLTkNVVGhrQmZCRl9ZTjBaVmM2NjBQVXRxSmV4Sld2bjVpNkNBZENfMXdFNi1ka0pNS2xfakxzSTFqRWtGdW1ybnJpSmZleDYyVGJLV3BFdGtWTWpuczBLS25nX3ZQYmVUOUNXNFJRUg?oc=5

NetApp-related ai item collected from Google News / Reddit / RSS feeds.

Open source
News

2026-09-07-companies-can-now-move-storage-and-databases-straight-to-aws

Source: https://news.google.com/rss/articles/CBMirgFBVV95cUxOanZRS3RqdldqMTNHdjVSa0ZXSDhfN1N3MWFnTVR1TDJsMm9PbWxRX2pYQXNzVVdpeWFzX2lpRk9TUTZFZk1CWGRnTDVnR1JfcDIzbDluckY5M19FX1hIM3pIVUxPbVdRb2Fvb3hzMWx5SUVjY0Z1aGMtMWdxUE44dHdUbFZsUjlpM0NLWkJFNHpuZTdvY3V3a01uVkxxRHkzdDhaRE1HZVpSZDRvQWc?oc=5

NetApp-related news item collected from Google News / Reddit / RSS feeds.

Open source
News

2026-09-07-announcement-flexpod-ai-expands-enterprise-ai-netapp

Source: https://news.google.com/rss/articles/CBMifEFVX3lxTE93UU9DUzlZS2NwdEVPc0dNYVZ6am9JcHZMUU1BWGpHQnBZcWhZZnhjcmFsNmJwOGhndUVoMUVPZUpGbGFsWXJNWnFzal9JMU43MUJZNGVYTTN0RUo2ekgzcFRlRUxLUFJIZUZWSUdsQjFXX3c4c1dJX2hITHk?oc=5

NetApp-related news item collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-05-marketbeat-wsz-strong-buy

Source: https://www.marketbeat.com/instant-alerts/analyst-wall-street-zen-upgrades-netapp-nasdaq-ntap-to-strong-buy-2026-09-05/

Wall Street Zen raised NetApp (NTAP) from "Buy" to "Strong-Buy" on 2026-09-05, joining the post-Q1 FY27 earnings upgrade cycle. MarketBeat's coverage rounds up the Street's recent targets: BofA $180→$206 (Neutral, 2026-08-31), Susquehanna $185→$195 (Neutral), Northland $171→$187 (Outperform), Wells Fargo $180→$190 (Equal Weight), JPMorgan $110→$150 (Neutral, 2026-05-29). Consensus currently sits at "Hold" with a $192.07 average target — six Buys vs ten Holds, with Wall Street Zen's Strong-Buy the most bullish rating on the board. Why it matters: the spread of recent target lifts (BofA +$26, Northland +$16, JPM +$40) quantifies how much the Street is repricing NetApp after the Q1 beat-and-raise; Wall Street Zen's Strong-Buy adds an AI-aligned bull case on top of the otherwise cautious Street consensus, useful for any AI-data-infrastructure modeling that anchors on analyst targets.

Open source
AI

The Bull Case For NetApp (NTAP) Could Change Following Upgraded VMware Support And Raised 2027 Guidance

Source: https://news.google.com/rss/articles/CBMiwwFBVV95cUxNZWQ1aTRMRWlwWkZROGM5bGNfVnlqUzFoTmNjNjB2RUFHOGxLUWdVTnpYS3FCaVM4QmJVZG5OVU1PaU5seENOM2RMZmVTS0FMOThyLTI2aUlaUFM5TUdsWHRrQ1l1MnRzdVFOaXVZNjRLeWRCZGluTnllcDBQMGFweEd1OU5qMjRQWmlsamp5SnhJSFJpRjVSMElRUXhiV2RBQ2ktOF9Gb0YyTE9VcUlNSC03c2IwY28tSld1S3padTd1UjTSAcMBQVVfeXFMTWVkNWk0TEVpcFpGUThjOWxjX1Z5alMxaE5jYzYwdkVBRzhsS1FnVU56WEtxQmlTOEJiVWRuTlVNT2lObHhDTjNkTGZlU0tBTDk4ci0yNmlJWlBTOU1HbFh0a0NZdTJ0c3VRTml1WTY0S3lkQmRpbk55ZXAwUDBhcHhHdTlOajI0UFppbGpqeUp4SUhSaUY1UjBJUVF4YldkQUNpLThfRm9GMkxPVXFJTUgtN3NiMGNvLUpXdUt6WnU3dVI0?oc=5

Industry coverage of NetApp's Q1 FY2027 earnings and AI-driven storage demand, including commentary on guidance, AI workload bookings, and competitive positioning against Pure Storage and Dell. The piece is useful context for tracking how AI infrastructure capex is flowing through enterprise storage vendors.

Open source
AI

News: NetApp Raised FY27 Guidance; Ciena Revenue Jumps 37% on AI Networks

Source: https://finance.yahoo.com/news/netapp-raised-guidance-cienas-revenue-jumped-143000772.html

Yahoo Finance round-up that pairs NetApp's **raised FY27 guidance** (lifted ~$650M after the Q1 FY27 print) with Ciena's **+37% revenue jump** to argue that AI-infrastructure networking and storage vendors are finally translating hyperscaler AI demand into real earnings beats. Frames the two companies as a pair: Ciena for the optical-networking underlay of AI fabrics, NetApp for the all-flash data-plane attached to NVIDIA DGX/HGX compute. Notes that despite the beats, both stocks sold off after the prints — the article reads that selloff as the market rotating to "AI revenue purity" rather than questioning the storage/networking fundamentals.

Open source
News

News: Memory cost surge squeezes margins at Nvidia and AI-supply peers (incl. NetApp)

Source: https://pluang.com/en/news-feed/ledakan-ai-memakan-margin-perusahaan-teknologi

Pluang market write-up on the **memory cost surge** (DRAM/NAND price spike) that's pressuring AI-infrastructure vendor margins through Q3/Q4 2026. Names Nvidia and adjacent AI-system/storage names (NetApp included) as exposed to component-cost inflation even as AI-server demand stays strong. The argument: while pricing on storage-class NAND and high-bandwidth memory components is rising fast enough to offset the price increases absorbed by AI-server OEMs, the same dynamic means storage vendors like NetApp can either pass costs on (hurting share) or absorb them (hurting gross margin). Frames the trade-off as a near-term overhang on FY27 margin guidance, not on demand.

Open source
AI

NetApp Raised Guidance as Ciena’s Revenue Jumped 37%. Are AI Networks and Storage Finally Converting Into Earnings?

Source: https://news.google.com/rss/articles/CBMiogFBVV95cUxNY01CeG5NSTNnTzFyeWFsamVHRkkyRVNEWWMxTjVvQ0d1V0ZlTWFGSFBYT0NZaHlvUFhfOGJoQkhxNnRvRGRUOXV6cGVCeWtManVXLVJHNW9Nem1tTHh6eU16WEJmNTNSUllzejA1X2pzVVYwSjc4a3VaQnFpZUhGby15TXRobjBhSzNLdU5Vb29uWGFZVzVFT2pxVXNyX08zb1E?oc=5

Coverage of NetApp's raised FY27 guidance in the context of Ciena reporting a 37% revenue jump, suggesting AI networking and storage capex is finally converting into measurable earnings for adjacent infrastructure vendors. The piece compares storage vendors' AI-mix and order book dynamics across NetApp, Pure, and Vast.

Open source
AI

NetApp Q1 FY 2027: AI-Ready Storage Drives Enterprise Momentum

Source: https://news.google.com/rss/articles/CBMinAFBVV95cUxORG42THZ3UFI5LU15cUJralJYZEt6Y0ZNZ1Y1QlItOHhQRUd4ZWh5aHJtOUxnYnNQMmxTYjd1MjZJTFRQRDctbjJjejFCWUVSMUFXZVJ2alpmNjluOVhVeG5talA1RXBVd0tmZDFxTTJwSFVJYUc3TjhNOU9XRGlISzFSWGZ1RXVCT0JrNTEyd1R0UDZGeGF6YVg5cGw?oc=5

NetApp reported Q1 FY2027 results with revenue of approximately $2.03B (up ~30% YoY) and raised full-year guidance by ~$650M, driven primarily by AI-related all-flash demand. Management emphasized that AI-led bookings have moved from a future aspiration to a recurring revenue contributor, with all-flash array momentum and object-storage growth as supporting tailwinds.

Open source
AI

NetApp Inc. stock gains after strong fiscal 2027 Q1 earnings and AI demand (Ad-Hoc News)

Source: https://www.ad-hoc-news.de/boerse/news/corporate-news/netapp-inc-stock-gains-after-strong-fiscal-2027-q1-earnings-and-ai-demand/70054804

European-market coverage of the post-earnings stock reaction: NetApp shares climbed on the Q1 FY27 beat-and-raise, with AI demand cited as the primary narrative driver. The piece threads together the print, the guidance lift, and the sell-side upgrade cycle into a single readable summary aimed at European retail investors.

Open source
AI

Don't Overlook These 2 AI-Driven Tech Stocks After Earnings: CIEN, NTAP

Source: https://news.google.com/rss/articles/CBMiwwFBVV95cUxQTTMzeWVXZTNQejFUeF9IaEdtT2JaTEdENFVqbExnNTkyWTNhLVRoUXAxLTZ5QTVkNnpFMDJmM0FBd2lfYlotcDhFMTlqVHNVcFBtblROVFVYcHVXR25aVW84YVVKdmI5aHA0d1hsZEkzTjhrcUYxXzZBV1VnMFZOQ3FXamthNW9MdnNKbDVMTzNVNXBYSVhPVmFUa1JmTmV3MzFIdnlUcjhySVgyOHFVeGgtbGtaa0FQOWRHMGJ3MW5rSWM?oc=5

Industry coverage of NetApp's Q1 FY2027 earnings and AI-driven storage demand, including commentary on guidance, AI workload bookings, and competitive positioning against Pure Storage and Dell. The piece is useful context for tracking how AI infrastructure capex is flowing through enterprise storage vendors.

Open source
Community

Community: Trident 26.06 controller concurrency at 1,000-volume scale

Source: https://community.netapp.com/community/discussion/468298/from-hours-to-minutes-trident-26-06-controller-concurrency-at-1000-volume-scale

Community deep-dive on the Trident 26.06 release, where the **concurrent core** controller architecture (originally a tech preview in Trident 25.06) reaches GA. With traditional Trident, all operations were serialized by a global lock; concurrent core removes that bottleneck so many provisioning requests can run in parallel. 26.06 extends the GA coverage to ONTAP-NAS-Economy, ONTAP-SAN-Economy, and Azure NetApp Files backends. Reported throughput gains from the NetApp benchmark: ONTAP NAS +707% (~8.1×), ONTAP NAS Economy +472% (~5.7×), ONTAP SAN iSCSI +449% (~5.5×), ONTAP SAN Economy +285% (~3.9×). Methodology is a large batch of operations submitted then timed to terminal state.

Open source
Community

Community: The strategic cost advantage of Azure NetApp Files

Source: https://community.netapp.com/community/discussion/468324/the-strategic-cost-advantage-of-azure-netapp-files

Community post (NetApp engineer Robert) addressing the common perception that Azure NetApp Files (ANF) is expensive versus other Azure storage options. The argument: **list price ≠ effective price**, and once you factor in ANF's tools for adjusting how capacity, performance, and data protection are billed based on actual access patterns (cool access tiers, capacity pools, thin provisioning, snapshot efficiency), the effective monthly cost frequently lands at parity with cheaper Azure storage while delivering enterprise data management, protection, and security those services can't match. The post walks through scenarios — paying hot-tier prices for cold data, paying for snapshots as full copies, paying for replication capacity twice — where ANF's tooling (cool access, snapshot savings, cross-region replication efficiencies) compresses the bill materially.

Open source
Community

Community: SnapMirror Active Sync + ONTAP tools for VMware vSphere 10.6 Granular Datastore Protection

Source: https://community.netapp.com/community/discussion/468300/snapmirror-active-sync-ontap-tools-for-vmware-vsphere-10-6-granular-datastore-protection

Co-authored community post (NetApp engineers RajivJain + ChanceBingen) on combining **SnapMirror Active Sync** with the new **ONTAP tools Granular Datastore Protection (GDP)** feature in ONTAP tools for VMware vSphere 10.6. GDP lets administrators pick specific VMFS-FC or VMFS-iSCSI datastores inside an ESXi host cluster and protect them with **zero RTO / zero RPO** SnapMirror Active Sync replication. Two host-proximity modes are described: **uniform** (each ESXi host can see the peered datastore at both sites) and **non-uniform** (hosts only see the local copy, with host-coordinated I/O redirection). Reported typical failover IORT is ~11 ms in the uniform case, environment-dependent. Workloads can actively use I/O from either side, so VMs can read/write from either location.

Open source
Community

Community: NetApp extends Symmetric Active-Active SAN pathing to Unified AFF

Source: https://community.netapp.com/community/discussion/468316/netapp-extends-symmetric-active-active-san-pathing-to-unified-aff

Community announcement (NetApp engineer sydamin) that **symmetric active-active SAN pathing** is being extended from NetApp ASA into **NetApp AFF unified systems** starting with **ONTAP 9.19.1**. Symmetric active-active gives simultaneous active-optimized LUN access across both controllers in an HA pair, with predictable I/O behavior and minimal path-transition delay on failover. The AFF extension specifically targets customers consolidating mission-critical SAN, NAS, and mixed workloads onto a single ONTAP platform — getting ASA-class SAN resilience alongside unified-protocol capability. The post explicitly differentiates AFF (unified consolidation) from ASA (SAN-only, single-purpose) — NetApp is sharpening rather than blurring the line.

Open source
Community

Community: NetApp Harvest real-time GCNV insights on Cloud Monitoring

Source: https://community.netapp.com/community/discussion/468311/unlock-precision-at-scale-with-netapp-harvest-real-time-gcnv-insights-directly-on-cloud-monitoring

Community post (NetApp engineer Rishikesh) following up on NetApp Harvest's role as a single collection layer across on-prem ONTAP and Google Cloud NetApp Volumes. New in this post: real-time (sub-5-minute) performance and health telemetry from GCNV pools is now exported directly into Google Cloud Monitoring, complementing the existing five-minute polling. The motivation is concrete — I/O microbursts that hit transactional databases get averaged out in 5-minute samples, masking the actual latency spike that triggered application timeouts. By the time the averaged data is visible, the customer-impact window has already passed. Harvest's per-second resolution surfaces transient bottlenecks as they happen.

Open source
Community

Community: Monitoring storage volume growth at folder level (Active IQ + alternatives)

Source: https://community.netapp.com/t5/Discussions/td-p/468368

NetApp community thread asking how to monitor per-volume capacity growth **and** which folders inside the volume are growing, not just the top-level volume growth that Active IQ Unified Manager reports weekly. OP mentions Active IQ gives volume-level growth only (no folder breakdown) and asks whether anyone uses the ONTAP REST API to script a custom monitor. Multiple responders note that Active IQ Unified Manager only gives coarse weekly growth with a limited retention window — not useful for trend analysis or alerting. A community suggestion is **qtree quota capacity reporting via Xormon** (third-party NetApp monitoring tool) as a workaround that exposes per-qtree capacity and growth rates. The thread is useful for any NetApp operator building capacity dashboards: it surfaces the real gap between what Unified Manager shows (weekly volume totals) and what storage admins actually need (folder/file-level growth trending with enough history to forecast).

Open source
Community

Community: Monitor storage volume capacity and per-folder growth over time (ONTAP APIs)

Source: https://community.netapp.com/community/discussion/468368/monitor-storage-volume-capacity-over-time

A NetApp community question (answered) on the perennial capacity-monitoring problem: stay ahead of growing volumes *and* identify which folders inside each volume are growing. The asker notes that **Active IQ Unified Manager** gives volume-level growth but no folder-level drill-down, and wants to know what people use beyond that. Tags include FAS, CIFS/SMB, and Active IQ Unified Manager — the answer thread (6 comments, 19 views, marked **Answered**) discusses practical approaches such as the **ONTAP REST API** (`/storage/volumes` metrics, per-volume inode and capacity time-series), `volume efficiency` show commands, and **ONTAP File Analytics** / **XCP** for folder-level breakdowns. Discussion also touches **AIQUM** REST API endpoints that can be polled into a Grafana or observability stack.

Open source
Community

Community: Measuring Oracle Data Guard Fast-Start Failover RTO and RPO on GCNV

Source: https://community.netapp.com/community/discussion/468305/measuring-oracle-data-guard-fast-start-failover-rto-and-rpo-on-google-cloud-netapp-volumes

Community technical evaluation (NetApp engineer kanikaj) of Oracle 19c Data Guard with Fast-Start Failover (FSFO) running on **Google Cloud NetApp Volumes (GCNV) iSCSI** storage, measured across four failure scenarios: planned switchover, instance crash, VM-level outage, and network partition. Headline results: **observed RPO = 0 in all four scenarios; observed RTO ≈ 45–58 seconds app-visible** when running in Zero Data Loss Mode. Validation uses Oracle's own System Change Number (SCN) commit-ordering record for two of the four scenarios — so the zero-data-loss claim is anchored in Oracle-internal evidence rather than just application logs.

Open source
Community

Community: Locking to enable Trident controller scalability

Source: https://community.netapp.com/community/discussion/468318/locking-to-enable-trident-controller-scalability

Technical follow-up (NetApp engineer creeder) to the Trident 26.06 concurrency GA post — goes deeper into **how** the concurrent controller works internally. Trident orchestrates between Kubernetes resources (PVCs) and storage backends (ONTAP, ANF, etc.) with strict ordering requirements (e.g. FlexVol must exist before an export policy is attached on the ONTAP-NAS backend). The new design introduces a **concurrent cache** with hierarchical lock ordering — locks are always acquired and released in the same sequence, which prevents deadlocks while allowing many operations on different volumes to proceed in parallel. The post also references the broader pattern (hierarchical locks) used in databases and kernels for decades.

Open source
Community

Community: Independent Storage Scaling with GCNV NFS Datastores for Google Cloud VMware Engine

Source: https://community.netapp.com/community/discussion/468297/independent-storage-scaling-with-google-cloud-netapp-volumes-nfs-datastores-for-google-cloud-vmware-engine

Community walkthrough (by NetApp engineer sajith) of mounting Google Cloud NetApp Volumes (GCNV) Flex Unified NFS volumes as **external NFS datastores** on Google Cloud VMware Engine (GCVE) clusters. Walks the prerequisites (active GCVE private cloud with at least one cluster, an existing Flex Unified storage pool), provisions an NFS volume, and mounts it as a datastore — works with both zonal and regional Flex Unified storage pools. The architectural pitch is that storage now scales independently of ESXi node count, so adding nodes purely to grow datastore capacity is no longer the only option, while ONTAP data services (snapshots, clones, replication) stay available behind the volume.

Open source
Community

Community: FAS50 ONTAP 9.16.1P7 → 9.17.1P10 upgrade and SnapCenter 5.0 EOVS compatibility (CONTAP-621129)

Source: https://community.netapp.com/community/discussion/468367/fas50-upgrade-9-16-1p7-to-9-17-1p10-snapcenter-5-0-eovs-compatibility

Field-engineer checklist thread from a NetApp customer planning a FAS50 jump from **ONTAP 9.16.1P7 → 9.17.1P10**. The trigger is an open mgwd-panic / controller-reboot defect (**CONTAP-621129**) for which the fix is only present in 9.17.1P10 — not in any 9.16.1 patch. The interesting part is the upgrade-validation matrix the user assembles around a real Oracle / SQL / Exchange estate protected by **SnapCenter 5.0 SP2 + SnapCenter 6.2P1** — components that already show up as **EOVS** in NetApp's Interoperability Matrix Tool (IMT) for 9.17.1. Pre-upgrade gating inventory: per-DB stack (Linux OS, Oracle version/RU, RAC vs standalone, ASM, FC vs iSCSI, plug-in versions), per-app host inventory (Windows Server, SQL Server CU/AG topology, Exchange DAG), confirmation that 5.0 SP2 and 6.2P1 are independent SnapCenter Servers, that all protected storage is on the same FAS50, and any SnapMirror/DR secondary ONTAP. Pre-flight commands cited: `Upgrade Advisor` plus shelf/disk firmware check, plus Host Utilities / MPIO / HBA driver+firmware / SAN switch firmware review. The open question is whether EOVS in IMT means SnapCenter 5.0 must be upgraded first, or whether the ONTAP 9.17.1 upgrade can proceed independently.

Open source
Docs

AWS Transform now supports NetApp ONTAP as a migration target (SMB Tech AU)

Source: https://smbtech.au/news/aws-transform-now-supports-netapp-ontap-as-a-migration-target-for-enterprise-storage-workloads/

Announces AWS Transform adding NetApp ONTAP as a supported migration target, extending the AWS Transform AI-driven migration service beyond AWS-native targets to include NetApp's flagship storage OS. The integration lets enterprises use AWS Transform's generative-AI-assisted discovery, planning, and execution workflows to migrate workloads onto on-premises or cloud-resident ONTAP (including Amazon FSx for NetApp ONTAP).

Open source
News

2026-09-04-smbtech-aws-transform-supports-netapp-ontap

Source: https://smbtech.au/news/aws-transform-now-supports-netapp-ontap-as-a-migration-target-for-enterprise-storage-workloads/

NetApp and AWS integration of Amazon FSx for NetApp ONTAP into AWS Transform (now GA). AWS Transform's agentic-AI automates discovery/planning/migration of workloads to AWS, and with FSx for ONTAP as a supported storage target, enterprises can migrate attached storage (block) from on-premises or cloud alongside compute and networking in a single migration wave — eliminating intermediate storage platforms and separate storage-migration tools. Supports migrations from NetApp ONTAP or any on-premises block storage. Post-migration: built-in data protection, rapid cloning, multi-app support, and storage efficiency features (thin provisioning, dedupe, compression, snapshots) remain available on the managed FSx for ONTAP landing zone. Use cases called out: virtualised workloads (VM migrations without separate storage tools), enterprise databases (preserved performance/protection/consistency), and business-critical apps (single managed storage service). Quoted: Pravjit Tiwana, SVP & GM Cloud Storage and Services at NetApp ("Cloud migration projects often take longer and cost more than expected ... With AWS Transform and Amazon FSx for NetApp ONTAP, customers can simplify that process"). Available in all AWS regions where both services are offered. Why it matters: this is the first generally available path for FSx for ONTAP to be a native migration target inside an AWS-managed AI-driven migration tool — relevant to anyone planning hybrid cloud consolidations, VMware-to-AWS moves, or large enterprise database migrations that need ONTAP data-management features (SnapMirror, snapshots, FlexClone) preserved post-migration.

Open source
AI

2026-09-04-futurum-netapp-q1fy27-ai-ready-storage-enterprise-momentum

Source: https://futurumgroup.com/insights/netapp-q1-fy-2027-ai-ready-storage-drives-enterprise-momentum/

Futurum Research coverage of NetApp's Q1 FY 2027 earnings beat-and-raise quarter (revenue $2.03B, +30% YoY), with analysis tying the result to broad demand across customer sizes, geographies, workloads, and deployment models. Quotes CEO George Kurian emphasizing new-customer wins and the NetApp Platform role in powering AI and hybrid multi-cloud initiatives. Highlights named-account activity across AI, Kubernetes, Red Hat OpenShift, Azure NetApp Files, Cisco, CGI, and SK Telecom as concrete evidence of hybrid-cloud and enterprise-AI positioning. Why it matters: this is one of the earliest analyst takes on the Q1 FY27 print that walks through deal-level AI/Kubernetes/hybrid signals rather than just headline numbers — useful for anyone modeling how NetApp's all-flash refresh, AIPod/NVIDIA-DGX deployments, and BlueXP subscription growth compound into the raised FY27 guidance.

Open source
AI

NetApp and AWS Accelerate Storage Migrations with AWS Transform

Source: https://news.google.com/rss/articles/CBMilgFBVV95cUxNMzlZVEJBUjhyaTNjak1KSTJCTjJXcTNyYXU3anFJNmctZDVWbFVuVXRvV0ZIUDFHcE9TajEzYmxQN25pMEtaX2tCdXJHaFZtYWRFTHFZQWZIdHZ2SWJrUHlqcWx0dTBGTUd4dWlXZDJ1MGVuSnBFTzZYeG45TWxXVHM0bnYtWm50ckdFdGFlNWoyWDgwOXc?oc=5

NetApp announced expanded integration with AWS Transform, making NetApp ONTAP (including on-prem AFF/FAS and FSx for ONTAP) a supported migration target for enterprise storage modernization workloads. The integration streamlines lift-and-shift migrations to AWS by treating NetApp storage as a first-class endpoint in AWS Transform's automated discovery and migration flows, reducing manual data-mover configuration.

Open source
AI

NetApp Q1 Earnings Call Highlights Durable AI-Led Demand

Source: https://news.google.com/rss/articles/CBMisgFBVV95cUxOY0JTaG1laEhwMGtqWWtiem5ELWd3c2xwOXlCNkV5REt4NHhYcVBwdlFQRXhHay1iSnZUZkg1Zm5ieTE0NUFXaGdDN1NxSndwNHRYTHVwamJxbVAzWWpFdVl1SXMyb0FuQlB2LTdtODVMQzJCbnJFeFllWDQ2bjRjZmFSQUNQak9fWGZPVnNyTFhSbUF0Q1dheWxwUHlxNjFoY0NpYnZpbFFXMGxkQmxubjV3?oc=5

NetApp reported Q1 FY2027 results with revenue of approximately $2.03B (up ~30% YoY) and raised full-year guidance by ~$650M, driven primarily by AI-related all-flash demand. Management emphasized that AI-led bookings have moved from a future aspiration to a recurring revenue contributor, with all-flash array momentum and object-storage growth as supporting tailwinds.

Open source
AI

NetApp ONTAP adds validated storage support for VMware Cloud Foundation 9.1

Source: https://news.google.com/rss/articles/CBMiqAFBVV95cUxQOW5zekdJMGlmNHB1VU1YUjM3MGF3TVdBM2lqQUVUN09LRFFBeVRyQnZ0ZldFdTU3cUc1eDZndkNOZFVwN25KaFVEM2o3VllJNHpKNkZFMjhvOF9XdkFCOUJvdDFvMzFXZUpFWFVqMEt4SXI3R2ZsSEotS1NzQnM2a1cwYWJEbVFOY3Z6eGl2OFExcERTeDliRlczVEhrSzA1VExLVXRxbzU?oc=5

NetApp ONTAP has been added to VMware's Cloud Foundation 9.1 validated storage compatibility matrix, certifying ONTAP 9.x as a primary storage backend for VCF 9.1 deployments (vVols, NFS datastores, iSCSI). This validation matters for the 'VMware exodus' crowd: customers consolidating onto VCF 9.1 can keep NetApp as their data plane with full vSphere APIs for Storage Awareness (VASA) and array-integrated snapshot support.

Open source
AI

NetApp Helps Customers Accelerate Adoption of Latest VMware Cloud Foundation Innovations

Source: https://news.google.com/rss/articles/CBMi1AFBVV95cUxQTTdIb29SQXdPWHNlcXFTbkJ3WHZ3Sll6ZEgtSFBRWFNXV3R6emFKMGVxeFZRTF8tSV9kQzA5RjFzbGRTUndpSjJKMU1NeTBubnAxM3lrcHIwYm1oZHRSVERJV01POHAwdGRrMklpbGwybWhGR3kxQmFDMWM2aXhLRlowZ2lYTGpoYU1iWnIwS3NucG5VWWNFaVZlNTNxUjZqRXVjQnlFdVlQVmFhdFhUV1NCR2dIdU8zVEE1cEdlVktOT0gxdjV1Q2pGbVdYRE9QODFXQw?oc=5

Industry coverage of NetApp's Q1 FY2027 earnings and AI-driven storage demand, including commentary on guidance, AI workload bookings, and competitive positioning against Pure Storage and Dell. The piece is useful context for tracking how AI infrastructure capex is flowing through enterprise storage vendors.

Open source
AI

NetApp CEO: AI Is No Longer A Future Aspiration—It’s Driving Record Growth Now

Source: https://news.google.com/rss/articles/CBMitgFBVV95cUxOSjRfcUNkOFRsYVoxR0ZnZWhLMHFOV0YxUjl4bkJobktDOWJselZyUjgtNlc0Q09WTWZKRnd5bFlnTWZ2ZnY5emhkSFpjNXpmNnJzRFpFVklXa2tUdGd1eU5xU0tMNnBXNFpjZ0M3eVJyUVBtdWdZZlN4b1pIeHhSLTFPRkVWc0xvM2Y1VEJoTE11RlZMU0VLMDRwWUw0YTFwNE5FMFFzaU9BWl9fbFowYnU5cUwxQQ?oc=5

Industry coverage of NetApp's Q1 FY2027 earnings and AI-driven storage demand, including commentary on guidance, AI workload bookings, and competitive positioning against Pure Storage and Dell. The piece is useful context for tracking how AI infrastructure capex is flowing through enterprise storage vendors.

Open source
AI

NetApp (NTAP) Added ONTAP Support For Cloud Foundation 9.1

Source: https://news.google.com/rss/articles/CBMitwFBVV95cUxNeHctMmU0TGU3OGxheS1pUUhOTXhHSzlsQWNBaUJwUlFzTmN4YVd6QWFLQ3hpeDJ1YkpEU19GY0VRb3otQUtNS0FTZmRrbW9hSFB3UzIxQzdwRHMzaXJvV0xxRlQyU091bldTUERyMm5pWmxsNGhOM0J3RERYTlcxYzRqRERZdmJLN2hVTDcxWUNXemtOLTA5RHBoMkI4dXRpZUoxTWhoMU9hXzZoemROZWtNVHJnX2PSAbwBQVVfeXFMT3NFTEhub0RtcGR3b1lhU0dmV3RwbEQ5Z21jT0Q4SjU3S2NLUGZXS3VEcTZ5eVBzczNyOWRTTFRWWDJKVHpEeWE3SGw5T3VzUDUzbks5QWQ3NUh4SHNPWVZOZ2FURXlsUW9haE9FQms0ZEVWQ0Jfa0ppTVZ2ZmJMUmViZTllZmhtRFl0UmNiX2lDOFpfN3IwemdHV29FTkxYXzRVekZOMDZ2a1lQVXExZGJnSXRzd1FrcHFmN1E?oc=5

NetApp ONTAP has been added to VMware's Cloud Foundation 9.1 validated storage compatibility matrix, certifying ONTAP 9.x as a primary storage backend for VCF 9.1 deployments (vVols, NFS datastores, iSCSI). This validation matters for the 'VMware exodus' crowd: customers consolidating onto VCF 9.1 can keep NetApp as their data plane with full vSphere APIs for Storage Awareness (VASA) and array-integrated snapshot support.

Open source
AI

NetApp (NASDAQ:NTAP) Posts Record Q1, Raises Outlook (Value The Markets)

Source: https://www.valuethemarkets.com/news/netapp-nasdaq-ntap-posts-record-q1-raises-outlook

Investor-side coverage of NetApp's Q1 FY27 earnings print: revenue beat consensus with all-flash arrays and AI-data-platform bookings cited as the growth engine, plus a raised full-year guidance. The article frames the quarter as a structural inflection — AI demand is moving from pilots to in-line enterprise infrastructure spend, and NetApp's data-tier positioning (ONTAP, AFX, AI Data Engine) lets it capture a chunk of that without competing on the model-training GPU side.

Open source
AI

NTAP Q2 Deep Dive: AI, Cloud, and Product Innovation Drive Market Outperformance

Source: https://news.google.com/rss/articles/CBMi2AFBVV95cUxOUWZ3a2ZiOWV4dDdXc0E4UXZPcEFxdHZ3Sk4tak1rb2VxcWZiVGdHa0FvNlJlZ1c4UGJUbmpGZ19IbnhKZ3FyQ29hTXZSbU5xYjR2Rmo5YjZJQU1lS19nUXNKd0NDZnA5NTF5bFJyU1JjOHY3SXo4el9JazQ2b1Q5M2JweV9XWklZaG1PeE5xYkZWc1c4bUx4WmRYOV84VFZpa1ZuWVpSZXdVekZGYlFQdmI0OG1XREFKaG5XbVpJOVN0YXozSThRdTNzQVZvRWhqQjd4V0ZsS0U?oc=5

Industry coverage of NetApp's Q1 FY2027 earnings and AI-driven storage demand, including commentary on guidance, AI workload bookings, and competitive positioning against Pure Storage and Dell. The piece is useful context for tracking how AI infrastructure capex is flowing through enterprise storage vendors.

Open source
Docs

Migrate VMware Storage to Amazon FSx for NetApp ONTAP using AWS Transform

Source: https://aws.amazon.com/blogs/storage/migrate-vmware-storage-to-amazon-fsx-for-netapp-ontap-using-aws-transform/

AWS Storage Blog (Advanced / 300, Technical How-to). This technical how-to walks VMware administrators and storage engineers through a direct migration path from on-premises enterprise storage (NetApp ONTAP, Dell, Everpure, HPE) to Amazon FSx for NetApp ONTAP using AWS Transform, the agentic AI–driven modernization service. It explains why enterprise storage capabilities (automatic failover, instant snapshots, writable clones, inline deduplication, multi-protocol access) must be preserved Day 1, then maps each on-prem capability to its FSx for ONTAP counterpart, and shows how AWS Transform delivers non-disruptive testing, built-in failback, and atomic cutover that moves compute, network, and storage together in one operation. Existing ONTAP customers keep their operational workflows, automation scripts, and monitoring tools; customers from other platforms get the same category of capabilities without adopting unfamiliar tooling. The post matters because Q1 FY27 saw NetApp emphasise VMware Cloud Foundation 9.1 + FSx for ONTAP + AWS Transform as the canonical path for VMware customers modernising around ONTAP, and AWS Transform's AI-driven discovery/dependency-mapping reduces the project-blocking re-architecture conversation that usually delays enterprise storage migrations.

Open source
AI

AWS Storage Blog — Migrate VMware Storage to Amazon FSx for NetApp ONTAP using AWS Transform

Source: https://aws.amazon.com/blogs/storage/migrate-vmware-storage-to-amazon-fsx-for-netapp-ontap-using-aws-transform/

Official AWS Storage Blog post (Sep 3 2026, authors Kiran Chukkala / Arun K / Srivalsan Mannoor Sudhagar) walking through how AWS Transform now migrates block-storage workloads directly to Amazon FSx for NetApp ONTAP as part of a coordinated VMware-to-AWS wave that moves compute, network, and storage together in one atomic cutover. The piece explicitly maps the on-premises VMware storage capabilities customers depend on — automatic failover (RPO/RTO), inline dedup/compression (60–80% raw-capacity reduction), crash-consistent snapshots, writable clones, multi-protocol access (iSCSI, FC, NFS, SMB), and shared storage for vMotion/HA/DRS — to FSx for ONTAP equivalents (Multi-AZ failover, inline dedup with auto-tiering to S3, instant snapshots and space-efficient FlexClone, iSCSI LUNs across EC2, etc.). Key technical detail: AWS Transform handles discovery, planning, and execution with non-disruptive testing and built-in failback; the cutover is atomic across compute, network, and storage so the day-2 capability parity is preserved from Day 1. Why this matters: it is the first tier-1 primary-source walkthrough (from AWS itself, not third-party coverage) of the new AWS Transform ↔ FSx for ONTAP path, validating the NetApp side of the integration announced earlier in the week. For NetApp Black Box readers running hybrid VMware estates, this post is the authoritative reference for how the migration actually moves data — useful as both an architecture source and an operations reference.

Open source
AI

AI adds impetus to NetApp revenue rise

Source: https://news.google.com/rss/articles/CBMimgFBVV95cUxQMGRrV1RXdTU5X2hOWVpoSzVaWVg5MXB1MFhBMkVPWXIxb003WnlFT1NTR1JpSDBFZVM5R0puNkRtdEliNXlsdFNuN3Ewc2dnalZ5N0N2ek1qLVpHbWM1RmkzUzVCSXRJMFJlR3h4SFdnbVB2a1I5SkVSeTFtTUVUYnhpU1ltUWVGTllYNnBQUVhOc0tpa1RuT0lR?oc=5

Industry coverage of NetApp's AI-driven revenue acceleration: AI workload demand lifted both NetApp and HPE to record quarters, though investors sold both names on concerns about AI capex sustainability. The pieces detail how NetApp's all-flash and object storage lines are positioned as primary data planes for enterprise AI/ML pipelines, complementing NVIDIA GPU infrastructure.

Open source
News

2026-09-04-pulse2-netapp-q1fy27-record-revenue

Source: Pulse 2.0

Pulse 2.0 (Amit Chowdhry), dated 2026-09-03, 13:13 UTC. Mainstream tech-press recap of NetApp's Q1 FY2027 (quarter ended July 31, 2026) earnings beat: net revenue of $2.03B (+30% YoY from $1.56B prior-year period); Hybrid Cloud segment $1.82B (+30%); Public Cloud segment $206M (+28%, a record); billings $2.06B (+36%); GAAP operating margin 23.9%; non-GAAP operating margin 31.9%; free cash flow $401M. The article frames the quarter as the cleanest public confirmation that NetApp's AI-storage attach (AIPod / AIPod Mini / AIPod with NVIDIA) is the dominant growth vector, with all-flash array revenue hitting record levels — and the raised FY27 guidance as management confidence that the demand is durable, not a single-quarter anomaly. Why it matters for ONTAP admins: when an analyst-friendly third-party source confirms the headline numbers from the investor press release, it removes one of the usual pushback lines ("that was just an IR talking point") and makes the case for AFF/ASA refresh-with-AI-roadmap easier to defend in a budget review. It also confirms $401M free cash flow — the same figure flagged in the investor release and the source of the post-print stock weakness, so admins defending AI-storage capex can pre-empt the FCF question by citing this independent recap.

Open source
Advisory

2026-09-04-ntap-20260903-0009

Source: https://security.netapp.com/advisory/NTAP-20260903-0009/

CVEs: CVE-2026-11972. Affected products (excerpt): Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Management Services for Element Software and NetApp HCI.

Open source
Advisory

2026-09-04-ntap-20260903-0001

Source: https://security.netapp.com/advisory/NTAP-20260903-0001/

CVEs: CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076. Affected products (excerpt): .

Open source
News

2026-09-04-marketbeat-ntap-analyst-pt-roundup

Source: MarketBeat analyst roundup

MarketBeat's NTAP analyst price-target page (consensus $192.07, median $169.33, low $124.07) captures the wall-street reaction to NetApp's Q1 FY27 earnings beat in real time. On 9/3/2026 alone four firms moved targets: Citigroup (Asiya Merchant) cut to $190 from $209 — the only cut in the batch, framed as a "Lower Target / Neutral" tweak as Citi digests the FCF commentary; TD Cowen (Krish Sankar) reiterated Buy with a $200 target; Morgan Stanley (Erik Woodring) lifted to $191 from $173 — the closest to current price, "Equal Weight"; Wedbush (Matt Bryson) boosted to $170 from $150; Susquehanna (Mehdi Hosseini) lifted to $195 from $185. Earlier in 2026 the bank-side consensus had already drifted up — Bank of America (Wamsi Mohan) boosted to $206 from $180 on 8/31 ahead of the print; Argus raised to $200 from $130 on 6/1; Barclays moved to $199 from $120 back in May (Tim Long, Overweight). The mix is consistent with the post-print stock weakness story: revenue/EPS beat drove target bumps, but the FCF question stopped the street from upgrading en masse. Why it matters for ONTAP admins: this is the cleanest single-source view of how analyst confidence is shifting around the AI-storage thesis NetApp is selling. When storage admins defend AFF/ASA capex to a CFO who watches sell-side targets, the Wedbush→$170 and Susquehanna→$195 prints are useful evidence that growth durability is more consensus than the post-print 10% stock move suggests.

Open source
News

2026-09-04-https-www-hpcwire-com-2026-09-03-netapp-helps-customers-accelerate-adoption-of-l

Source: https://www.hpcwire.com/2026/09/03/netapp-helps-customers-accelerate-adoption-of-latest-vmware-cloud-foundation-innovations/

HPCwire coverage of NetApp's announcement that ONTAP is now validated for VMware Cloud Foundation 9.1, enabling customers to standardize on NetApp storage for VCF deployments — a key step for hybrid-cloud AI/VM workloads that need enterprise-grade data services.

Open source
AI

2026-09-04-https-aithority-com-2026-09-03-netapp-aws-accelerate-storage-migrations-with-aws

Source: https://aithority.com/news/netapp-and-aws-accelerate-storage-migrations-with-aws-transform/

AiThority coverage of NetApp expanding AWS Transform support to accelerate enterprise storage migrations — NetApp ONTAP integration with AWS Transform provides automated discovery, planning, and migration workflows for moving on-prem file/block workloads to AWS, a key enabler for AI-data-lake consolidation in the cloud.

Open source
Product

2026-09-04-aithority-vmware-cloud-foundation-91

Source: https://www.aithority.com/technology/netapp/netapp-helps-customers-accelerate-adoption-of-latest-vmware-cloud-foundation-innovations/

AiThority coverage of NetApp's VCF 9.1 announcement (Sept 3, 2026). NetApp's first-party cloud storage services (FSx for NetApp ONTAP, Google Cloud NetApp Volumes, Azure NetApp Files) are positioned as the only external enterprise storage certified across the major hyperscalers for VMware Cloud Foundation environments — so VCF customers can run VMware workloads in the cloud without refactoring via VCF license portability. Quoted: Alvaro Celis, Chief Partner and Ecosystem Officer at NetApp: "NetApp continues to innovate to ensure VCF customers can operate consistently and without disruption across cloud environments. Together with Broadcom, we are giving organizations the autonomy to optimize, protect, and scale their virtualized environments across any cloud on their own terms." VCF 9.1 highlights cited: density gains for VMs and containerized AI workloads, automated resource management, integration with ONTAP for cost-effective enterprise-grade storage. Why it matters: this is NetApp's play to remain the default external data plane for VMware estates during the Broadcom-era VCF transition — both for traditional VMs and for AI/containerized workloads running in VCF.

Open source
Docs

2026-09-03-tr-1462-2-ansible-automation-ontap

Source: NetApp

NetApp released a refreshed technical report (TR-1462-2) covering end-to-end automation of ONTAP cluster operations through Red Hat Ansible Automation Platform (AAP). The report walks through installing `netapp.ontap` collection from Ansible Galaxy, configuring the ONTAP REST API credential (`/api/cluster` and `/api/security`), and using Ansible Controller (Execution Environments with `python 3.11` + `netapp-lib`) to drive day-1 (cluster setup, SVM create, NFS/SMB export policy) and day-2 (volume create, snapshot policy, SnapMirror schedule, quota report) workflows. The -2 revision adds AAP 2.5 workflow job templates and inventory plug-ins, plus integration with ONTAP's webhook notifications (`/api/support/auto-support/events`) so Ansible can react to ASUP events and run remediation playbooks automatically.

Open source
Docs

2026-09-03-spglobal-fsx-ontap-dr-snapshots-aws

Source: AWS Big Data Blog

AWS published an architectural case study detailing how S&P Global built a multi-region disaster recovery solution for SQL Server workloads running on Amazon FSx for NetApp ONTAP, using ONTAP's native snapshot technology plus SnapMirror to replicate the FSx file systems cross-region. The design relies on consistent application-aware snapshots via the FSx ONTAP REST API (`/api/protocols/snapmirror/relationships` and `/api/storage/volumes/{id}/snapshots`) so that VSS-equivalent quiescing happens before the snapshot is taken, then the snapshots are replicated to a secondary FSx ONTAP instance in the DR region. Recovery time objectives (RTO) hit sub-60 minutes because the SnapMirror destination is kept near-current and the SQL Server databases are mounted from the secondary FSx volume rather than being restored from backup.

Open source
News

2026-09-03-netapp-q1-2027-record-revenue-24-7-wall-st

Source: Original source unavailable (canonical URL returned 404; no replacement verified)

24/7 Wall St. coverage of NetApp's Q1 FY2027 print (reported Sep 2, quarter ended Jul 31). Frames the quarter as a record-revenue/big-guidance-raise event and contrasts the strong headline numbers with the post-print stock drop on light operating-cash-flow commentary. Useful second-source read on the DataPelago acquisition framing and the raised $7.975B–$8.225B FY27 revenue band — the all-flash-array +47% YoY figure is the line most enterprise storage admins should track against their own AFF/ASA refresh roadmaps.

Archive digest
News

2026-09-03-netapp-ntap-stock-thursday-benzinga

Source: https://www.benzinga.com/news/26/09/03/netapp-stock-thursday

Benzinga intraday note on NTAP's Sep 3 price action, which followed the Q1 FY27 print from the prior day. Useful as a market-reaction timestamp and to track analyst commentary momentum (BofA, Wells Fargo) after the record-revenue + DataPelago-acquired quarter. For storage admins the takeaway is sentiment context: AI-storage demand narrative is intact with Wall Street, even when shares trade off on free-cash-flow conservatism.

Open source
News

2026-09-03-netapp-helps-customers-accelerate-vmware-cloud-foundation-aithority

Source: https://aithority.com/2026/09/03/netapp-helps-customers-accelerate-adoption-of-latest-vmware-cloud-foundation-innovations/

AiThority's coverage of NetApp's VCF 9.1 launch support, with explicit mention of the ONTAP for VMware vSphere toolchain (ONTAP Tools for VMware 10.x, vVols 3.0, NVMe/TCP) and the SnapMirror/SnapCenter-based DR paths for VVF/VCF deployments. Use this as a second-source validation that NetApp is positioning ONTAP as a strategic VCF backing for both traditional VM and AI/VM mixed estates — useful for architects reviewing vendor-supported reference designs.

Open source
Docs

2026-09-03-flex-unified-ontap-mode-ga-netapp

Source: NetApp

NetApp announced the general availability of "Flex Unified ONTAP-mode" — a new deployment mode that consolidates SAN (iSCSI/FC) and NAS (NFS/SMB) protocols on the same FlexVol volume while exposing a unified management plane via ONTAP System Manager. The new mode replaces the prior protocol-licensing friction where enabling both SAN and NAS on a single SVM required a feature license key swap; Flex Unified mode activates all four protocols at cluster create time and lets admins carve LUNs and shares from the same aggregate. ONTAP 9.16.1+ is required. Documentation note: cluster peers should still use `cluster peer create` and SVM peering remains a separate workflow — the only change is the unified licensing envelope.

Open source
News

2026-09-03-aws-transform-ontap-migrations-yahoo

Source: Yahoo Finance

NetApp announced an expanded integration with AWS Transform, the AWS generative-AI-powered service that automates large-scale VMware-to-EC2 and storage migration projects. The deeper support is intended to let enterprises move NetApp ONTAP-based workloads — including on-premises AFF/FAS volumes, SnapMirror relationships, and FSx for ONTAP instances — into AWS with auto-generated migration plans, dependency mapping, and execution runbooks generated from existing ONTAP inventory. For NetApp admins this matters because AWS Transform now treats ONTAP as a first-class source system: SnapMirror topology, SVM exports, NFS/SMB share ACLs, and FlexClone lineage are factored into the AI-generated cutover plan rather than being reconstructed manually.

Open source
AI

2026-09-03-ai-impetus-netapp-revenue-blocks-files

Source: https://www.blocksandfiles.com/flash/2026/09/03/ai-adds-impetus-to-netapp-revenue-rise/5294164

Blocks & Files' analyst take on NetApp's Q1 FY2027 earnings beat: AI-driven all-flash attach (AIPod, AIPod Mini, AIPod with NVIDIA) is the dominant growth vector, but the storage market's reaction is more measured than the storage-vendor tone. Useful for understanding how NetApp's AI-storage momentum is being priced against the broader enterprise capex slowdown narrative. Filed the same day as NetApp's earnings (Sep 3 2026).

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-58094-freebsd-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260903-0006

CVE-2026-58094 FreeBSD Vulnerability in NetApp Products. All supported versions of FreeBSD are susceptible. An unprivileged local user can escalate privileges. Impact: disclosure of sensitive information, data modification, or DoS. Part of the Sept 3 FreeBSD local-privilege-escalation cluster. Review the NetApp affected-products table in the advisory and align patching with NTAP-20260903-0004 / -0005 / -0007 to avoid partial remediation.

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-58093-freebsd-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260903-0007

CVE-2026-58093 FreeBSD Vulnerability in NetApp Products. All supported versions of FreeBSD are susceptible. An unprivileged local user can escalate privileges. Successful exploitation can lead to disclosure of sensitive information, data modification, or Denial of Service. Fourth CVE in the Sept 3 FreeBSD privilege-escalation cluster (with -58090 / -58091 / -58094). Apply FreeBSD security errata together to keep NetApp controllers in a consistent patched state.

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-58092-freebsd-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260903-0008

CVE-2026-58092 FreeBSD Vulnerability in NetApp Products. FreeBSD versions 15.0 and later are susceptible. Certain mac_do rules can be abused to set a process' group ID to 0 (effective root-equivalent group), leading to disclosure of sensitive information or addition or modification of data. The mac_do(4) framework is uncommon on production NetApp controllers but applies to ONTAP Select / FreeBSD-based NetApp edge nodes where jail-friendly mac_do policies are in use. See the advisory for affected products and remediation.

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-58091-freebsd-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260903-0005

CVE-2026-58091 FreeBSD Vulnerability in NetApp Products. All supported versions of FreeBSD are susceptible. An unprivileged local user can escalate privileges. Successful exploitation can lead to disclosure of sensitive information, addition or modification of data, or Denial of Service. Part of the Sept 3 FreeBSD local-privilege-escalation cluster (also CVE-2026-58090, -58093, -58094). Plan a coordinated FreeBSD security patch window across affected NetApp controllers.

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-58090-freebsd-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260903-0004

CVE-2026-58090 FreeBSD Vulnerability in NetApp Products. FreeBSD versions 15.0 and later are susceptible. An unprivileged local user can escalate privileges. Impact ranges from disclosure of sensitive information to data modification or DoS. NetApp-affected products and remediation steps are listed in the advisory body; track alongside CVE-2026-58091 / -58093 / -58094 (same privilege-escalation family, also published Sept 3) for a single change window.

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-58089-freebsd-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260903-0003

CVE-2026-58089 FreeBSD Vulnerability in NetApp Products. All supported versions of FreeBSD are susceptible. An unprivileged local user who has attached PMCs (Performance Monitoring Counters) to a process can continue monitoring it after the process executes a setuid or setgid binary, leading to disclosure of sensitive information, addition or modification of data, or Denial of Service. The bug class is a process-credentials leak via hwpmc(4); applies wherever NetApp ships FreeBSD-derived code paths with PMC tooling enabled.

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-53362-linux-kernel-vulnerability-in-netapp-products

Source: https://security.netapp.com/advisory/NTAP-20260903-0010

CVE-2026-53362 Linux Kernel Vulnerability in NetApp Products. Linux kernel versions 6.0-rc1 through 6.1.176, 6.13-rc1 through 6.18.37, 6.19-rc1 through 7.1.2, 6.2-rc1 through 6.6.143, and 6.7-rc1 through 6.12.94 are susceptible. Successful exploitation can lead to disclosure of sensitive information, addition or modification of data, or Denial of Service. Applies wherever NetApp ships Linux-based nodes — ONTAP Select on Linux hypervisors, BlueXP/Cloud Manager SaaS connectors, StorageGRID appliance nodes, and AI control-plane pods running AIPod with NVIDIA — see the advisory's affected-products table for exact applicability and remediation per ONTAP / BlueXP / StorageGRID release.

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-11972-python-vulnerability-in-netapp-products

Source: https://security.netapp.com/advisory/NTAP-20260903-0009

CVE-2026-11972 Python Vulnerability in NetApp Products. Python versions 2.3 through 3.10.20, 3.11.0a1 through 3.11.15, 3.12.0a1 through 3.12.13, 3.13.0a1 through 3.13.14, 3.14.0a1 through 3.14.6, and 3.15.0a1 through 3.15.0b3 are susceptible. Successful exploitation leads to Denial of Service (DoS). Because NetApp management tooling (OnCommand Workflow Automation, Active IQ, Docker images behind BlueXP connectors, Ansible modules) ships CPython, customers should confirm the bundled Python version against the advisory's affected-products list before the next NetApp software update window.

Open source
Advisory

2026-09-03-2026-09-03-august-2026-freebsd-point-to-point-protocol-vulner

Source: https://security.netapp.com/advisory/NTAP-20260903-0002

August 2026 FreeBSD Point-to-Point Protocol (PPP) Vulnerabilities in NetApp Products. All supported FreeBSD versions are susceptible. CVEs: CVE-2026-58095, CVE-2026-58096, CVE-2026-58097. A malicious PPP peer (CVE-2026-58095 or CVE-2026-58096) or a local user with access to the ppp(8) command interface (CVE-2026-58097) can crash ppp(8) or potentially execute arbitrary code as root. Successful exploitation can lead to disclosure of sensitive information, modification of data, or DoS. PPP exposure is uncommon on production NetApp storage but applies to ONTAP Select and any deployment where FreeBSD's ppp(8) is reachable; review the affected-product list in the advisory before scheduling the FreeBSD security update.

Open source
Advisory

2026-09-03-2026-09-03-august-2026-freebsd-openssl-vulnerabilities-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260903-0001

August 2026 FreeBSD OpenSSL Vulnerabilities in NetApp Products. Multi-CVE roll-up covering OpenSSL vulnerabilities shipped in supported FreeBSD releases prior to 15.1-RELEASE-p3, 15.0-RELEASE-p13, and 14.4-RELEASE-p9. CVEs: CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076. Successful exploitation can lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS), or potential remote code execution. Because ONTAP 9.x relies on FreeBSD internally and ONTAP Select / ONTAP on third-party hosts may carry upstream OpenSSL packages, customers should track the per-CVE remediation matrix in the advisory text. Cross-references the Sept 2 individual OpenSSL CVEs (NTAP-20260902-0001..-0009) which were published one day earlier.

Open source
AI

[NetApp Q1 2027 Earnings Call] NetApp Revenue Surges 30% to $2.03B, Raises FY27 Guidance by $650M as AI-Driven Demand Accelerates

Source: https://news.google.com/rss/articles/CBMiXkFVX3lxTE5BX1lobmRRYXdsczRJQVVRRHdHOGVVRi0tc0RmZGRvaWRhRDE2SkxzUFVEekJUNXoxOHdxWVQya1FFaHdXSzhjWk0xZ0MxY053UVhQLXRrQ1h0TE10cWc?oc=5

Industry coverage of NetApp's Q1 FY2027 earnings and AI-driven storage demand, including commentary on guidance, AI workload bookings, and competitive positioning against Pure Storage and Dell. The piece is useful context for tracking how AI infrastructure capex is flowing through enterprise storage vendors.

Open source
AI

NetApp expects strong Q3 earnings with 18% revenue rise (Pluang)

Source: https://pluang.com/en/news/2026/09/02/netapp-expects-strong-q3-earnings-with-18-revenue-rise-96108

Pre-print coverage of analyst expectations for NetApp's upcoming quarter: revenue growth projected in the high-teens, with AI-driven all-flash and hybrid-cloud bookings as the primary drivers. The piece synthesizes sell-side estimates and frames NetApp as one of the enterprise storage vendors most exposed to AI tailwinds in the second half of FY27.

Open source
AI

NetApp earnings today: AI momentum meets high expectations By Investing.com

Source: https://news.google.com/rss/articles/CBMiugFBVV95cUxOZjhtZU8xci1xSFdiZlFCVzUtai01blRBZURUXzdlVFQ0NWpOWGM2Wm9iR01BdzlOd2hWb3FXTzh6eGI3ckNZaC15c1JYQUJMTUFnNzNLaHNvNk42d05Cd0t0R2NsU1BKZnE5TmJISXZqS005Q25NekRabjA5YkJDM2UyUkhGajRTOXJkb19lU2cxcjJnVjB1M2tPYkhjX0xuVTVJbFQ4dGhOVlZZam5yeFQ2ako0emxtdVE?oc=5

Industry coverage of NetApp's Q1 FY2027 earnings and AI-driven storage demand, including commentary on guidance, AI workload bookings, and competitive positioning against Pure Storage and Dell. The piece is useful context for tracking how AI infrastructure capex is flowing through enterprise storage vendors.

Open source
AI

NetApp earnings today: AI momentum meets high expectations (Investing.com)

Source: https://za.investing.com/news/netapp-earnings-today-ai-momentum-meets-high-expectations-249CH-2430054

Pre-earnings note from Investing.com framing the Q1 FY27 print as a high-bar moment: consensus had already priced in a beat-and-raise on the AI thesis, so the article focuses on what would constitute an upside surprise versus in-line execution. Notes that the buy-side was watching all-flash array bookings, AI-data-platform attached-storage metrics, and gross-margin commentary — all of which were positives in the eventual print.

Open source
AI

NetApp Reports First Quarter of Fiscal Year 2027 Results (official press release)

Source: https://investors.netapp.com/news/news-details/2026/NetApp-Reports-First-Quarter-of-Fiscal-Year-2027-Results/default.aspx

NetApp's official Q1 FY27 earnings press release (Sept 2 2026, quarter ended July 31 2026): record net revenues of $2.03B (+30% YoY), record all-flash array net revenues of $1.3B (+47% YoY), record Public Cloud segment revenue of $206M (+28% YoY), GAAP EPS $1.88 (+63% YoY), record non-GAAP EPS $2.58 (+66% YoY), billings $2.057B (+36% YoY), GAAP operating margin 23.9% / non-GAAP 31.9%, net cash from operations $503M. CEO George Kurian quoted: "Our momentum reflects not only the trust of existing customers but also our success in winning new ones, as organizations choose the NetApp Platform to power their AI and hybrid multi-cloud initiatives." Notable AI signal embedded in the headline bullets: NetApp acquired DataPelago, Inc., an AI data infrastructure company, "to help customers simplify and accelerate AI deployment at scale" — DataPelago's GPU-accelerated data-processing technology (acquired earlier in 2026 per separate coverage) is now positioned as a core NetApp platform component for AI ingestion and transformation. Free cash flow declined ~35% YoY to $401M, explaining the post-print stock drop despite the topline beat. Why this matters: this is the canonical primary source for the Q1 FY27 numbers — every other article (Pulse 2.0, finance.biggo, Investing.com, MarketBeat, SiliconANGLE, BofA, etc.) is downstream of this release. Use this URL whenever an NCDA exam answer, customer presentation, or analyst brief cites the exact figures.

Open source
AI

NetApp Q1 FY27 slides reveal strong AI demand despite stock selloff

Source: https://news.google.com/rss/articles/CBMiwgFBVV95cUxQVkhJbFIwTkZJRzBTQTYxVUFlVFNDTzhIVjlsb2F3b1pKZkJwV2p4RXJCdjdWZFMzeEJRZ2hkUFZVQmY3XzdlaHVxMjRMVS1lOXA0bTE4OU11VGpmaVVHZ2NybC0xbkdreGVyY1VjbExUWUxFVDlYVmV5T09mZTB3eWFkdmR0cktPdzlXcGRzSFpIUk16RVozS2tyamhYTWttYnRjZUZsYTNFMDYxSUFVaHJrSmxjc3lsdmxZV2V1MnpLQQ?oc=5

NetApp reported Q1 FY2027 results with revenue of approximately $2.03B (up ~30% YoY) and raised full-year guidance by ~$650M, driven primarily by AI-related all-flash demand. Management emphasized that AI-led bookings have moved from a future aspiration to a recurring revenue contributor, with all-flash array momentum and object-storage growth as supporting tailwinds.

Open source
AI

NetApp Inc (NTAP) JUL/2026 Earning Prediction

Source: https://news.google.com/rss/articles/CBMiggFBVV95cUxOb3k4Y0FhaDY5bndPaDdUUEd3MFNFQUt4YVk2ZWIxbHI0LWVXV3VQSGd6UEZJejdrMENwNHcyYW1GYUQzcHpmeGZxcU1nSXVWOThVSHpsNEdBMHlfcVRxSURzRGpseWlCNHExVGxjV09SeWRPcVdZeDQ0U19vdGRMbEl3?oc=5

Industry coverage of NetApp's Q1 FY2027 earnings and AI-driven storage demand, including commentary on guidance, AI workload bookings, and competitive positioning against Pure Storage and Dell. The piece is useful context for tracking how AI infrastructure capex is flowing through enterprise storage vendors.

Open source
AI

NetApp Inc (NTAP) Earnings Prediction (Intellectia AI)

Source: https://intellectia.ai/news/detail/netapp-inc-ntap-jul2026-earning-prediction-9tK4j8z9bU9X6mL8C1

Earnings-prediction analysis from Intellectia AI (an AI-native equity research platform) on NetApp's Q1 FY27 print. Combines historical earnings patterns, AI-storage sector sentiment, and machine-learning-based consensus modeling to produce a directional EPS/revenue forecast ahead of the release. The article is itself a meta-example of an AI tool being used to predict the earnings of a company whose data infrastructure powers AI workloads.

Open source
Advisory

CVE-2026-73180 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0020

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.43 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-68763 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0019

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.39 through 9.0.120, and 8.5.59 through 8.5.100 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-68569 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0016

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.0 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-68525 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0013

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.0 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-66422 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0015

Apache Tomcat versions 1.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.25 through 9.0.120, 8.5.46 through 8.5.100 (EOL), and 7.0.97 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-65905 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0011

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.30 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-65637 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0010

Apache Tomcat versions 11.0.20 through 11.0.24, 10.1.53 through 10.1.57, and 9.0.115 through 9.0.120 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-65183 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0014

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, and 9.0.42 through 9.0.120 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-65182 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0012

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.0 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-63076 OpenSSL Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0008

OpenSSL versions 4.0, 3.6, 3.5, 3.4, and 3.0 are susceptible to a vulnerability which when successfully exploited could allow a remote, unauthenticated attacker to crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service (DoS).

Open source
Advisory

CVE-2026-63075 OpenSSL Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0007

OpenSSL versions 4.0, 3.6, 3.5, and 3.4 are susceptible to a vulnerability which when successfully exploited could allow a remote peer that can complete a QUIC handshake to cause connection-scoped memory growth which may lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-63074 OpenSSL Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0009

OpenSSL versions 4.0, 3.6, 3.5, 3.4, and 3.0 are susceptible to a vulnerability which when successfully exploited could lead to users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process observing unbounded memory growth in the event that a malicious client repeatedly sends requests containing unique extra certificates, potentially leading to OOM conditions.

Open source
Advisory

CVE-2026-63073 OpenSSL Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0001

OpenSSL versions 4.0, 3.6, 3.5, and 3.4 are susceptible to a vulnerability which when successfully exploited could allow a malicious or intercepted CMP endpoint to crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender.

Open source
Advisory

CVE-2026-63072 OpenSSL Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0006

OpenSSL versions 4.0, 3.6, 3.5, 3.4, 3.0, and 1.1.1 are susceptible to a vulnerability which when successfully exploited could allow an attacker who supplies a crafted CMS message to trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service (DoS).

Open source
Advisory

CVE-2026-54874 OpenSSL Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0005

OpenSSL versions 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are susceptible to a vulnerability which when successfully exploited could allow a peer to use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service (DoS).

Open source
Advisory

CVE-2026-18798 OpenSSL Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0004

OpenSSL versions 4.0, 3.6, and 3.5 are susceptible to a vulnerability which when successfully exploited could lead to a double free resulting in heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service (DoS).

Open source
AI

AI demand lifts HPE and NetApp to record quarters, but investors sell both

Source: https://news.google.com/rss/articles/CBMiqgFBVV95cUxPTDh5RTdlaTFjWjR3czQtWXA3N0JTQjdWYzFYenRfeGNLb21lbWNQNXR3VmhZUjRHMFA1THdHekZSbi1ycEdLTWxpR0dWNmhsVXVOWlBSSDF3T1NyMmhaU09QU3dPNmlJWHZoLWpkLW5QTXpJSHlzMGZtQi1rcU4zeEJMcHplV0JhZHlYc3ZwZFVuX0Zxd1o3clNKbkRiVlBBSENTclR6anJvQQ?oc=5

Industry coverage of NetApp's AI-driven revenue acceleration: AI workload demand lifted both NetApp and HPE to record quarters, though investors sold both names on concerns about AI capex sustainability. The pieces detail how NetApp's all-flash and object storage lines are positioned as primary data planes for enterprise AI/ML pipelines, complementing NVIDIA GPU infrastructure.

Open source
AI

2026-09-04-siliconangle-ai-demand-hpe-netapp-record-quarters

Source: https://siliconangle.com/2026/09/ai-demand-lifts-hpe-and-netapp/

SiliconANGLE (Duncan Riley), dated 2026-09-02. HPE and NetApp both beat Wall Street Q3 (HPE) / Q1 FY27 (NetApp, July-quarter-end) estimates, both raised full-year outlooks, and both saw shares fall in late trading — a sign the storage/AI-infrastructure market has priced in continued AI-led capex but is sensitive to even minor disappointment. HPE: adj EPS $1.11 (vs 93c expected), revenue $12.2B (vs $11.91B est), +34% YoY; unadjusted diluted EPS $1.06 vs 21c a year earlier. NetApp Q1 FY27 came in with ~30% YoY revenue growth to ~$2.03B and raised guidance by $650M (per the parallel biggo/Zacks call transcripts). The disconnect — record AI-storage demand vs share-price selloff — is the key macro story for the quarter and suggests the AI-storage trade may be more about consistency (durability of all-flash attach, AIPod/AIPod-Mini pipeline) than about upside surprises.

Open source
AI

2026-09-03-q1-2027-earnings-call-biggo

Source: https://finance.biggo.com/news/NetApp-Q1-2027-Earnings-Call

Biggo Finance recap of NetApp's Q1 FY2027 earnings call: $2.03B revenue (+30% YoY), $650M raise to FY27 guidance, framed as AI-driven storage demand accelerating. Synthesizes the prepared remarks and analyst Q&A with focus on all-flash attach rate, AI-related bookings, and the DataPelago acquisition's role in GPU-accelerated data prep for AI pipelines. Useful secondary source that complements the official transcript and the SiliconANGLE/Investing.com coverage already gathered.

Open source
AI

2026-09-03-netapp-q1-fy27-slides-strong-ai-demand-investing-com

Source: https://news.google.com/rss/articles/CBMiwgFBVV95cUxQVkhJbFIwTkZJRzBTQTYxVUFlVFNDTzhIVjlsb2F3b1pKZkJwV2p4RXJCdjdWZFMzeEJRZ2hkUFZVQ

Investing.com recap of NetApp's Q1 FY2027 earnings slide deck. Slides highlight AI-related workload bookings, all-flash flash mix, AIPod traction, DataPelago integration timeline, and FY27 guidance range. Despite the strong AI narrative and revenue beat, shares sold off — likely on guidance conservatism versus elevated Wall Street expectations. Useful for tracking concrete AI-storage KPIs NetApp is willing to put on a slide.

Open source
AI

2026-09-03-netapp-q1-2027-earnings-revenue-surges-30-raises-guidance

Source: https://news.google.com/rss/articles/CBMiXkFVX3lxTE5BX1lobmRRYXdsczRJQVVRRHdHOGVVRi0tc0RmZGRvaWRhRDE2SkxzUFVEekJUNXoxOHdxWVQya1FFa

Topline summary of NetApp's Q1 FY2027 earnings call: revenue surged 30% to $2.03B, beating consensus, and FY27 guidance was raised. AI-storage demand and the DataPelago acquisition are cited as primary growth drivers, alongside strong all-flash adoption (AFF and ASA). Useful as a single-source recap of NetApp's AI positioning and forward outlook entering late FY27.

Open source
News

2026-09-03-netapp-ontap-vmware-cloud-foundation-9-1-portal-erp

Source: https://portalerp.com/article/netapp-ontap-adds-validated-storage-support-for-vmware-cloud-foundation-9-1

Coverage of NetApp announcing validated storage configurations for VMware Cloud Foundation (VCF) 9.1, the latest release from VMware by Broadcom. Confirms ONTAP as a vVols/NVMe/TCP primary backing for VCF 9.1 workloads, with reference designs covering AFF A-series, AFF C-series, and ONTAP Select deployments running under VCF's automated deployment framework. Important for storage/VM admins running VVF/VCF on legacy 7-Mode or ONTAP 9.10–9.12 deployments who need a clear upgrade path that preserves VM storage policy automation.

Open source
News

2026-09-03-netapp-helps-customers-accelerate-vmware-cloud-foundation

Source: https://news.google.com/rss/articles/CBMi7gFBVV95cUxQRV9Nb1RleXUyNFpadkFWVXBOOERVNEtBNmVZNFdyZzVCXzk0V0J6YTNOVWpWMjJHb1JBa254X2toc

NetApp announcement from the ONTAP Google News RSS feed covering NetApp's collaboration with VMware/Broadcom to help customers adopt the latest VMware Cloud Foundation (VCF) innovations. Highlights ONTAP for VMware vSphere integration, including ONTAP Tools for VMware 10.x, vVols, NVMe/TCP, and SnapMirror-based disaster recovery for VM workloads. Useful for storage admins running VMware VCF on NetApp AFF/AFF-C/ONTAP Select who need to understand the validated configurations and toolchain alignment as VCF evolves.

Open source
News

2026-09-03-earnings-call-transcript-netapp-beats-q1-2026-investing-com

Source: https://news.google.com/rss/articles/CBMizAFBVV95cUxNY2VsdzJCNmxQVkxfellTTm15WE9zX0podXZXbWF2eTMzRFR1ZzZCUjgzSDVrbFNDY19aRnd6dkVtU

Earnings call transcript for NetApp Q1 FY2027 (reported 2026-09-02). Investing.com covers NetApp beating analyst estimates on revenue and EPS while the stock dipped on guidance — the transcript includes prepared remarks from CEO George Kurian and CFO Mike Berry on AI-driven demand, all-flash mix shift, DataPelago integration, and FY27 outlook. Useful for tracking storage-market color and recurring vs. product mix trends that affect NetApp buyer behavior.

Open source
AI

2026-09-03-ai-demand-lifts-hpe-netapp-record-quarters-siliconangle

Source: https://news.google.com/rss/articles/CBMiqgFBVV95cUxPTDh5RTdlaTFjWjR3czQtWXA3N0JTQjdWYzFYenRfeGNLb21lbWNQNXR3VmhZUjRHMFA1THdHekZSb

SiliconANGLE coverage of NetApp's record Q1 FY2027 revenue ($2.03B, +30% YoY) driven by AI-driven storage demand, alongside HPE's strong quarter — both stocks sold off despite the beat. Frames NetApp's AI story in terms of all-flash attach, AIPod/AIPod Mini deployments, DataPelago acquisition for GPU-accelerated data prep, and the recurring-revenue mix shift. Useful for tracking how the market is pricing AI-storage tailwinds versus near-term enterprise capex caution.

Open source
Community

2026-09-02-visibility-of-volumes-from-google-netapp-in-netapp-console

Source: https://community.netapp.com/community/discussion/468355/visibility-of-volumes-from-google-netapp-in-netapp-console

I have Netapp Console configure and can see my on-prem Netapp volumes fine. I have a google agent configured and it shows an icon of how much data there is in Google and how many volumes there are, but in the console, Im not able to see the volumes, is this expected? TIA, Todd

Open source
Community

2026-09-02-rethinking-on-premises-storage-management-at-scale

Source: https://community.netapp.com/community/discussion/468359/rethinking-on-premises-storage-management-at-scale

An application owner pings Anna on Teams: "We need 500 GB for a new service, today, if possible." She knows the drill. She opens NetApp® ONTAP® System Manager on the target cluster to check aggregates, Active IQ Unified Manager to see whether anything is already alerting on that system, and NetApp Digital Advisor® to confirm capacity trends look healthy, each tool doing exactly what it was built to do. The provisioning itself takes minutes.

Open source
Community

2026-09-02-ontap-simulate-download-page-broken

Source: https://community.netapp.com/community/discussion/468360/ontap-simulate-download-page-broken

Hi there, Apologies if this isn't the correct place to post this, however the ONTAP Simulate download page fails to provide a download link. Is there something I could be doing wrong?

Open source
Docs

2026-09-02-ontap-s3-bucket-policy

Source: https://docs.netapp.com/us-en/ontap/s3-config/create-bucket-policy-task.html

Step-by-step procedure for writing a JSON access policy on an ONTAP S3 bucket, including Allow/Deny statements on s3:GetObject, s3:PutObject, s3:ListBucket, and principal/user conditions. The reference is the operational foundation for multi-tenant object storage on ONTAP 9.x: required reading for any ONTAP S3 deployment, especially when isolating tenant data inside a single SVM.

Open source
Docs

2026-09-02-ontap-manage-iscsi-san-initiators

Source: https://docs.netapp.com/us-en/ontap/san-admin/manage-iscsi-san-initiators-task.html

How-to for adding, removing, and viewing iSCSI initiators on an ONTAP SVM using System Manager or the ONTAP CLI (vserver iscsi initiator add/remove/show). Covers initiator naming conventions (IQN), group/portal binding, and per-LUN masking. Essential reference for SAN administrators who script LUN access or troubleshoot connectivity from Linux/ESXi hosts. Applies to ONTAP 9.x and ASA systems.

Open source
Docs

2026-09-02-ontap-fpolicy-event-config-plan

Source: https://docs.netapp.com/us-en/ontap/nas-audit/plan-file-fpolicy-event-config-concept.html

Conceptual reference covering how to plan FPolicy events in ONTAP: file-operation filtering (create, read, write, rename, delete, setattr), volume scope, persistent vs. non-persistent notifications, and the engine/protocol pairing. FPolicy is the NAS-native file-auditing/quotas-blocker; this page is the design pre-requisite for any FPolicy implementation that uses either the native or an external FPolicy server.

Open source
Docs

2026-09-02-ontap-fpolicy-create-policy

Source: https://docs.netapp.com/us-en/ontap/nas-audit/create-fpolicy-policy-task.html

How-to for assembling an FPolicy policy from its components (event, engine, scope, policy), enabling it on an SVM, and verifying status. The article is the canonical operational reference for `vserver fpolicy policy create` and its required parameters. Required reading whenever an enterprise deploys ONTAP-native file auditing, ransomware detection, or data-loss-prevention workflows.

Open source
Community

2026-09-02-ontap-base-immutabilty-features

Source: https://community.netapp.com/community/discussion/468362/ontap-base-immutabilty-features

All, Does the standard ONTAP base (FAS2820) include any immutability feature by default, or do I need ONTAP ONE to get WORM functionality and SnapLock licensed and enabled to ensure immutability? TIA.

Open source
Community

2026-09-02-netapp-ontap-powershell-toolkit-installation-error-version-9-19-1-260

Source: https://community.netapp.com/community/discussion/468356/netapp-ontap-powershell-toolkit-installation-error-version-9-19-1-2608

I got the below error while running the .\Install.ps1 Any ideas how to fix this?tia#—————————————————————————————————————————————- Output running PWSH 7 as Admin PS E:\Library\Tech Vendors\NetApp\powershell.ontap\NetApp.ONTAP\NetApp.ONTAP .\Install.ps1 NetApp ONTAP PowerShell Toolkit Installer Running on: Windows (PowerShell 7.6.

Open source
News

2026-09-02-netapp-ntap-could-be-2-undervalued-following-this-week-s-earnings-report-simplywall

Source: https://news.google.com/rss/articles/CBMivgFBVV95cUxPdkU0dEZjMVdFOENtUV9nRFBjQXc2eGhSWEFNYlk0M3BjQ3dJUVROQ3A1LVkydlNYZm52QWpCNng0a

simplywall.st article from the NetApp earnings Google News RSS feed. NetApp (NTAP) Could Be 2% Undervalued Following This Week's Earnings Report. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
AI

2026-09-02-netapp-earnings-today-ai-momentum-meets-high-expectations-investing-com

Source: https://news.google.com/rss/articles/CBMiugFBVV95cUxQRzJlcUtySVRvaGtYME40UE14aFF6ek1nOS1oNnRFSWRsMFhFOXFxaWVhSFZYbzBBTnNiZjZaNHFCQ

Investing.com article from the NetApp earnings Google News RSS feed. NetApp earnings today: AI momentum meets high expectations. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-netapp-earnings-today-ai-momentum-meets-high-expectations-by-investing-com-investing-com

Source: https://news.google.com/rss/articles/CBMiugFBVV95cUxNVWc3VllyZzlKTkstYTh4ZjVCVlJjWWszTVJBX19ub3luMmplMzlsRDc1dWF0VXpXcDA4OXBrc1pFV

Investing.com Canada article from the NetApp AI Google News RSS feed. NetApp earnings today: AI momentum meets high expectations By Investing.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Community

2026-09-02-netapp-console-autonomous-operations-from-managing-infrastructure-to-

Source: https://community.netapp.com/community/discussion/468345/netapp-console-autonomous-operations-from-managing-infrastructure-to-declaring-outcomes

Hybrid multicloud operations have reached an inflection point. For years, infrastructure teams have worked across disconnected tools, fragmented management planes, and environment-specific workflows to keep storage estates running. That model worked when estates were smaller, more centralized, and easier to reason about manually. But today, many organizations are operating dozens, or even hundreds, of clusters across on-premises environments, public clouds, sovereign clouds, and edge locations. At that scale, the operational unit is no longer the individual cluster.

Open source
News

2026-09-02-how-to-earn-500-a-month-from-netapp-stock-ahead-of-q1-earnings-benzinga

Source: https://news.google.com/rss/articles/CBMixAFBVV95cUxPSnJqRzl0aEVFUmVvRDhGckg4MUo4S0JhTk9LOXA2OHdxUFNINU04bzllSFhFNFpUUklCQk96TDAtT

Benzinga article from the NetApp earnings Google News RSS feed. How To Earn $500 A Month From NetApp Stock Ahead Of Q1 Earnings. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
Community

2026-09-02-flex-unified-comes-to-google-cluster-toolkit

Source: https://community.netapp.com/community/discussion/468354/flex-unified-comes-to-google-cluster-toolkit

Google Cloud NetApp Volumes Flex Unified is now a first-class citizen in the Google Cluster Toolkit . Starting with release v1.102.0 , the netapp-storage-pool and netapp-volume modules provision Flex Unified pools and volumes directly from a blueprint, including zonal and regional pools, large capacity (scale-out) pools, custom performance, and auto-tiering.

Open source
Community

2026-09-02-dro-snapshots-created-by-shift-toolkit

Source: https://community.netapp.com/community/discussion/468357/dro-snapshots-created-by-shift-toolkit

Hello, We are using the NetApp Shift Toolkit as part of a VM migration project (from VMware to Proxmox). I noticed that there are several “DRO” (Disaster Recovery Orchestrator) snapshots on the volumes. From my understanding, these are related to the Shift Toolkit, which creates a volume snapshot before converting the disks. It then creates a clone (FlexClone) to convert the disk format from .vmdk to .qcow2, without modifying the original virtual machine. These snapshots are consuming a significant amount of storage space (more than 18 TB! on flash array for few tests).

Open source
Community

2026-09-02-check-out-the-new-blogs-and-post-on-console-autonomous-operations

Source: https://community.netapp.com/community/discussion/468361/check-out-the-new-blogs-and-post-on-console-autonomous-operations

Console Autonomous Operations (LinkedIn) Embrace autonomous operations for hybrid multicloud | NetApp Blog NetApp Console Autonomous Operations: From Managing Infrastructure to Declaring Outcomes Rethinking On-premises Storage Management at Scale - NetApp Community

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-75803-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0002

CVE-2026-75803 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-75803. OpenSSL versions 4.0, 3.6, 3.5, 3.4, and 3.0 are susceptible to a vulnerability which when successfully exploited could lead to applications calling EVP_Cipher() accepting forged messages.

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-73180-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0020

CVE-2026-73180 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-73180. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.43 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-68763-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0019

CVE-2026-68763 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-68763. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.39 through 9.0.120, and 8.5.59 through 8.5.100 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-68569-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0016

CVE-2026-68569 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-68569. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.0 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-68525-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0013

CVE-2026-68525 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-68525. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.0 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-66422-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0015

CVE-2026-66422 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-66422. Apache Tomcat versions 1.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.25 through 9.0.120, 8.5.46 through 8.5.100 (EOL), and 7.0.97 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-66299-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0018

CVE-2026-66299 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-66299. Apache Tomcat versions 11.0.0-M20 through 11.0.24, 10.1.24 through 10.1.57, and 9.0.89 through 9.0.120 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-65927-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0017

CVE-2026-65927 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-65927. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, and 9.0.0.M1 through 9.0.120 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-65905-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0011

CVE-2026-65905 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-65905. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.30 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-65637-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0010

CVE-2026-65637 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-65637. Apache Tomcat versions 11.0.20 through 11.0.24, 10.1.53 through 10.1.57, and 9.0.115 through 9.0.120 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-65183-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0014

CVE-2026-65183 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-65183. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, and 9.0.42 through 9.0.120 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-65182-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0012

CVE-2026-65182 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-65182. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.0 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-63076-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0008

CVE-2026-63076 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-63076. OpenSSL versions 4.0, 3.6, 3.5, 3.4, and 3.0 are susceptible to a vulnerability which when successfully exploited could allow a remote, unauthenticated attacker to crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-63075-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0007

CVE-2026-63075 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-63075. OpenSSL versions 4.0, 3.6, 3.5, and 3.4 are susceptible to a vulnerability which when successfully exploited could allow a remote peer that can complete a QUIC handshake to cause connection-scoped memory growth which may lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-63074-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0009

CVE-2026-63074 OpenSSL Vulnerability in NetApp Products. Affected: NetApp HCI Baseboard Management Controller (BMC) - H610S. CVEs: CVE-2026-63074. OpenSSL versions 4.0, 3.6, 3.5, 3.4, and 3.0 are susceptible to a vulnerability which when successfully exploited could lead to users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process observing unbounded memory growth in the event that a malicious client repeatedly sends requests containing unique extra certificates, potentially leading to OOM conditions.

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-63073-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0001

CVE-2026-63073 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-63073. OpenSSL versions 4.0, 3.6, 3.5, and 3.4 are susceptible to a vulnerability which when successfully exploited could allow a malicious or intercepted CMP endpoint to crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender.

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-63072-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0006

CVE-2026-63072 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-63072. OpenSSL versions 4.0, 3.6, 3.5, 3.4, 3.0, and 1.1.1 are susceptible to a vulnerability which when successfully exploited could allow an attacker who supplies a crafted CMS message to trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-54874-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0005

CVE-2026-54874 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54874. OpenSSL versions 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are susceptible to a vulnerability which when successfully exploited could allow a peer to use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-18798-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0004

CVE-2026-18798 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-18798. OpenSSL versions 4.0, 3.6, and 3.5 are susceptible to a vulnerability which when successfully exploited could lead to a double free resulting in heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-14457-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0003

CVE-2026-14457 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-14457. OpenSSL versions 4.0, 3.6, 3.5, and 3.4 are susceptible to a vulnerability which when successfully exploited could cause an application abort leading to a Denial of Service (DoS).

Open source
Community

2026-09-02-100-cpu-utilization-on-a30

Source: https://community.netapp.com/community/discussion/468350/100-cpu-utilization-on-a30

When looking at a system node run -command sysstat -m I get half of the cpus as pegged at 100%: ntap01:: system node run -node ntap01-01 -command sysstat -mANY AVG CPU0 CPU1 CPU2 CPU3 CPU4 CPU5 CPU6 CPU7 CPU8 CPU9 CPU10 CPU11 CPU12 CPU13 CPU14 CPU15 CPU16 CPU17 CPU18 CPU19 CPU20 CPU21 CPU22 CPU23 CPU24 CPU25 CPU26 CPU27 CPU28 CPU29 CPU30 CPU31 &#13; 99% 28% 27% 100% 13% 100% 12% 100% 25% 100% 14% 100% 15% 100% 22% 100% 13% 100% 14% 100% 18% 100% 21% 100% 11% 100% 12% 100% 76% 100% 76% 100% 76% 100% &#13; 99% 25% 23% 100% 10% 100% 9% 100% 18% 100% 11% 100% 12% 100% 18% 100% 12% 100% 11% 100% 15.

Open source
Docs

Protect ONTAP consistency groups

Source: https://docs.netapp.com/us-en/ontap/consistency-groups/protect-task.html

Creating a consistency group does not automatically enable protection. Protection policies can be set at the time of creation or after creating your consistency group. You can protect consistency groups using: SnapMirror active sync (referred to as SnapMirror Business Continuity in versions of ONTAP before 9.15.1) If you are utilizing nested consistency groups, you can set different protection policies for the parent and child consistency groups. Beginning with ONTAP 9.11.1, consistency groups offer two-phase consistency group snapshot creation . The two-phase snapshot operation executes a pre-check, ensuring the snapshot is captured successfully.

Open source
Docs

ONTAP S3 architecture using FlexGroup volumes

Source: https://docs.netapp.com/us-en/ontap/s3-config/architecture.html

Access to the bucket is provided through authorized users and client applications. When a bucket is used exclusively for S3 applications, including use as a FabricPool endpoint, the underlying FlexGroup volume will only support the S3 protocol. Beginning with ONTAP 9.12.1, the S3 protocol can also be enabled in multiprotocol NAS volumes that have been preconfigured to use NAS protocols. When the S3 protocol is enabled in multiprotocol NAS volumes, client applications can read and write data using NFS, SMB, and S3. Minimum bucket capacity is determined by the ONTAP platform.

Open source
Docs

Learn about NFS over RDMA in ONTAP

Source: https://docs.netapp.com/us-en/ontap/nfs-rdma/index.html

Official ONTAP docs index page for NFS over RDMA (Remote Direct Memory Access). Covers the protocol overview, why RDMA lowers latency for AI/HPC workloads, supported hardware (RoCE-capable NICs), supported ONTAP versions, and configuration entry points. Useful as the canonical reference when sizing RDMA-capable NFS exports and pairing with NFS clients that support NFSoRDMA (Linux kernel client + MellusX/RXE software emulation where supported).

Open source
Docs

Configure external directory services for ONTAP S3 access

Source: https://docs.netapp.com/us-en/ontap/s3-config/configure-access-ldap.html

You can provide user groups belonging to an external directory service with access to your ONTAP object storage environment. Lightweight Directory Access Protocol (LDAP) is an interface for communicating with directory services, such as Active Directory, that provide a database and services for identity and access management (IAM). To provide access, you need to configure LDAP groups in your ONTAP S3 environment. After you have configured access, the group members have permissions to ONTAP S3 buckets. For information about LDAP, see Learn about using LDAP name services on ONTAP NFS SVMs . You can also configure Active Directory user groups for fast bind mode, so that user credentials can be validated and third-party and open-source S3 applications can be authenticated over LDAP connections. Ensure the following before configuring LDAP groups and enabling the fast bind mode for group access: An S3-enabled storage VM containing an S3 server has been created. See Create an SVM for S3 .

Open source
Docs

Configure a hierarchical ONTAP consistency group

Source: https://docs.netapp.com/us-en/ontap/consistency-groups/configure-hierarchy-task.html

Hierarchical consistency groups have a parent that can include up to five individual consistency groups. Hierarchical consistency groups can support different local snapshot policies across consistency groups or individual volumes. If you use a remote protection policy, that will apply for the entire hierarchical consistency group (parent and children). Beginning with ONTAP 9.13.1, you can modify the geometry of your consistency groups and move volumes between child consistency groups . For object limits on consistency groups, see Object limits for consistency groups . When creating a hierarchical consistency group, you can populate it with new LUNs. Beginning with ONTAP 9.13.1, you can also use new NVMe namespaces and NAS volumes.

Open source
Docs

Configure LIFs for NFS over RDMA

Source: https://docs.netapp.com/us-en/ontap/nfs-rdma/configure-lifs-task.html

You must be running ONTAP 9.12.1 or later to create a network interface for NFS over RDMA with System Manager. When you select NFS,SMB/CIFS,S3 , you have the option to Use RoCE ports . Select the checkbox for Use RoCE ports . Select the storage VM and home node. Assign a Name , IP address , and Subnet mask . Once you enter the IP address and subnet mask, System Manager filters the list of broadcast domains to those that have RoCE capable ports. Select a broadcast domain. You can optionally add a gateway.

Open source
Docs

Configure Cisco Duo 2FA for ONTAP SSH logins

Source: https://docs.netapp.com/us-en/ontap/authentication/configure-cisco-duo-mfa-task.html

If you enable Duo authentication for SSH logins, users will need to enroll a device the next time they log in using SSH. For enrollment information, refer to the Cisco Duo enrollment documentation . You can use the ONTAP command line interface to perform the following tasks with Cisco Duo: You can create a Cisco Duo configuration for either the entire cluster or for a specific storage VM (referred to as a vserver in the ONTAP CLI) using the security login duo create command. When you do this, Cisco Duo is enabled for SSH logins for this cluster or storage VM. Learn more about security login duo create in the ONTAP command reference . Enable Cisco Duo authentication for this storage VM, substituting information from your environment for the values in brackets:

Open source
Docs

Clone an ONTAP consistency group

Source: https://docs.netapp.com/us-en/ontap/consistency-groups/clone-task.html

When cloning a consistency group, you can clone it with its current configuration, but with volume contents as they are or based on an existing consistency group snapshot. Cloning a consistency group is supported only for the entire consistency group. You cannot clone an individual child consistency group in a hierarchical relationship: only the complete consistency group configuration can be cloned. When you clone a consistency group, the following components are not cloned: When you clone a consistency group, ONTAP will not create SMB shares for the cloned volumes if a share name is not specified. * Cloned consistency groups are not mounted if a junction path is not specified.

Open source
Docs

Change an ONTAP administrator password

Source: https://docs.netapp.com/us-en/ontap/authentication/change-login-password-task.html

You must be a cluster or SVM administrator to change your own password. You must be a cluster administrator to change another administrator's password. Change an administrator password: security login password -vserver svm_name -username user_name The following command changes the password of the administrator admin1 for the SVM vs1.example.com . You are prompted to enter the current password, then enter and reenter the new password.

Open source
Docs

Azure NetApp Files application volume group is now GA for SAP HANA

Source: NetApp video / product page (https://www.netapp.com/video/cgsqqqxcco8/azure-netapp-files-application-volume-group/)

Microsoft and NetApp have promoted the Azure NetApp Files (ANF) **application volume group** feature to general availability, and NetApp has documented it as the standard provisioning method for SAP HANA volumes on ANF. The feature replaces the per-volume manual placement that used to require Azure-team intervention for HANA-sized workloads.

Open source
Docs

Assess ONTAP S3 physical storage requirements

Source: https://docs.netapp.com/us-en/ontap/s3-config/assess-physical-storage-requirements-task.html

When you create an S3 bucket in an S3-enabled SVM, a FlexGroup volume is automatically created to support the bucket. You can let ONTAP select the underlying aggregates and FlexGroup components automatically (the default) or you can select the underlying aggregates and FlexGroup components yourself. If you decide to specify the aggregates and FlexGroup components — for example, if you have specific performance requirements for the underlying disks — you should make sure that your aggregate configuration conforms to best practice guidelines for provisioning a FlexGroup volume. Learn more: NetApp Technical Report 4571-a: NetApp ONTAP FlexGroup Volume Top Best Practices If you are serving buckets from Cloud Volumes ONTAP, it is strongly recommended that you manually select the underlying aggregates to ensure that they are using one node only. Using aggregates from both nodes can impact performance, because the nodes will be in geographically separated availability zones and hence susceptible to latency issues. Learn about creating buckets for Cloud Volumes ONTAP .

Open source
Docs

Add or remove volumes to an ONTAP consistency group

Source: https://docs.netapp.com/us-en/ontap/snapmirror-active-sync/add-remove-consistency-group-task.html

In most instances, this is a disruptive process requiring you to delete the SnapMirror relationship, modify the consistency group, then resume protection. Beginning with ONTAP 9.13.1, adding volumes to a consistency group with an active SnapMirror relationship is a non-disruptive operation. In ONTAP 9.9.1, you can add or remove volumes to a consistency group using the ONTAP CLI. Beginning with ONTAP 9.10.1, it is recommended that you manage consistency groups through System Manager or with the ONTAP REST API. If you want to change the composition of the consistency group by adding or removing a volume, you must first delete the original relationship and then create the consistency group again with the new composition.

Open source
News

2026-09-02-netapp-earnings-what-to-look-for-from-ntap-yahoo-finance

Source: https://news.google.com/rss/articles/CBMilAFBVV95cUxPdzJETFFuS0N1ZFRPTFlLT0tkUnZlaHlGTW11djl0czR0WVR6dEpBVkgxNHExNTE2WUwtaVBCTjdHW

Yahoo Finance article from the NetApp earnings Google News RSS feed. NetApp Earnings: What To Look For From NTAP. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
News

2026-09-02-netapp-earnings-what-to-look-for-from-ntap-tradingview-com

Source: https://news.google.com/rss/articles/CBMipgFBVV95cUxOdXBOVWlOYVZLX1RkdU1sbjBaVkJmc0hNaWJJSUFTRjhDMEt4enpnQWwwN3ZvMzQ0NjctM0UtREVHS

tradingview.com article from the NetApp earnings Google News RSS feed. NetApp Earnings: What To Look For From NTAP. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
AI

2026-09-02-netapp-earnings-what-to-look-for-from-ntap-the-chronicle-journal

Source: https://news.google.com/rss/articles/CBMiwAFBVV95cUxQR1h2QTBmVmgtSmtfUVlxaGczbGlFdXpGb0JNNVQ0UjVaMnVhX05NaEo2N04xUS1Lc1ljR3czanpjdktNUmFKRS11eHdDT0x4Tm5hX29IRmlvOFNIUTdXZDRqYzlROTlDb1RDMFNNZ3ZZWkk5emoxNi1RS1o0MDlBWUJ1N042OXpZeWpmYVZjamxuWUM3RXY4LUpnNXE3SFNtZzEyaExsUXFSdFlOa05VRGlpcENIMEJJWUJadVN5eEw?oc=5

The Chronicle-Journal article from the NetApp NVIDIA Google News RSS feed. NetApp Earnings: What To Look For From NTAP - The Chronicle-Journal. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
News

2026-09-02-netapp-earnings-what-to-look-for-from-ntap-barchart-com

Source: https://news.google.com/rss/articles/CBMijwFBVV95cUxNZFJuam5XWDA3Y21UVFJjbWhZVlFrTXVLU2NYLWJFZWlpMXhnUFRDbXhCYnNRWC1xSjFtQlkxT3lFc

Barchart.com article from the NetApp earnings Google News RSS feed. NetApp Earnings: What To Look For From NTAP. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
Community

2026-09-02-internal-job-switch-r-netapp

Source: https://www.reddit.com/r/netapp/comments/1w4ivfj/internal_job_switch/

Reddit r/netapp discussion thread. Internal Job Switch. Auto-aggregated from public community sources. Refer to publisher for full content. Categorized as `community` for the NetApp Black Box library.

Open source
News

2026-09-02-double-the-density-half-the-cost-amazon-fsx-for-netapp-ontap-and-amazon-elastic-

Source: https://news.google.com/rss/articles/CBMiX0FVX3lxTE9zVkkzckVzNDkwRFhHMkx6NHNZUW5ER0MtQnVVYi1qQll3VG9wQkp2UGNTVEdUNjMxNEdRVDRzNXR3dXQzVUZ4THRhZDByNEp5X2hWOENhZGtSa1hPWkhN?oc=5

VMware article from the NetApp ONTAP Google News RSS feed. Double the density, half the cost: Amazon FSx for NetApp ONTAP and Amazon Elastic VMware Service (EVS) - VMware. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
News

2026-09-01-s-p-global-s-innovative-disaster-recovery-strategy-using-ama

Source: https://news.google.com/rss/articles/CBMi0AFBVV95cUxQczY4QnBVbHRGd1BRWVcyZUZvdnVGOXNnTkFZQWtFeC1HNVc1c2Y3LTNEVTlpdk1HYm5oRDJ0dlFCTUtoNlpWMWZCbW90cmxSQWJPQnFBQ25JLVRQaW02NldiMWVFN25mSjJHbkRvYW92LXJvS3ZvUXhxQjVPcHlqcEhYVjB0ZTdBb3NHdWZpUElKWl9odzVPZW9zTmRfOWJDUGhSb1B1UGxIVU5PTEEwb1N4SmFWVUZrR3FWaFYyNVNKOVV0UlJkUk4wVlFaVVpa?oc=5

NetApp-related news article collected from Google News / Reddit / RSS feeds.

Open source
News

2026-09-01-ontap-storage-os-connect-your-core-to-the-cloud-netapp

Source: https://news.google.com/rss/articles/CBMikwFBVV95cUxPMkVfWU1tUmhEdnAxSHdWcDRiR0FtQktISnVqVTZrMlFMSTZmRFltYzN1UWRnaEtUOWN4Sk9EdjZNVkVnNmt5YzhGYXBSTmZmYzBTU2psNHJ6WjhZQkpqX0lMMGtNZldSSklyRlVyRnhhSXhmVEY1REpicWwzMzdsTGJFTDNXd3EyX1BiQUJlbUx6NTg?oc=5

NetApp-related news article collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-01-netapp-sees-strong-storage-demand-with-ai-related-tailwinds

Source: https://news.google.com/rss/articles/CBMizgFBVV95cUxNWVo2T2ZIWWYtY19vNllsdFpvQ3BnVFlDdVpnampEaVA1dzdiZUVjemdZdmhNcmlPS0dqZUhBNExCNnZHREdLbm55ckFRSl9feWlVQjdRdjBaQ1ZaYzRZOGtJR1k0M0lweHZ4WXJSZlVxMGlLdDhxRmM0cGtMT21waHJQTkRlRS14eFZUVUxiMmZrUEhqd2xWdEtLcDZwNk9wUDZjd2RlUnpwalpiVnBwcDVsZElJR2NTNGVicXk5SFI1SHlQVEdlam9idFRyZw?oc=5

NetApp-related ai article collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-01-netapp-platform-unveils-ai-ready-data-unified-storage-proact

Source: https://news.google.com/rss/articles/CBMi4gFBVV95cUxNTXNtMmg2TC1ScC1Wc2dYNFVORFlzNTlsQWY4eG5tUE5DeUxRX3dVSW5scFVqb05naXZKRTYxdENCemJaX0lvZHE0VEpNOGNLMHg4bTQ3cnFlQXdGQmFkaFdyeFB2eENJYkk1WXRtY1N4d2NkcjktNTdvT2Yzb0k1NmxQQlhMWWxHeF9IZWJ5ZUJvZE5iR3ZkZklmbFdIWExFOGdvckgyTzIwcy1fdmJndWFaRHhJQzlVVnBPc2NFLWVacXMwRkdrVkdlVDg5V19xeGpOSWJ0QzJMTm9qM1lGUkpB?oc=5

NetApp-related ai article collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-01-netapp-boosts-enterprise-data-security-and-ai-protection-at

Source: https://news.google.com/rss/articles/CBMimwFBVV95cUxPaUdDN2h0eW83MkNMTWtUallHZDlOVkpWZ28tVUZ5Y1haeHFVQWdLeTRMdG9rWHA3S0pBQzFDdjZrSGVZcUdRR1BORzdYcm9ma0ppalBFa1JLVGhoamc3UTh4amtJeVBXQkU3QUl5QUJWa1F6SVMydkxON3pVT21pNkhYdW5IclFqOG03WEcyVTRFVVdOa1dGcW9SSQ?oc=5

NetApp-related ai article collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-01-jensen-huang-george-kurian-nvidia-netapp-revolutionary-ai-pr

Source: https://news.google.com/rss/articles/CBMirAFBVV95cUxQUTlwdDBFNUh2ZVdZRngtX1F3b3h2WXVyMWU2aFljVEF2WVo3ampjVUwzcnFEY3BDZnBQY0hUYTI2c0FSdmdVVmxZV05laEQyVWVOMDZ0aGdSUVpSUnV3N0gyamdxX2c4TFhjMW5sSV9YZU16MGk0NUgxMDF4TTY3aFFvcEhXRmM1NDdlVllhaTJPTWVGc3huRGlia29pT0UtUy1UWGR0Wk9XNGlZ?oc=5

NetApp-related ai article collected from Google News / Reddit / RSS feeds.

Open source
News

2026-09-01-integrating-amazon-fsx-for-netapp-ontap-and-amazon-fsx-for-w

Source: https://news.google.com/rss/articles/CBMi1wFBVV95cUxOY3p4SG1Zdko0RjBWWjJHaHctRUtTVGVHZWZQdGJkVjV0NF82cDRyQW8zZlk3UnZnM2VIUUJNWnV3THQyZm9rSnRBTzdLZ0l0QmRWYTJWZ1lUcXdnNU93Qll1YlNwcmdxSGY1U1ZrbkV2WGV3NnBVaEhUQm1JNGFraTRlOEpfZHlSS25Lck1DekNoM2poY3lwSFR2c09KRHJPVGNweGNMNjBUaFNEZl9NNU5qZXBFTFNfQlpCcDc1blE1M2hVOGgzaUsyWXR1WjFhSlkyMkU0Zw?oc=5

NetApp-related news article collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-01-how-netapp-is-simplifying-its-way-to-an-ai-powered-enterpris

Source: https://news.google.com/rss/articles/CBMisgFBVV95cUxQaE9sZVgwbnBpU0FHcERpbmhyejNEcWZKMV9ReUNxd0g2S0tQWDZ1VUxoTXgtTElaTGxia0NqOWhXN2tCRmxVdWRreVlrN2E4d1lxc2ZWblFieDRJUkpJOXZLektQYUpSV2o2NGpGeUxjcDB1YXpwQkd5ZG90UFZzUHE4eFZQMWxrVW5RU2ZHbEZhaHFycXpBSDNwRHFac2hqQVZBdU43QllETk9xY0VIcEZ3?oc=5

NetApp-related ai article collected from Google News / Reddit / RSS feeds.

Open source
AI

2026-09-01-bofa-sees-ai-driven-storage-demand-lifting-netapp-s-outlook

Source: https://news.google.com/rss/articles/CBMikAFBVV95cUxNY2ZRT0VwVWs4RmFVQk9CeDA3ZjUxR2tMQ3Y3VTktVjRVUzI1WWxwaEpBU1QzWVdBWllvZXRoOHdrMmpoNjZlMFNFbktWY2UyeVJMdWRtVWlpSHpHSkFQU3RnWFJKQ1FwQ0ZndU9FeFJUeENNZUF4eThkeE9MZEtsbFpQdTByaWNqT25ZMWdBLUQ?oc=5

NetApp-related ai article collected from Google News / Reddit / RSS feeds.

Open source
Community

Visibility of volumes from Google NetApp in NetApp Console

Source: community

User troubleshooting: Google Cloud NetApp Volumes (GCNV) agent shows an icon in NetApp Console with only data-size info, but on-prem volumes show full inventory. Discussion covers NetApp Console agent permissions, GCV volume import vs. native agent mode, and known visibility gaps for GCNV/Native Flex/Aggr-block tiers. Relevant for admins running hybrid Google Cloud + on-prem NetApp deployments.

Open source
Docs

StorageGRID 12.1 — What's new (NetApp Docs)

Source: https://docs.netapp.com/us-en/storagegrid/release-notes/whats-new.html

NetApp StorageGRID 12.1 release-notes landing page enumerating the new capabilities grouped by area. Highlights that matter operationally: access buckets across multiple StorageGRID systems for cross-grid replication; Object-Lock-enabled buckets, cross-grid replication for non-empty buckets, S3 Batch operations for pre-replicating versioning-enabled objects, and non-functional S3 REST headers + pre-calculated checksum values; **Security** brings multi-admin verification and refreshed FIPS policy updates; endpoints with mTLS; **Capacity** improves EC rebalance (now uses free space) and exposes metadata-allowed-space. Upgrade time has increased from <5 min to up to an hour for feature enablement. Reference for any 12.0.x → 12.1 upgrade or for evaluating the federated-namespace and multi-admin-verification features against regulatory/governance requirements.

Open source
Community

Snaplock and Simulator

Source: community

User running SnapLock Compliance on the ONTAP simulator runs into license/feature-pack errors configuring a SnapLock aggregate + log volume. Discussion covers the steps to enable snaplock on Sim (license add, snaplock create-volume privileged-delete) and known limits (ComplianceClock drift, no audit-log shipping). Good primer for hands-on SnapLock practice.

Open source
Docs

Provision a local tier (aggregate)

Source: docs

CLI command to create ONTAP aggregates with disk selection, RAID group layout, and cloud-tier attachment ('-cloud-tier'). Discusses mixed-Rate/RPM disks, FabricPool, and ONTAP 9.x node compatibility. Cornerstone of ONTAP storage administration.

Open source
AI

NetApp showcases AI-ready data platform and security posture at LEAP 2026 (Riyadh)

Source: INTLBM (https://intlbm.com/2026/08/31/netapp-boosts-enterprise-data-security-and-ai-protection-at-leap/)

NetApp is at LEAP 2026 in Riyadh (Aug 31 – Sep 3, RECC, Malham) with a booth pitched around the "Intelligent Data Infrastructure" narrative: keep enterprise data AI-ready AND secure across hybrid multi-cloud environments. The timing is deliberate — Saudi Arabia has designated 2026 the "Year of Artificial Intelligence", and NetApp's MEA leadership is framing the platform as the data plane underneath that national push.

Open source
News

NetApp Named Leader in 2026 Gartner Enterprise Storage MQ

Source: https://technosports.co.in/netapp-recognized-as-a-leader-in-2026/?amp=1

Independent syndication of NetApp's placement as a Leader in the 2026 Gartner Magic Quadrant for Enterprise Storage Platforms. Adds a different outlet's framing of the placement — useful for the syndication graph and to corroborate the original NetApp PR and earlier coverage from Yahoo Finance, IT Voice, NTB Kommunikasjon.

Open source
AI

NetApp CEO On Biggest AI Challenges, Investments And Partner Plans For 2026

Source: https://news.google.com/rss/articles/CBMi0AFBVV95cUxQaE9sZVgwbnBpU0FHcERpbmhyejNEcWZKMV9ReUNxd0g2S0tQWDZ1VUxoTXgtTElaTGxia0NqOWhXN2tCRmxVdWRreVlrN2E4d1lxc2ZWblFieDRJUkpJOXZLektQYUpSV2o2NGpGeUxjcDB1YXpwQkd5ZG90UFZzUHE4eFZQMWxrVW5RU2ZHbEZhaHFycXpBSDNwRHFac2hqQVZBdU43QllETk9xY0VIcEZ3

CRN interview with NetApp CEO George Kurian on the biggest AI challenges, investments, and partner plans for 2026: ONTAP positioned as the unified data layer for enterprise AI factories, AIPod Mini + Lenovo/NVIDIA partners driving turnkey hardware, and the AI Data Engine as the orchestrator for unstructured data preparation, embedding and RAG pipelines.

Open source
News

NetApp Boosts Enterprise Data Security and AI Protection at LEAP

Source: https://intlbm.com/netapp-boosts-enterprise-data-security-and-ai-protection-at-leap/

intlbm's coverage of NetApp at LEAP 2026: highlights NetApp's positioning of the platform around enterprise data security and AI protection, with explicit attention to unified governance for AI training data and proactive ransomware-style protection built into the storage layer. Pairs naturally with NetApp's own 'Empower autonomous operations' blog and the TahawulTech/Zawya syndication coverage already in the stream.

Open source
Docs

Map a LUN to an igroup

Source: docs

ONTAP SAN command that exposes a LUN to host initiator groups (igroups) by WWPN/IQN. Required for FC and iSCSI host-side LUN discovery, masking, and zoning verification. Cross-referenced by every SAN host setup doc.

Open source
Docs

Manage link costs in StorageGRID (NetApp Docs)

Source: https://docs.netapp.com/us-en/storagegrid/admin/manage-link-costs.html

StorageGRID 12.1 adds more-detailed link-cost information and settings that let operators prioritise which data-center site services a request when two or more sites exist. Link costs directly influence traffic-engineering decisions for the ADC service, load balancer placement, and object routing; mismatched costs are a common root cause of unexpected WAN egress or elevated latency between sites after topology changes. New in 12.1: explicit per-link settings and reporting that surface which sites are being preferred for which workflows, useful when validating multi-site deployments for AI factories that want to keep hot data close to GPU pools. Read alongside the StorageGRID 12.1 What's-new page and the global-namespace documentation when sizing cross-grid replication topology.

Open source
Docs

Logical storage management with the ONTAP CLI

Source: docs

Concept and CLI procedure for ONTAP volumes (FlexVol): creation, sizing, guarantees (none/file/vol), autosize, efficiency, snapshot policies, junction paths, and moving volumes across aggregates/SVMs. Updated 2026-05-04.

Open source
Docs

Learn about ONTAP data at rest encryption

Source: docs

End-to-end procedure for ONTAP NVE (NetApp Volume Encryption) with onboard/external key management (OKM / KMIP / SGX). Covers aggregate-level, volume-level, and SnapLock encryption; key-manager setup; key-transition; backup. Foundation for HIPAA/PCI/FIPS compliance.

Open source
Docs

Learn about ONTAP SnapMirror active sync

Source: docs

Bidirectional synchronous SnapMirror (SM-Business-continuity / SM-AS) for zero-RPO use cases including VMware vCenter Metro Storage Cluster, Oracle RAC, and SQL AlwaysOn. Discusses consistency-group mediation, planned/unplanned failover, ONTAP Mediator, and ONTAP 9.9.1+ availability. Updated 2026-06-17.

Open source
Docs

Learn about ONTAP SnapLock

Source: docs

Concepts and configuration for NetApp SnapLock Compliance and Enterprise WORM volumes - tamper-proof retention for regulatory workloads. Discusses 'snaplock create-volume', privileged-delete, retention periods, audit logging, and ComplianceClock. Updated 2026-06-16.

Open source
Docs

Learn about ONTAP SAN configuration

Source: docs

How to configure iSCSI, FC, FC-NVMe, and NVMe/TCP on ONTAP: SVM creation, LIFs, igroups, LUN mapping, host-side multipath, and zoning. Includes zoning best practices, switch config, and ASA/AFF build-outs. Updated 2025-03-31.

Open source
Docs

Learn about ONTAP S3 configuration

Source: docs

How to expose NetApp ONTAP as an S3 object-store endpoint without external servers: enable ONTAP S3, generate self-signed or CA-signed server certificates, create object-store SVMs/buckets, and integrate with AWS SDKs. Covers SnapMirror S3 for cross-cluster replication.

Open source
Docs

Learn about ONTAP FlexCache volumes

Source: docs

Concept and procedure doc for NetApp FlexCache - read-write caching of source volumes across clusters for WAN-distributed workloads. Covers cache creation ('volume create -volume ... -flexcache-cache-type'), origin/cache relationships, write-back semantics, and prepopulation. Updated 2026-03-19.

Open source
Docs

Learn about NFS configuration with the ONTAP CLI

Source: docs

Concepts and end-to-end procedure for delivering NFS exports from ONTAP: SVM creation, export policy + rules (vserver export-policy rule), NFSv3/NFSv4.x enablement, Kerberos, name-mapping, and client-troubleshooting flow. Updated 2025-05-30. Aligns with NCDA NFS domain.

Open source
Community

Kubernetes Meets Google Cloud NetApp Volumes ONTAP-Mode: Now Preview in Trident

Source: community

NetApp Trident 26.06.1 introduces Preview support for Google Cloud NetApp Volumes (GCNV) ONTAP-Mode (the full-ONTAP option, not just Flex). Discusses CSI driver provisioning, NFS/CSI topology constraints, snapshot/restore with TridentSnapshot, and how to migrate GKE workloads onto ONTAP-Mode. Pre-GA preview, so workflow details will evolve.

Open source
Community

Flex Unified comes to Google Cluster Toolkit

Source: community

Announcement: Google Cloud NetApp Volumes Flex Unified is now a first-class option in the Google Cluster Toolkit. With release v1.102.0, the netapp-storage-pool / GKE integration supports Flex Unified for HPC/scale-out AI workloads. Includes a usage recipe for Slurm/GKE clusters and points to docs for mounting NFS volumes from Flex Unified for parallel training jobs.

Open source
Docs

Enable NFS on an SVM

Source: docs

CLI command to enable NFS services on an SVM, configure NFSv3/NFSv4.x, Kerberos, and Windows-style name mappings. Covers -access-cache-config, -auth-sys-config, -nfsv3, -nfsv41, -root, -wdelay, -xprtsec. ONTAP 9.9.1-9.19.1.

Open source
Community

Cross-Region and Cross-Account Backup for Amazon FSx for NetApp ONTAP

Source: community

Architecture discussion: snapshots/replication vs. cross-region DR vs. cross-account backup patterns for FSx for ONTAP. Walks through account-boundary considerations, AWS Backup vault locks, FSx for ONTAP's per-AWS-account quota, and NetApp SnapMirror Cloud as an alternative. Concrete patterns for regulated workloads needing DR outside the original AWS account.

Open source
Docs

Create a logical interface

Source: docs

CLI command to provision LIFs on ONTAP SVMs across NAS/SAN/iSCSI/FC/S3 protocols. Covers role assignment (data, cluster-mgmt, node-mgmt, intercluster, backup), service policies, failover groups, and home-node/home-port selection. Documented across ONTAP 9.9.1-9.19.1.

Open source
Docs

Create a cluster

Source: docs

cluster creation CLI command for initializing a new ONTAP cluster; required before joining nodes or creating SVMs. Documents syntax (-node, -cluster-name, -cluster-username, -cluster-password, etc.), parameter reference, and bootstrap examples for single-node and multi-node setups. References ONTAP 9.9.1-9.19.1. Critical for NCDA/NCIE-SAN/NAS cluster bring-up workflows.

Open source
Docs

Create a SnapMirror relationship

Source: docs

CLI command to create ONTAP SnapMirror DR, vault (long-term retention), and DP/XDP relationships between source and destination SVMs/volume-paths. Covers schedule policies, throttle, identity-preservation, and '-type XDP' for unified SnapMirror. ONTAP 9.9.1-9.19.1; critical for disaster-recovery and data-protection exams.

Open source
News

BofA Sees AI-Driven Storage Demand Lifting NetApp Outlook

Source: https://finimize.com/content/bofa-sees-ai-driven-storage-demand-lifting-netapps-outlook

Finimize's digest of the BofA Securities note on NetApp: AI-related tailwinds visible in storage demand, supportive of an above-consensus outlook. Pairs with the marketscreener write-up of the BofA note and the original Aug 26 AI guidance coverage — together they track the AI-storage demand narrative into the Q1 earnings window.

Open source
Community

Agentic AI and NetApp

Source: community

NetApp Community discussion framing agentic AI in NetApp's product portfolio. Distinguishes marketing-defined AI agents (workflow automators with tool access) from true agentic systems (planning + memory + reasoning + execution). Useful context for evaluating NetApp AIPod, BlueXP AI/ML, AI Data Engine, and integration points where an AI agent could orchestrate ONTAP volumes/snapshots via the ONTAP REST API.

Open source
AI

2026-09-04-intlbm-leap-2026-netapp

Source: https://intlbm.com/netapp-boosts-enterprise-data-security-and-ai-protection-at-leap/

INTLBM (Aug 31, 2026): NetApp is showcasing its "Intelligent Data Infrastructure" portfolio at LEAP 2026 in Riyadh (Aug 31 – Sep 3, 2026, RECC Malham). Saudi Arabia has designated 2026 as its "Year of Artificial Intelligence," so the showcase is positioned around making enterprise data AI-ready and AI-secure across hybrid-multicloud deployments. Featured speaker: Suhail Hasanain, Senior Director and General Manager, MEA at NetApp. NetApp's pitch: the NetApp Platform provides always-AI-ready, always-secure data infrastructure for any workload across hybrid-multi-cloud environments — directly aimed at Saudi/MEA enterprises scaling AI workloads. Why it matters: regional AI infrastructure shows (LEAP, GITEX, etc.) are where hyperscaler-partner storage vendors (NetApp, Pure, Dell) make their Middle East sovereign-cloud and AI-factory announcements. LEAP 2026 is the marquee MENA AI-infrastructure event of the year, and NetApp's presence reflects where the AI-storage growth is geographically diversifying away from US/EU.

Open source
AI

2026-09-02-netapp-sees-strong-storage-demand-with-ai-related-tailwinds-bofa-securities-says

Source: https://news.google.com/rss/articles/CBMizgFBVV95cUxNWVo2T2ZIWWYtY19vNllsdFpvQ3BnVFlDdVpnampEaVA1dzdiZUVjemdZdmhNcmlPS0dqZUhBNExCNnZHREdLbm55ckFRSl9feWlVQjdRdjBaQ1ZaYzRZOGtJR1k0M0lweHZ4WXJSZlVxMGlLdDhxRmM0cGtMT21waHJQTkRlRS14eFZUVUxiMmZrUEhqd2xWdEtLcDZwNk9wUDZjd2RlUnpwalpiVnBwcDVsZElJR2NTNGVicXk5SFI1SHlQVEdlam9idFRyZw?oc=5

marketscreener.com article from the NetApp AI Google News RSS feed. NetApp Sees Strong Storage Demand With AI-Related Tailwinds, BofA Securities Says - marketscreener.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-netapp-boosts-enterprise-data-security-and-ai-protection-at-leap-intlbm

Source: https://news.google.com/rss/articles/CBMimwFBVV95cUxPaUdDN2h0eW83MkNMTWtUallHZDlOVkpWZ28tVUZ5Y1haeHFVQWdLeTRMdG9rWHA3S0pBQzFDdjZrSGVZcUdRR1BORzdYcm9ma0ppalBFa1JLVGhoamc3UTh4amtJeVBXQkU3QUl5QUJWa1F6SVMydkxON3pVT21pNkhYdW5IclFqOG03WEcyVTRFVVdOa1dGcW9SSQ?oc=5

intlbm article from the NetApp AI Google News RSS feed. NetApp Boosts Enterprise Data Security and AI Protection at LEAP - intlbm. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-bofa-sees-ai-driven-storage-demand-lifting-netapp-s-outlook-finimize

Source: https://news.google.com/rss/articles/CBMikAFBVV95cUxNY2ZRT0VwVWs4RmFVQk9CeDA3ZjUxR2tMQ3Y3VTktVjRVUzI1WWxwaEpBU1QzWVdBWllvZXRoOHdrMmpoNjZlMFNFbktWY2UyeVJMdWRtVWlpSHpHSkFQU3RnWFJKQ1FwQ0ZndU9FeFJUeENNZUF4eThkeE9MZEtsbFpQdTByaWNqT25ZMWdBLUQ?oc=5

Finimize article from the NetApp AI Google News RSS feed. BofA Sees AI-Driven Storage Demand Lifting NetApp’s Outlook - Finimize. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Community

100% CPU utilization on A30

Source: community

ONTAP A30 (AFF A30) node showing half its CPUs pegged at 100% in 'system node run -node ntap01-01 -command sysstat -m'. Discussion walks through diagnosing whether the load is wafl_exempt, nblade, or bplane, and what counter to pull (sysstat -c 50, perf-archive, wafl_iw, hya). Useful troubleshooting flow for NCDA/NCIE perf questions.

Open source
Docs

Working with local tiers in a MetroCluster configuration

Source: docs

Working with local tiers in a MetroCluster configuration — official NetApp ONTAP 9 documentation page (disks-aggregates). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Open source
Docs

SAN storage management

Source: docs

SAN storage management — official NetApp ONTAP 9 documentation page (san-management). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Open source
Docs

ONTAP 9.19.1 highlights

Source: docs

ONTAP 9.19.1 highlights — official NetApp ONTAP 9 documentation page (release-notes). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Open source
Docs

ONTAP 9.18.1 highlights

Source: docs

ONTAP 9.18.1 highlights — official NetApp ONTAP 9 documentation page (release-notes). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Open source
Docs

ONTAP 9.17.1 highlights

Source: docs

ONTAP 9.17.1 highlights — official NetApp ONTAP 9 documentation page (release-notes). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Open source
Docs

ONTAP 9.16.1 highlights

Source: docs

ONTAP 9.16.1 highlights — official NetApp ONTAP 9 documentation page (release-notes). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Open source
Docs

ONTAP 9.15.1 highlights

Source: docs

ONTAP 9.15.1 highlights — official NetApp ONTAP 9 documentation page (release-notes). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Open source
Docs

ONTAP 9.14.1 highlights

Source: docs

ONTAP 9.14.1 highlights — official NetApp ONTAP 9 documentation page (release-notes). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Open source
Docs

ONTAP 9.13.1 highlights

Source: docs

ONTAP 9.13.1 highlights — official NetApp ONTAP 9 documentation page (release-notes). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Open source
Docs

ONTAP 9.12.1 highlights

Source: docs

ONTAP 9.12.1 highlights — official NetApp ONTAP 9 documentation page (release-notes). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Open source
Docs

ONTAP 9 release highlights

Source: docs

ONTAP 9 release highlights — official NetApp ONTAP 9 documentation page (release-notes). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Open source
AI

NetApp to showcase how the NetApp platform enables AI-ready data, unified storage, proactive protection and complete control at LEAP 2026 - Zawya

Source: Google News RSS

NetApp to showcase how the NetApp platform enables AI-ready data, unified storage, proactive protection and complete control at LEAP 2026 - Zawya — coverage in the NetApp AI ecosystem: google news feed item dated 2026-08-30. Relevant to the NetApp AI priority: tracks AI infrastructure partnerships, AIPod deployments, BlueXP/AI Data Engine, NVIDIA integrations, and competitive AI storage market positioning (NetApp vs Nutanix, Pure, Vast). Adds to the NetApp Black Box AI knowledge base for cert exam context (NCIE-AI, NCDA) and site visitors researching NetApp's AI strategy.

Archive digest
AI

NetApp platform unveils AI-ready data, unified storage, proactive protection and complete control at LEAP 2026 - TahawulTech.com

Source: Google News RSS

NetApp platform unveils AI-ready data, unified storage, proactive protection and complete control at LEAP 2026 - TahawulTech.com — coverage in the NetApp AI ecosystem: google news feed item dated 2026-08-30. Relevant to the NetApp AI priority: tracks AI infrastructure partnerships, AIPod deployments, BlueXP/AI Data Engine, NVIDIA integrations, and competitive AI storage market positioning (NetApp vs Nutanix, Pure, Vast). Adds to the NetApp Black Box AI knowledge base for cert exam context (NCIE-AI, NCDA) and site visitors researching NetApp's AI strategy.

Archive digest
AI

NetApp platform unveils AI-ready data, unified storage at LEAP 2026 (TahawulTech)

Source: https://www.tahawultech.com/news/netapp-platform-unveils-ai-ready-data-unified-storage-proactive-protection-and-complete-control-at-leap-2026/

TahawulTech coverage of NetApp's LEAP 2026 keynote: positioning the NetApp platform as the unified storage + AI-ready data layer for enterprise customers in the Middle East, with proactive data protection and complete control highlighted as the headline benefits. Frames the announcements around ONTAP AI, BlueXP copilot, and AIPod Mini as the regional building blocks for enterprise AI factories in regulated industries.

Open source
AI

NetApp platform enables AI-ready data, unified storage at LEAP 2026 (Zawya)

Source: https://www.zawya.com/en/press-release/netapp-leap-2026-ai-data/

Zawya press release recap of NetApp's LEAP 2026 announcements: AI-ready data, unified storage, proactive protection and complete control. Highlights regional channel and partner commitments (Cisco, Lenovo, NVIDIA) and the AIPod Mini + BlueXP workflows that NetApp is positioning as the simplest path from pilots to production AI for Middle East enterprises.

Open source
AI

NetApp Sees Strong Storage Demand With AI-Related Tailwinds, BofA Securities

Source: https://news.google.com/rss/articles/CBMi1AFBVV95cUxQaE9sZVgwbnBpU0FHcERpbmhyejNEcWZKMV9ReUNxd0g2S0tQWDZ1VUxoTXgtTElaTGxia0NqOWhXN2tCRmxVdWRreVlrN2E4d1lxc2ZWblFieDRJUkpJOXZLektQYUpSV2o2NGpGeUxjcDB1YXpwQkd5ZG90UFZzUHE4eFZQMWxrVW5RU2ZHbEZhaHFycXpBSDNwRHFac2hqQVZBdU43QllETk9xY0VIcEZ3

BofA Securities coverage of NetApp: strong storage demand with AI-related tailwinds. Frames NetApp's growth thesis around enterprise AI infrastructure spend, EF-Series + AIPod partnerships with NVIDIA/Lenovo, and the AI Data Engine acquisition of DataPelago. Notes consensus revenue and ARR projections into 2027 with AI workloads cited as the primary driver.

Open source
AI

NetApp Insight 2026 — AI-ready data platform showcase (Zawya press release)

Source: https://www.zawya.com/en/press-releases/story/netapp-to-showcase-how-the-netapp-platform-enables-ai-ready-data-unified-storage-and-new-intelligent-data-infrastructure-capabilities-at-netapp-insight-2026

Pre-show press release for NetApp Insight 2026 (the annual NetApp customer + partner conference). Highlights the agenda pillars NetApp will showcase: AI-ready data pipelines, unified storage for hybrid cloud, and new Intelligent Data Infrastructure capabilities. NetApp Insight is the primary venue where NetApp announces platform-level product updates — the press framing here signals the themes (AI + unified storage + IDI) that the company's FY27 messaging will continue to lean on. Targets enterprise data-platform owners who are buying into the AIPod / AI Data Engine / AFX story and need a roadmap checkpoint for what's next.

Open source
Advisory

NetApp Advisories: 62 new entries published Aug 21–28 (sweep batch)

Source: NetApp Product Security (security.netapp.com advisory API)

This research sweep picked up 62 NetApp security advisories newly updated between Aug 21 and Aug 28, 2026 — covering OpenSSL, Node.js, Linux Kernel, Python, CPython, NGINX, Samba, MongoDB Drivers, Golang, Handlebars, Angular, Bouncy Castle, Runc, Apache ActiveMQ, Java Platform, ISC BIND, 7-Zip, GnuTLS, Glib, libxml2, libpng, Axios, Urllib3, PyJWT, pyca/cryptography, pyOpenSSL, Nghttp2, Node-Tar, qs, Jaraco, and more. Affected products span ONTAP, StorageGRID, BlueXP, SnapCenter, ONTAP Select, and the NetApp Manageability SDK. Notable interim entries: NTAP-20260123-0012 (January 2026 Java PS), NTAP-20260220-0013 (libxml2), NTAP-20260730-0005 (ISC BIND), and the July–August Linux Kernel CVE batch. Each advisory is in this library as a standalone record under the Advisory category.

Open source
Docs

NAS storage management

Source: docs

NAS storage management — official NetApp ONTAP 9 documentation page (nas-management). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Open source
Docs

Learn about cluster administration with the ONTAP CLI

Source: docs

Learn about cluster administration with the ONTAP CLI — official NetApp ONTAP 9 documentation page (system-admin). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Open source
Docs

Learn about SMB configuration with the ONTAP CLI

Source: docs

Learn about SMB configuration with the ONTAP CLI — official NetApp ONTAP 9 documentation page (smb-config). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Open source
Docs

Disks and ONTAP local tiers

Source: docs

Disks and ONTAP local tiers — official NetApp ONTAP 9 documentation page (disks-aggregates). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Open source
Community

Community: 100% CPU utilization on AFF A30 — WAFL/storage-efficiency background tasks

Source: https://community.netapp.com/t5/Discussions/td-p/468350

NetApp community thread where an AFF A30 customer reports persistent 100% CPU utilization on the **odd-numbered** cores in `sysstat` across 3 controllers, with minimal workload (mostly hourly SnapMirror destinations). NetApp engineer Jonathan Gaudette clarifies the architecture: the AFF A30 has **a single 16-core Xeon CPU with Intel Hyperthreading enabled**, so `sysstat` reports 32 logical processors — the apparent "odd-core" saturation is actually one of the two logical threads of each physical core being heavily used. He explains that newer ONTAP versions deliberately use as much CPU and RAM as possible for background tasks: **storage efficiency features (compression, dedupe, snapshots), WAFL free-block cleanup, filesystem metadata maintenance**, and (for SnapMirror destinations) replicating the source's storage-efficiency layouts. He warns against trusting AI-generated explanations of ONTAP sysstat that misattribute the load to "control vs data planes". The takeaway for operators: sustained near-100% CPU on AFF A-series is expected behavior under default efficiency settings — investigate only when it crosses into user-visible latency, not on raw utilization.

Open source
Community

AIQ Navigator is out — community discussion on r/netapp

Source: https://www.reddit.com/r/netapp/comments/1w2axt0/aiq_navigator_is_out/

Reddit r/netapp thread on the AIQ Navigator release: customers reacting to the new Active IQ Unified Dashboard UX, discussing migration from classic Active IQ, troubleshooting tip requests around AIOps alerts, and surfacing feature gaps vs BlueXP. Useful first-impression feedback for anyone evaluating AIQ Navigator for an ONTAP fleet.

Open source
AI

2026-09-02-netapp-platform-unveils-ai-ready-data-unified-storage-proactive-protection-and-c

Source: https://news.google.com/rss/articles/CBMi4gFBVV95cUxNTXNtMmg2TC1ScC1Wc2dYNFVORFlzNTlsQWY4eG5tUE5DeUxRX3dVSW5scFVqb05naXZKRTYxdENCemJaX0lvZHE0VEpNOGNLMHg4bTQ3cnFlQXdGQmFkaFdyeFB2eENJYkk1WXRtY1N4d2NkcjktNTdvT2Yzb0k1NmxQQlhMWWxHeF9IZWJ5ZUJvZE5iR3ZkZklmbFdIWExFOGdvckgyTzIwcy1fdmJndWFaRHhJQzlVVnBPc2NFLWVacXMwRkdrVkdlVDg5V19xeGpOSWJ0QzJMTm9qM1lGUkpB?oc=5

TahawulTech.com article from the NetApp AI Google News RSS feed. NetApp platform unveils AI-ready data, unified storage, proactive protection and complete control at LEAP 2026 - TahawulTech.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-netapp-ceo-on-biggest-ai-challenges-investments-and-partner-plans-for-2026-crn-c

Source: https://news.google.com/rss/articles/CBMitAFBVV95cUxPWjFkTURxb3pBZkstQTNuMFNMUkNWYkY5bTJBeHJjaEREZDU2NFhfUDBveFJnVzF4RU03a1NidDNKdnhTWUVFZy1iZE95ckE1dXF5M1o0VzZRcFc2bmk4TnlFN1VpSlV6M2czM0hRVFRSbUtkZkxOLU1fUjRLTFpRQl9HN0pmMC1Db2l1QUdaRjN5WFVmS0E1bEdGbVNhcGZoUEFtNjA5SEoydUxKOGlvTnlFekM?oc=5

crn.com article from the NetApp AI Google News RSS feed. NetApp CEO On Biggest AI Challenges, Investments And Partner Plans For 2026 - crn.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

Trust, but verify: why AI agents need Zero Trust infrastructure (NetApp)

Source: https://www.netapp.com/blog/trust-but-verify-ai-agents-zero-trust-infrastructure/

NetApp engineering blog on Zero Trust architecture for AI agents: why ONTAP becomes the policy enforcement point when LLM agents get read/write access to enterprise storage. Covers audit logging, immutable snapshots (SnapLock), RBAC + ABAC, ONTAP S3 access points, and how NetApp positions AIPod + AI Data Engine behind a Zero Trust control plane for agentic workflows.

Open source
Community

NetApp StorageGRID on VMware — ServerSideEncryption community thread

Source: https://www.reddit.com/r/netapp/comments/1vtswc2/netapp_storagegrid_on_vmware_serversideencryption/

Reddit r/netapp thread on configuring StorageGRID ServerSideEncryption (SSE) on VMware deployments: practitioners walk through KMS server setup, KMS key rotation, and the relationship between S3 SSE-S3, SSE-KMS and SSE-C on StorageGRID. Includes troubleshooting notes for failed PUTs due to clock skew and a workaround for VMware vCenter KMS key-pinning limitations.

Open source
News

NetApp Public Cloud Growth Momentum Question — qz.com

Source: qz.com (via Google News)

Quartz asks whether NetApp's public cloud segment (first-party and marketplace cloud storage services) can maintain its growth trajectory, as investors weigh the AI-driven storage demand wave against hybrid/on-prem strength. Reinforces the ongoing narrative that NetApp's AI upside is increasingly being priced through its cloud-attached storage business.

Open source
News

NTAP Markets & Flows Roundup — Aug 29, 2026

Source: Google News aggregation (MarketBeat, Stock Traders Daily, AD HOC NEWS)

Institutional flows keep accumulating into the fiscal Q1 FY2027 print: MarketBeat reports Skandia acquired 166,791 NTAP shares and Empowered Funds bought 119,168 shares (both Aug 29), following CDPQ's new $79.32M stake and Manufacturers Life's $18.95M position (Aug 28). Stock Traders Daily published a "Trading the Move, Not the Narrative: (NTAP) Edition" piece framing the stock on price action rather than the AI narrative. AD HOC NEWS notes NTAP steadied ahead of fiscal 2027 Q1 earnings.

Open source
AI

How NetApp's CMO Turned One AI-Generated Ad into a Rethink of Marketing

Source: Chief Marketer — https://news.google.com/rss/articles/CBMiowFBVV95cUxPTXI4dHUyWHR0VFlSNVlMaGlSUDRlQWJxbW1mTkV?oc=5

Chief Marketer covers how a single AI-generated ad campaign prompted NetApp's CMO to rethink the role of generative AI in enterprise marketing — a rare brand-side AI adoption story from NetApp itself. Beyond the creative angle it signals how NetApp positions its own Intelligent Data Infrastructure narrative using the same AI tooling it sells infrastructure for. Useful color for AI-era brand storytelling, not a storage product item.

Open source
AI

Accelerating data with NVIDIA GPUDirect Storage (NetApp)

Source: NetApp Blog (via Google News) — https://news.google.com/rss/articles/CBMikwFBVV95cUxNTHZHVnpXTldvVXhOY1IyakRmYVR4TVRxeG1OOGdESzh2ak5YOUVrMjFWTG9TYmxXSTVvTUVDWXduRTlVSWFrc3l1eG1LZFFLMm5ZSGcwenAwM3RlSzh3TnhkVVd6MC0zRkZSRncxeEN2V01UTGY0dVB2UlItdU95VWtpNlJLajFmbFZmU0NEQTh3anc?oc=5

A NetApp Blog piece on accelerating data movement with NVIDIA GPUDirect Storage: storage-to-GPU data paths that bypass the CPU for AI training and HPC workloads. It underpins NetApp's AI performance story around AFX/ONTAP storage in NVIDIA-validated stacks (AIPod, ONTAP AI) — direct-IO GPU access to datasets hosted on NetApp flash. Blog URL 403s to direct fetch; title and content captured via Google News RSS.

Open source
News

2026-08-29-netapp-autonomous-operations-storage-estate-blog

Source: NetApp Blog (via Google News) · **Date:** 2026-08-27 · **Category:** ai

NetApp Blog piece (27 Aug) urging admins to move storage estates toward autonomous operations: AI-driven monitoring, anomaly detection and self-healing across ONTAP fleets, tying together AIQUM, the AI-powered NetApp Console Assistant, and Console local deployment. Directly extends the Console-local-GA and TechTarget control-plane coverage already in the stream — this is NetApp's own manifesto for the manual-to-autonomous storage shift.

Open source
Community

2026-08-30 — NetApp AI signal: competitors + community angle

Source: Multiple — see entries below

Three AI-relevant signals from this run, none of which are pure NetApp-blog content but together sharpen the AI Hub's competitive-and-community positioning.

Archive digest
Docs

What's new in ONTAP 9.19.1

Source: docs

Official NetApp release notes for ONTAP 9.19.1 (Aug 2026): covers new features across Data protection, NAS, Networking, SAN, S3 object storage, Security, Storage resource management, System Manager, and Upgrade. Highlights include expanded ARP/AI enhancements, S3 SnapMirror improvements, NVMe/TCP performance work, and SnapMirror active sync refinements. Reference for admins planning 9.19.1 deployments.

Open source
Docs

SnapLock configuration overview (ONTAP docs)

Source: docs

Official NetApp ONTAP concept doc on configuring SnapLock Compliance and Enterprise volumes: WORM file locking, retention periods, privileged delete, audit logging, and SnapLock-to-SnapVault integration. Covers license requirements, per-volume mode selection, and operational considerations for compliance workloads (SEC 17a-4, HIPAA, GDPR Article 17).

Open source
AI

Simplify knowledge access with Claude for Desktop and NetApp

Source: https://www.netapp.com/blog/simplify-knowledge-access-claude-desktop-netapp/

NetApp engineering blog on integrating Claude for Desktop with NetApp ONTAP via MCP (Model Context Protocol): turn an ONTAP cluster into a knowledge base an LLM can read and cite, with native vector search, snapshot-scoped retrieval, and role-based filtering. Demonstrates how the ONTAP MCP GA in 2026 lets admins use Claude to query capacity, performance, and documentation without scripting.

Open source
Docs

S3 SnapMirror considerations and cloud targets (ONTAP docs)

Source: docs

Official NetApp ONTAP concept doc on S3 SnapMirror cloud-target requirements: compatibility matrix for ONTAP S3, StorageGRID, and AWS S3 targets. Covers bucket-policy prerequisites, replication topology, IAM mapping, and aggregate/cluster sizing for large-scale object replication to the cloud.

Open source
Docs

ONTAP volume SnapMirror relationships with FlexClone files and LUNs

Source: docs

Official NetApp ONTAP concept doc on how volume SnapMirror relationships interact with FlexClone files and LUNs: clone-from-snapshot semantics across DR relationships, dependencies on base snapshots, and best practices for cloning on DP volumes. Reference for admins managing test/dev clones on DR-replicated volumes.

Open source
Docs

ONTAP anti-ransomware overview

Source: docs

Official NetApp ONTAP overview of the Autonomous Ransomware Protection (ARP/ARP-AI) feature: detects anomalous file-activity patterns in real time, takes automatic protective snapshots, and alerts admins to suspicious workloads. Covers ARP vs ARP-AI differences, workload profiles, training/learning mode, and recommended response actions when an attack is detected.

Open source
Docs

ONTAP SnapMirror active sync use cases (ONTAP docs)

Source: docs

Official NetApp ONTAP concept doc on SnapMirror active sync use cases: symmetric active/active replication for zero-RPO/RTO business-critical workloads, VMware vSphere Metro Storage Cluster (vMSC) and Oracle/RHEL clustering. Covers host-side mediator requirements, planned/unplanned failover flows, and consistency group semantics.

Open source
Docs

ONTAP SnapMirror active sync strategy and architecture (ONTAP docs)

Source: docs

Official NetApp ONTAP concept doc on SnapMirror active sync strategy: synchronous and asynchronous replication modes, consistency group topology, ONTAP Mediator role, and cluster-aware failover orchestration. Reference for architects designing zero-RPO stretched-cluster and metro-distance configurations.

Open source
Product

Nutanix Fiscal 4Q26 and FY26 Financial Results (competitor watch)

Source: StorageNewsletter — https://www.storagenewsletter.com/2026/08/28/nutanix-fiscal-4q26-and-fy26-financial-results/

Nutanix closed fiscal 2026 (ended July 31, 2026) with Q4 revenue of $757.1M, up 7.7% sequentially and 16% YoY, approaching ~$3B in annual revenue, with FY26 ARR up 16% and CFO Rukmini Sivaraman highlighting "good balance of top and bottom line performance" plus strong free cash flow. Operating margin nearly doubled to 9.2% (per Pulse 2.0's coverage). Competitive read for NetApp: the HCI/AI-bundle rival enters NetApp's fiscal Q1 FY2027 earnings window with double-digit growth and improving profitability, keeping pricing and AI-infrastructure pressure on NetApp's AFX/AIPod motions — NetApp's counter remains owning the data layer (ONTAP, AI Data Engine, StorageGRID) beneath the compute stack.

Open source
AI

NetApp to Report Q1 Earnings: Here's What Investors Should Know - TradingView

Source: Google News RSS

NetApp to Report Q1 Earnings: Here's What Investors Should Know - TradingView — coverage in the NetApp AI ecosystem: google news feed item dated 2026-08-28. Relevant to the NetApp AI priority: tracks AI infrastructure partnerships, AIPod deployments, BlueXP/AI Data Engine, NVIDIA integrations, and competitive AI storage market positioning (NetApp vs Nutanix, Pure, Vast). Adds to the NetApp Black Box AI knowledge base for cert exam context (NCIE-AI, NCDA) and site visitors researching NetApp's AI strategy.

Archive digest
News

NetApp to Report Q1 Earnings: Here's What Investors Should Know

Source: TradingView News (via Google News)

NetApp is set to report its fiscal Q1 2027 results, with Wall Street focused on whether the company's AI-driven storage demand and raised guidance from the July Q4 report are carrying into the new quarter. Investor previews highlight NTAP trading near 12-month highs, with analyst fair values and price targets (including J.P. Morgan's $195) keying off AI data-platform momentum — the AI Data Engine, DataPelago integration, and AFX portfolio. Options markets imply a mid-single-digit move on the print; watch AI-related bookings commentary and enterprise hybrid-cloud growth rates.

Open source
Advisory

NetApp Advisories: NTAP-20260828-0021 — StorageGRID DoS (CVE-2026-22056)

Source: NetApp Product Security

NTAP-20260828-0021 is an Interim advisory for CVE-2026-22056, a Denial of Service vulnerability in StorageGRID (formerly StorageGRID Webscale). Successful exploitation could lead to DoS. StorageGRID operators should watch for the fix and check the affected-versions list; this is a follow-on to the Aug 28 batch of 20 advisories (NTAP-20260828-0001 to -0020) already covered.

Open source
News

NTAP Markets Roundup: Aug 28 evening — outperformer day, new institutional buys, long-run piece

Source: MarketWatch / Benzinga / MarketBeat (via Google News)

Evening routine-market sweep: MarketWatch reports NetApp stock outperformed competitors despite losses on the day (Aug 28); Benzinga runs a "If You Invested $1000 In NetApp Stock 10 Years Ago" retrospective on the AI-era rerating; MarketBeat flags MASTERINVEST Kapitalanlage taking a $1.42M NTAP position, Manufacturers Life Insurance investing $18.95M, and NetApp holding an average analyst recommendation of "Hold." No operational impact for ONTAP admins; sentiment backdrop remains AI-guidance-led strength into the fiscal Q1 print.

Open source
Advisory

June 2026 FreeBSD ZFS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0005/

NetApp published this interim advisory covering CVE-2026-49429, CVE-2026-49430, CVE-2026-49431; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 FreeBSD ZFS Vulnerabilities in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0005

NetApp published security advisory NTAP-20260828-0005 on 2026-08-28. All supported versions of FreeBSD are susceptible to vulnerabilities in ZFS which when successfully exploited could allow local users with various permissions to trigger a kernel heap overflow, trigger kernel memory corruption or set the internal ZFS metadata flag "$hasrecvd" on datasets.

Open source
Advisory

June 2026 FreeBSD ZFS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0005/

All supported versions of FreeBSD are susceptible to vulnerabilities in ZFS which when successfully exploited could allow local users with various permissions to trigger a kernel heap overflow, trigger kernel memory corruption or set the internal ZFS metadata flag "$hasrecvd" on datasets.

Open source
Advisory

January 2026 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260123-0012 (2026-08-28) (interim — details may evolve) covering CVE-2026-21932, CVE-2026-21945, CVE-2026-21925, CVE-2026-21933. The advisory affects Active IQ Unified Manager for VMware vSphere, Data Infrastructure Insights and Data Secure Storage Workload Security Agent, NetApp Console Agent, OnCommand Insight. Fix status: Fix status not yet published. Impact: Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data as well as unauthorized read access to a subset of Oracle Java SE accessible data, unauthorized creation, deletion or modification access Administrators should compare the affected-version and remediation tables with their inventory.

Open source
News

J.P. Morgan Keeps Hold Rating on NetApp — Globe and Mail

Source: The Globe and Mail (via Google News)

J.P. Morgan reiterated its Hold rating on NetApp (NTAP) ahead of the fiscal Q1 FY2027 report. NetApp's average analyst recommendation remains "Hold" per MarketBeat, with the Q1 print next week expected to test whether AI-driven storage demand and July's raised guidance carry through.

Open source
Docs

FabricPool volume tiering policies (ONTAP docs)

Source: docs

Official NetApp ONTAP concept doc on FabricPool volume tiering policies: explains snapshot-only, auto, all, and none tiering policies, and how they interact with the cloud retrieval policy. Covers what happens when a tiering policy is modified, when a volume is moved or cloned, and how cloud-retrieval policies compose with tiering policies. Reference for capacity-tier planning.

Open source
Docs

FC and FC-NVMe SAN configuration overview (ONTAP docs)

Source: docs

Official NetApp ONTAP concept doc on configuring FC and FC-NVMe fabrics: zoning, switch configuration, host-side masking, asymmetric namespace access (ANA), and HA-pair failover behavior. Covers direct-attach and switched fabrics, NVMe/FC and NVMe/TCP, and LUN/namespace service migration between SVMs.

Open source
Docs

Considerations for S3 SnapMirror upgrades (ONTAP docs)

Source: docs

Official NetApp ONTAP concept doc on upgrade considerations when S3 SnapMirror relationships are present: mixed-version replication support windows, target cluster minimum-version requirements, and recommended upgrade order (consumers first, producers last). Reference for cluster upgrade planning.

Open source
Docs

Configure external key management with ONTAP NetApp Volume Encryption

Source: docs

Official NetApp ONTAP concept doc on configuring external KMIP key managers (Thales, Gemalto, Utimaco, IBM SKLM) for NetApp Volume Encryption (NVE) and NetApp Aggregate Encryption (NAE). Covers key-manager connectivity, key-availability validation, and high-availability cluster key replication. Required reading for FIPS-140-3 and KMIP deployments.

Open source
Advisory

CVE-2026-59889 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0016/

NetApp published this interim advisory covering CVE-2026-59889; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59889 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0016

NetApp published security advisory NTAP-20260828-0016 on 2026-08-28, CVE-2026-59889. FasterXML Jackson Databind versions 2.18.0-rc1 through 2.18.8, 2.18.0-rc1 through 2.18.8, 2.21.0 through 2.21.4, 2.21.0 through 2.21.4, 2.22.0 through 2.22.0, 2.22.0 through 2.22.0, 3.0.0-rc1 through 3.1.4, 3.0.0-rc1 through 3.1.4, 3.2.0 through 3.2.0, and 3.2.0 through 3.2.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

CVE-2026-59889 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0016/

FasterXML Jackson Databind versions 2.18.0-rc1 through 2.18.8, 2.18.0-rc1 through 2.18.8, 2.21.0 through 2.21.4, 2.21.0 through 2.21.4, 2.22.0 through 2.22.0, 2.22.0 through 2.22.0, 3.0.0-rc1 through 3.1.4, 3.0.0-rc1 through 3.1.4, 3.2.0 through 3.2.0, and 3.2.0 through 3.2.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

CVE-2026-59888 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0015/

NetApp published this interim advisory covering CVE-2026-59888; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59888 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0015

NetApp published security advisory NTAP-20260828-0015 on 2026-08-28, CVE-2026-59888. FasterXML Jackson Databind versions 2.15.0-rc1 through 2.18.7, 2.19.0-rc2 through 2.21.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data.

Open source
Advisory

CVE-2026-59888 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0015/

FasterXML Jackson Databind versions 2.15.0-rc1 through 2.18.7, 2.19.0-rc2 through 2.21.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data.

Open source
Advisory

CVE-2026-59875 Tar Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0004/

NetApp published this interim advisory covering CVE-2026-59875; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-59875 Tar Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0004

NetApp published security advisory NTAP-20260828-0004 on 2026-08-28, CVE-2026-59875. Tar versions prior to 7.5.17 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-59874 Tar Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0002/

NetApp published this interim advisory covering CVE-2026-59874; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59874 Tar Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0002

NetApp published security advisory NTAP-20260828-0002 on 2026-08-28, CVE-2026-59874. Tar versions prior to 7.5.18 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-59873 Tar Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0001/

NetApp published this interim advisory covering CVE-2026-59873; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59873 Tar Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0001

NetApp published security advisory NTAP-20260828-0001 on 2026-08-28, CVE-2026-59873. Tar versions prior to 7.5.19 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-59871 Tar Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0003/

NetApp published this interim advisory covering CVE-2026-59871; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-59871 Tar Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0003

NetApp published security advisory NTAP-20260828-0003 on 2026-08-28, CVE-2026-59871. Tar versions prior to 7.5.18 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-59250 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0009/

NetApp published this interim advisory covering CVE-2026-59250; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59250 Erlang/OTP Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0009

NetApp published security advisory NTAP-20260828-0009 on 2026-08-28, CVE-2026-59250. Erlang/OTP versions 17.0 prior to 29.0.4 and 28.5.0.4 prior to 27.3.4.15 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS).

Open source
Advisory

CVE-2026-59250 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0009/

Erlang/OTP versions 17.0 prior to 29.0.4 and 28.5.0.4 prior to 27.3.4.15 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS).

Open source
Advisory

CVE-2026-55953 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0008/

NetApp published this interim advisory covering CVE-2026-55953; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-55953 Erlang/OTP Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0008

NetApp published security advisory NTAP-20260828-0008 on 2026-08-28, CVE-2026-55953. Erlang/OTP versions R13B03 prior to 27.3.4.15, from 28.0 prior to 28.5.0.4, and from 29.0 prior to 29.0.4 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-55953 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0008/

Erlang/OTP versions R13B03 prior to 27.3.4.15, from 28.0 prior to 28.5.0.4, and from 29.0 prior to 29.0.4 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-54513 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0014/

NetApp published this interim advisory covering CVE-2026-54513; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-54513 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0014

NetApp published security advisory NTAP-20260828-0014 on 2026-08-28, CVE-2026-54513. FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-54513 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0014/

FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-54512 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0013/

NetApp published this interim advisory covering CVE-2026-54512; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-54512 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0013

NetApp published security advisory NTAP-20260828-0013 on 2026-08-28, CVE-2026-54512. FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-54512 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0013/

FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-54370 Acl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0011/

NetApp published this interim advisory covering CVE-2026-54370; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-54370 Acl Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0011

NetApp published security advisory NTAP-20260828-0011 on 2026-08-28, CVE-2026-54370. Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data.

Open source
Advisory

CVE-2026-54370 Acl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0011/

Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data.

Open source
Advisory

CVE-2026-54369 Acl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0010/

NetApp published this interim advisory covering CVE-2026-54369; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-54369 Acl Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0010

NetApp published security advisory NTAP-20260828-0010 on 2026-08-28, CVE-2026-54369. Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data.

Open source
Advisory

CVE-2026-54369 Acl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0010/

Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data.

Open source
Advisory

CVE-2026-45292 OpenTelemetry Java Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0020/

NetApp published this interim advisory covering CVE-2026-45292; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-44604 RPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0018/

NetApp published this interim advisory covering CVE-2026-44604; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-44604 RPM Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0018

NetApp published security advisory NTAP-20260828-0018 on 2026-08-28, CVE-2026-44604. RPM versions through 6.1.0-RC1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-44604 RPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0018/

RPM versions through 6.1.0-RC1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-44604 Attr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0012/

NetApp published this interim advisory covering CVE-2026-54371; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-44604 Attr Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0012

NetApp published security advisory NTAP-20260828-0012 on 2026-08-28, CVE-2026-44604. Attr versions prior to 2.6.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-44604 Attr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0012/

Attr versions prior to 2.6.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-44170 Mariadb Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0019/

NetApp published this interim advisory covering CVE-2026-44170; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-44170 Mariadb Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0019

NetApp published security advisory NTAP-20260828-0019 on 2026-08-28, CVE-2026-44170. MariaDB versions 10.6.1 prior to 10.6.25, 10.11.1 prior to 10.11.17, 11.4.1 prior to 11.4.11, 11.8.1 prior to 11.8.7, and 12.3.1 prior to 12.3.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-44170 Mariadb Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0019/

MariaDB versions 10.6.1 prior to 10.6.25, 10.11.1 prior to 10.11.17, 11.4.1 prior to 11.4.11, 11.8.1 prior to 11.8.7, and 12.3.1 prior to 12.3.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-31790 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0017 (2026-08-28) (interim — details may evolve) covering CVE-2026-31790. The advisory affects E-Series SANtricity OS Controller Software, FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400, Management Services for Element Software and NetApp HCI, NetApp HCI Baseboard Management Controller (BMC) - H610S. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-31789 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0011 (2026-08-28) (interim — details may evolve) covering CVE-2026-31789. The advisory affects NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp LOADER 8.x. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-31402 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0008 (2026-08-28) (interim — details may evolve) covering CVE-2026-31402. The advisory affects ONTAP tools for VMware vSphere 10. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-28390 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0012 (2026-08-28) (interim — details may evolve) covering CVE-2026-28390. The advisory affects Management Services for Element Software and NetApp HCI, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP tools for VMware vSphere 10. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-28389 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0013 (2026-08-28) (interim — details may evolve) covering CVE-2026-28389. The advisory affects Management Services for Element Software and NetApp HCI, NetApp HCI Baseboard Management Controller (BMC) - H610S. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-28388 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0014 (2026-08-28) (interim — details may evolve) covering CVE-2026-28388. The advisory affects NetApp HCI Baseboard Management Controller (BMC) - H610S. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-28387 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0015 (2026-08-28) (interim — details may evolve) covering CVE-2026-28387. The advisory affects NetApp HCI Baseboard Management Controller (BMC) - H610S. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-27141 Golang Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260320-0012 (2026-08-28) (interim — details may evolve) covering CVE-2026-27141. The advisory affects Astra Control Center - NetApp Kubernetes Monitoring Operator. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-27135 Nghttp2 Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260717-0011 (2026-08-28) (interim — details may evolve) covering CVE-2026-27135. The advisory affects Active IQ Unified Manager for VMware vSphere, ONTAP Select Deploy administration utility. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-25639 Axios Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260313-0010 (2026-08-28) (interim — details may evolve) covering CVE-2026-25639. The advisory affects NetApp Shift Toolkit, ONTAP tools for VMware vSphere 10, Storage Manager for ProxMox. Fix status: 2 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-23949 Jaraco.Context Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260327-0011 (2026-08-28) (interim — details may evolve) covering CVE-2026-23949. The advisory affects ONTAP tools for VMware vSphere 10. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-2391 Qs Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260515-0010 (2026-08-28) (interim — details may evolve) covering CVE-2026-2391. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-23095 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260424-0020 (2026-08-28) (interim — details may evolve) covering CVE-2026-23095. The advisory affects NetApp HCI Baseboard Management Controller (BMC) - H610S. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-23001 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260305-0018 (2026-08-28) (interim — details may evolve) covering CVE-2026-23001. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22990 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260508-0002 (2026-08-28) (interim — details may evolve) covering CVE-2026-22990. The advisory affects ONTAP tools for VMware vSphere 10. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22796 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260204-0004 (2026-08-28) (interim — details may evolve) covering CVE-2026-22796. The advisory affects Brocade SAN Navigator (SANnav), Management Services for Element Software and NetApp HCI, NetApp Console Agent Container (adc), NetApp Console Agent Container (cbs), NetApp Console Agent Container (cbs-backend). Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22795 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260204-0005 (2026-08-28) (interim — details may evolve) covering CVE-2026-22795. The advisory affects Brocade SAN Navigator (SANnav), Management Services for Element Software and NetApp HCI, NetApp Console Agent Container (cbs-backend), NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp LOADER 8.x. Fix status: 2 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-21714 Node.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0012 (2026-08-28) (interim — details may evolve) covering CVE-2026-21714. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-21710 Node.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0013 (2026-08-28) (interim — details may evolve) covering CVE-2026-21710. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-21637 Node.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260313-0009 (2026-08-28) (interim — details may evolve) covering CVE-2026-21637. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-21441 Urllib3 Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260130-0010 (2026-08-28) (interim — details may evolve) covering CVE-2026-21441. The advisory affects Management Services for Element Software and NetApp HCI, NetApp Data Classification. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-18963 Keycloak Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0006/

NetApp published this interim advisory covering CVE-2026-18963; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-18963 Keycloak Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0006

NetApp published security advisory NTAP-20260828-0006 on 2026-08-28, CVE-2026-18963. Keycloak versions prior to 26.7.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-17106 Docker Engine Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0017/

NetApp published this interim advisory covering CVE-2026-17106; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-17106 Docker Engine Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0017

NetApp published security advisory NTAP-20260828-0017 on 2026-08-28, CVE-2026-17106. Docker Engine versions prior to 29.7.2 are susceptible to a vulnerability via moby/go-archive which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-17106 Docker Engine Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0017/

Docker Engine versions prior to 29.7.2 are susceptible to a vulnerability via moby/go-archive which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-15571 Keycloak Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0007/

NetApp published this interim advisory covering CVE-2026-15571; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-15571 Keycloak Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0007

NetApp published security advisory NTAP-20260828-0007 on 2026-08-28, CVE-2026-15571. Keycloak versions prior to 26.7.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-15308 CPython Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260717-0016 (2026-08-28) (interim — details may evolve) covering CVE-2026-15308. The advisory affects Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Management Services for Element Software and NetApp HCI. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-12617 ISC BIND Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260730-0005 (2026-08-28) (interim — details may evolve) covering CVE-2026-12617. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-0990 Libxml2 Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260220-0013 (2026-08-28) (interim — details may evolve) covering CVE-2026-0990. The advisory affects NetApp Manageability SDK, ONTAP 9. Fix status: 2 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

April 2026 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260429-0012 (2026-08-28) (interim — details may evolve) covering CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-34268. The advisory affects Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Data Infrastructure Insights and Data Secure Storage Workload Security Agent, NetApp Console Agent, OnCommand Insight. Fix status: 1 fix entries. Impact: Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE accessible data, unauthorized access to critical data or complete access to all Oracle Java SE accessible data or the unauthorized ability to cause a partial Denial of Se Administrators should compare the affected-version and remediation tables with their inventory.

Open source
News

Analyst Optimism + Gartner Leadership Shape NTAP Earnings Narrative (Yahoo Finance); Zacks Q1 Preview

Source: Yahoo Finance / Zacks (via Google News)

Yahoo Finance's earnings-narrative piece argues that analyst optimism and NetApp's Leader placement in the 2026 Gartner Magic Quadrant for Enterprise Storage could shape the NTAP story into the fiscal Q1 FY2027 report — estimates revisions and Gartner validation reinforcing the AI-storage growth thesis. Zacks' concurrent preview frames the same print around revenue/EPS expectations and AI-driven all-flash demand. Complements the Aug 28 TradingView preview already gathered.

Open source
AI

2026-09-02-netapp-to-report-q1-earnings-here-s-what-investors-should-know-the-globe-and-mai

Source: https://news.google.com/rss/articles/CBMi3wFBVV95cUxQRDFTQTB2WVd6QVhaQ0JtdlVpeVphOE5OcGR2M2FnQmc3LUFXZDZ4cUJtUlFaUGwydUsxZHhuVlY3Z1h0cldTbzczanZxVURtblRlOGZCMXhEbE5Sa2U5XzFJNEQ2em10eUx3MlktTXRuMHhmbk5sdUtPNk94T1ppNGw1RjB2M3RPT0dtTk1tamZMZWp3bjFBM2lNXzNoRGphTUJxdnoxVi1VejI5bzFmNFlKdktpNjVLOWROLUhZTWJKbWxUcV9HQWU1TkR1eGlkbDFveWY2QzBtSk5idmJv?oc=5

The Globe and Mail article from the NetApp AI Google News RSS feed. NetApp to Report Q1 Earnings: Here's What Investors Should Know - The Globe and Mail. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

2026-09-02-2026-08-28-june-2026-freebsd-zfs-vulnerabilities-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260828-0005

June 2026 FreeBSD ZFS Vulnerabilities in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-49429, CVE-2026-49430, CVE-2026-49431. All supported versions of FreeBSD are susceptible to vulnerabilities in ZFS which when successfully exploited could allow local users with various permissions to trigger a kernel heap overflow, trigger kernel memory corruption or set the internal ZFS metadata flag "$hasrecvd" on datasets.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-59889-fasterxml-jackson-databind-vulnera

Source: https://security.netapp.com/advisory/NTAP-20260828-0016

CVE-2026-59889 FasterXML Jackson Databind Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-59889. FasterXML Jackson Databind versions 2.18.0-rc1 through 2.18.8, 2.18.0-rc1 through 2.18.8, 2.21.0 through 2.21.4, 2.21.0 through 2.21.4, 2.22.0 through 2.22.0, 2.22.0 through 2.22.0, 3.0.0-rc1 through 3.1.4, 3.0.0-rc1 through 3.1.4, 3.2.0 through 3.2.0, and 3.2.0 through 3.2.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-59888-fasterxml-jackson-databind-vulnera

Source: https://security.netapp.com/advisory/NTAP-20260828-0015

CVE-2026-59888 FasterXML Jackson Databind Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-59888. FasterXML Jackson Databind versions 2.15.0-rc1 through 2.18.7, 2.19.0-rc2 through 2.21.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-59875-tar-vulnerability-in-netapp-produc

Source: https://security.netapp.com/advisory/NTAP-20260828-0004

CVE-2026-59875 Tar Vulnerability in NetApp Products. Affected: NetApp HCI Baseboard Management Controller (BMC) - H610S. CVEs: CVE-2026-59875. Tar versions prior to 7.5.17 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-59871-tar-vulnerability-in-netapp-produc

Source: https://security.netapp.com/advisory/NTAP-20260828-0003

CVE-2026-59871 Tar Vulnerability in NetApp Products. Affected: NetApp HCI Baseboard Management Controller (BMC) - H610S. CVEs: CVE-2026-59871. Tar versions prior to 7.5.18 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-59250-erlang-otp-vulnerability-in-netapp

Source: https://security.netapp.com/advisory/NTAP-20260828-0009

CVE-2026-59250 Erlang/OTP Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-59250. Erlang/OTP versions 17.0 prior to 29.0.4 and 28.5.0.4 prior to 27.3.4.15 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-55953-erlang-otp-vulnerability-in-netapp

Source: https://security.netapp.com/advisory/NTAP-20260828-0008

CVE-2026-55953 Erlang/OTP Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-55953. Erlang/OTP versions R13B03 prior to 27.3.4.15, from 28.0 prior to 28.5.0.4, and from 29.0 prior to 29.0.4 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-54513-fasterxml-jackson-databind-vulnera

Source: https://security.netapp.com/advisory/NTAP-20260828-0014

CVE-2026-54513 FasterXML Jackson Databind Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54513. FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-54512-fasterxml-jackson-databind-vulnera

Source: https://security.netapp.com/advisory/NTAP-20260828-0013

CVE-2026-54512 FasterXML Jackson Databind Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54512. FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-54370-acl-vulnerability-in-netapp-produc

Source: https://security.netapp.com/advisory/NTAP-20260828-0011

CVE-2026-54370 Acl Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54370. Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-54369-acl-vulnerability-in-netapp-produc

Source: https://security.netapp.com/advisory/NTAP-20260828-0010

CVE-2026-54369 Acl Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54369. Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-45292-opentelemetry-java-vulnerability-i

Source: https://security.netapp.com/advisory/NTAP-20260828-0020

CVE-2026-45292 OpenTelemetry Java Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-45292. OpenTelemetry Java versions through 1.61.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-44604-rpm-vulnerability-in-netapp-produc

Source: https://security.netapp.com/advisory/NTAP-20260828-0018

CVE-2026-44604 RPM Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-44604. RPM versions through 6.1.0-RC1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-44604-attr-vulnerability-in-netapp-produ

Source: https://security.netapp.com/advisory/NTAP-20260828-0012

CVE-2026-44604 Attr Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54371. Attr versions prior to 2.6.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-44170-mariadb-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260828-0019

CVE-2026-44170 Mariadb Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-44170. MariaDB versions 10.6.1 prior to 10.6.25, 10.11.1 prior to 10.11.17, 11.4.1 prior to 11.4.11, 11.8.1 prior to 11.8.7, and 12.3.1 prior to 12.3.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-22056-denial-of-service-vulnerability-in

Source: https://security.netapp.com/advisory/NTAP-20260828-0021

CVE-2026-22056 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale). Affected: StorageGRID (formerly StorageGRID Webscale). CVEs: CVE-2026-22056. StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are susceptible to a Denial of Service vulnerability. Successful exploit could allow an attacker with some control over the environment to cause a partial Denial of Service.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-18963-keycloak-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260828-0006

CVE-2026-18963 Keycloak Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-18963. Keycloak versions prior to 26.7.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-17106-docker-engine-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260828-0017

CVE-2026-17106 Docker Engine Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-17106. Docker Engine versions prior to 29.7.2 are susceptible to a vulnerability via moby/go-archive which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-15571-keycloak-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260828-0007

CVE-2026-15571 Keycloak Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-15571. Keycloak versions prior to 26.7.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Community

2026-08-30 — Community: Cross-Region / Cross-Account Backup for FSx for ONTAP

Source: NetApp Community — https://community.netapp.com/community/discussion/468353/cross-region-and-cross-account-backup-for-amazon-fsx-for-netapp-ontap

NetApp Community walk-through of AWS Backup's new cross-account / cross-Region copy for Amazon FSx for NetApp ONTAP (announced 2026-08-27 by AWS). The post walks through four architecture patterns and a step-by-step: local backups → cross-Region copy → cross-account copy → organization-wide backup plans via AWS Organizations. Positions cross-account copies as a managed complement to Snapshot copies, SnapMirror, and FSx backups — not a replacement — and clarifies when each option protects against operator error, account compromise, or region loss.

Open source
Community

2026-08-30 — Community: 100% CPU utilization on NetApp A30 (AFF A30 / ASA A30)

Source: NetApp Community — https://community.netapp.com/community/discussion/468350/100-cpu-utilization-on-a30

Customer post on NetApp A30 nodes running flat at 100% CPU under what should be modest workload. Community + NetApp staff trace it to a specific subsystem (mhost / RAID / nbl process depending on the thread), identify workload-driven saturation versus a known issue, and recommend a perfstat collection + AutoSupport review before opening a case. Useful real-world trace for anyone operating AFF A30 / ASA A30 fleets at scale.

Open source
News

2026-08-28-techtarget-storage-control-planes-autonomous

Source: TechTarget / IT Infrastructure · **Date:** 2026-07-01 · **Category:** ai/news

TechTarget feature on the industry shift from manual storage administration to autonomous, AI-driven control planes. Covers AIOps-driven anomaly detection, predictive provisioning, and self-healing storage operations — the trend NetApp is riding with AIQUM, the AI-powered Console Assistant, and the newly GA'd Console local deployment for fleet-scale ONTAP management.

Open source
News

2026-08-28-storagemath-afx-aide-critique

Source: storagemath.com (surfaced on Hacker News) · **Date:** 2025-12-14 · **Category:** ai

A skeptical technical deep-dive into NetApp's INSIGHT 2025 AFX announcement: it walks the math behind the "over 1 exabyte of effective capacity" claim (≈74.9PB raw from 52 NX224 enclosures, implying heavy thin-provisioning/dedup assumptions), questions whether "proven over decades" applies to a brand-new disaggregated architecture, and critiques the AI Data Engine's four bundled solutions. A useful counterpoint analysis for anyone evaluating AFX/AIDE claims — a rare critical AI-era take resurfacing on HN this week.

Open source
News

2026-08-28-sp-global-fsx-ontap-dr-snapshots

Source: AWS Storage Blog · **Date:** 2026-07-07 · **Category:** community

AWS publishes a customer case study on S&P Global's DR architecture built on Amazon FSx for NetApp ONTAP snapshots — snapshot-based replication as the backbone of recovery objectives for financial data workloads, with no secondary full arrays to manage.

Open source
News

2026-08-28-ontap-tools-10-4-deployment-walkthrough

Source: NetApp · **Date:** 2026-01-16 · **Category:** docs

NetApp publishes a complete end-to-end deployment walkthrough for ONTAP Tools 10.4 on VMware vSphere — covering deployment, registration, and configuration of the vSphere plugin used to provision and manage ONTAP datastores.

Open source
News

2026-08-28-modernize-virtualization-nutanix-ontap

Source: NetApp Blog · **Date:** 2026-04-07 · **Category:** product

NetApp details the Nutanix + ONTAP partnership: running Nutanix clusters backed by ONTAP enterprise storage gives VMware-refugee customers a migration path that keeps proven NetApp data services (snapshots, SnapMirror, security) underneath a new virtualization stack.

Open source
News

2026-08-28-console-local-deployment-ga-ai

Source: NetApp Community (Cathi_Allen) · **Date:** 2026-08-27 · **Category:** ai/product

NetApp announced general availability of NetApp Console local deployment: a locally deployed, AI-driven control plane bringing fleet-scale management to on-premises ONTAP estates for the first time as a unified Console experience. It adds fleet organization, unified observability, policy-governed provisioning via Storage Classes, and an AI-powered Console Assistant — running inside the customer environment with no constant cloud connection required. One platform, two deployments (cloud + local); validated through the Early Access Program. Directly relevant to the autonomous-operations and agentic-AI management storyline.

Open source
News

2026-08-28-cisco-secure-ai-factory-nvidia

Source: DataCenterNews Asia Pacific · **Date:** 2026-08-26 · **Category:** ai

Cisco broadened its Secure AI Factory with NVIDIA to include validated designs spanning air-gapped, sovereign, and hybrid clouds. The Cisco-NVIDIA AI infrastructure ecosystem — where NetApp's AFF and ONTAP AI validated designs have long anchored the storage layer — keeps deepening, which matters for NetApp AI data platform positioning against it in hyperscaler-adjacent AI factory deals.

Open source
News

2026-08-28-aws-fsx-hybrid-ml-inferencing

Source: AWS Storage Blog · **Date:** 2026-08-28 · **Category:** docs

AWS walks through keeping multi-GB ML model weights out of container images by loading them at runtime from Amazon FSx for NetApp ONTAP — including hybrid setups where the same data is served from on-premises NetApp systems. Inference pods stay stateless and small while ONTAP multiprotocol access (NFS) supplies checkpoints, tokenizer files, and compiled artifacts; a strong pattern for EKS-based AI inference estates bridging on-prem ONTAP.

Open source
Community

2026-08-30 — Community AI signal: "Agentic AI and NetApp" discussion

Source: NetApp Community Discussion — https://community.netapp.com/community/discussion/468349/agentic-ai-and-netapp

A NetApp Community thread exploring how agentic AI maps onto the NetApp stack — MCP-style agents invoking ONTAP operations, AI assistants surfacing storage telemetry, and how AIPod / NetApp Console / AI Data Engine fit an agent-driven enterprise AI story. Discusses agent governance concerns (read vs. write actions, RBAC), and what infrastructure primitives (snapshots, clones, SnapMirror) look like from an autonomous-agent perspective.

Open source
News

Will NetApp's Public Cloud Business Maintain Its Growth Momentum?

Source: The Globe and Mail (Zacks Equity Research) · **Date:** 2026-08-27 · **Category:** news

Zacks analysis asking whether NetApp's public cloud segment — Azure NetApp Files, Amazon FSx for NetApp ONTAP, Google Cloud NetApp Volumes, Cloud Volumes ONTAP and Keystone — can keep being the growth engine while the on-prem all-flash/AI wave takes the headlines. The segment's trajectory is the earnings variable to watch tonight (fiscal Q1 FY2027 results, Wednesday after close): cloud growth has moderated from its hypergrowth phase just as hyperscaler-native rivals (Everpure and first-party file services) press on the same workloads. Complements this week's Everpure-competitor piece and the pre-earnings chatter roundup already logged.

Open source
Product

Trident 26.06.1 previews Google Cloud NetApp Volumes ONTAP-mode support

Source: NetApp Community (DianePatton) · **Date:** 2026-08-26 · **Category:** product

NetApp Trident 26.06.1 is available in Preview for Google Cloud NetApp Volumes (GCNV) ONTAP-mode, letting Kubernetes admins provision and manage GCNV-backed persistent volumes through the standard CSI workflow. This closes a gap versus AWS FSx for ONTAP / Azure NetApp Files Astra-style integrations — worth tracking for GKE teams that need ONTAP-class snapshots, QoS, or NAS features behind native cloud volumes.

Open source
Docs

Tech ONTAP: PowerShell automation for VMware datastores on ASA systems

Source: NetApp Tech ONTAP Blogs via Community (ChanceBingen, active thread w/ OGill) · **Date:** 2026-08-25 · **Category:** docs

NetApp updated its VMware vSphere with ONTAP best practices to recommend the latency optimization policy (`latency_optimized_workload`) for VMware datastores on the new ASA series controllers, with companion PowerShell automation to enforce it at scale across datastore provisioning. Active community thread adds real-world tuning notes — directly applicable to anyone standardizing ASA-backed vSphere estates.

Open source
Community

System Manager passkey MFA for ONTAP local accounts

Source: NetApp Community (MarktheSpark, 3 comments, OGill active) · **Date:** 2026-08-24 · **Category:** community

Admin investigation thread on enabling MFA via passkeys (WebAuthn) for ONTAP System Manager when systems use local accounts instead of AD — a deliberate design some shops take so that an Active Directory compromise doesn't cascade into storage management access. Thread covers feasibility of passkey-backed MFA on FAS/AFF local auth and its trade-offs; useful reference for security-hardening drives on air-gap-adjacent or reduced-AD-footprint environments.

Open source
News

StructureCraft Scales Data-Driven Design on NetApp

Source: HPCwire · **Date:** 2026-07-22 · **Category:** ai

HPCwire customer profile of StructureCraft, the structural timber engineering firm known for computationally heavy, data-driven design workflows. The story is a useful AI-ecosystem data point for NetApp beyond the classic datacenter: generative/simulation-assisted engineering pipelines (large CAD/geometric datasets, analysis runs, versioned design corpora) are an enterprise AI-adjacent workload class that ONTAP's multiprotocol file services, snapshots and clone workflows serve well. Customer evidence like this backs the "governed data next to the workload" pitch NetApp makes for AI factories — design and simulation data staying on one platform instead of scattered across endpoints.

Open source
Community

SnapLock on the ONTAP simulator

Source: NetApp Community (JB) · **Date:** 2026-08-27 · **Category:** community

Fresh morning thread asking whether SnapLock works in the ONTAP simulator: the admin created a SnapLock aggregate, volume and compliance/enterprise log volume mirroring production settings. Relevant to lab planning — SnapLock WORM behaviors (retention clocks, compliance volume restrictions) validate differently on simulator hardware, so this is a good caution flag before rehearsing SnapLock runbooks purely in ONTAP Select-style labs.

Open source
News

Pre-earnings market flows: Sanctuary Advisors opens NTAP position

Source: MarketBeat via Google News; simplywall.st · **Date:** 2026-08-27 · **Category:** news

Final pre-results filer batch before fiscal Q1 FY2027 earnings: Sanctuary Advisors LLC opened a fresh NTAP position, CIBC World Markets made a new investment, and Connor Clark & Lunn put in $7.67M — continuing the week's institutional accumulation pattern ahead of Wednesday-after-close results. simplywall.st ties the narrative together: does Gartner MQ leadership plus rising consensus estimates materially change the bull case, with AI-led storage demand still the load-bearing assumption.

Open source
News

OpenNebula Systems and NetApp partner to power enterprise clouds and AI factories

Source: AiThority · **Date:** 2026-08-04 · **Category:** ai

OpenNebula Systems — the open-source cloud platform vendor behind EU AI-factory builds — is partnering with NetApp so ONTAP-based data services underpin enterprise private clouds and sovereign AI-factory deployments. The tie-up positions NetApp storage as the data layer inside OpenNebula-managed clouds, extending the NVIDIA AI Data Platform / AFX ecosystem play toward European sovereign-AI customers who want an alternative to hyperscaler-only stacks.

Open source
AI

Nutanix’s AI And Cloud Stack Is Winning Over Wall Street - Finimize

Source: Google News RSS

Nutanix’s AI And Cloud Stack Is Winning Over Wall Street - Finimize — coverage in the NetApp AI ecosystem: google news feed item dated 2026-08-27. Relevant to the NetApp AI priority: tracks AI infrastructure partnerships, AIPod deployments, BlueXP/AI Data Engine, NVIDIA integrations, and competitive AI storage market positioning (NetApp vs Nutanix, Pure, Vast). Adds to the NetApp Black Box AI knowledge base for cert exam context (NCIE-AI, NCDA) and site visitors researching NetApp's AI strategy.

Archive digest
AI

Nutanix's AI and cloud stack is winning over Wall Street

Source: Finimize via Google News · **Date:** 2026-08-27 (16:37 UTC) · **Category:** ai

Finimize profiles Nutanix's Wall Street momentum, crediting its AI-capable hyperconverged stack and cloud partnerships for the institutional affection. The competitive read for NetApp: Nutanix is packaging AI infrastructure for the same mid-enterprise buyers NetApp's AIPod Mini/AFX line courts, but Nutanix sells the software+subscription motion while NetApp owns the data layer (ONTAP, AI Data Engine, StorageGRID) underneath. NetApp's answer so far is governance-grade AI data infrastructure versus HCI-first AI bundles — a fight worth tracking as both court the same enterprise AI budgets.

Open source
AI

NetApp: the enterprise-grade data platform for AI

Source: NetApp blog (netapp.com) · **Date:** 2026-06-14 · **Category:** ai

Backfill from the AI priority stream: NetApp's anchor page for its enterprise AI data platform, laying out the full stack — ONTAP unified storage under AI workloads, AFX disaggregated systems, the AI Data Engine for discovering/securing/transforming enterprise data into AI-ready form, and the NVIDIA partnership (AIPod, DGX SuperPOD certification, NIM/NeMo integrations). It is the canonical "one platform from edge to cloud for training and inference" pitch, and the reference point the news stream's AIDE/AFX coverage keeps circling.

Open source
News

NetApp to Participate in Upcoming Conferences

Source: Yahoo Finance (press release) · **Date:** 2026-08-27 (20:01 UTC) · **Category:** news

NetApp published its upcoming investor-conference schedule the evening after fiscal Q1 FY2027 results week's close. Roadshow appearances are where the AI storage narrative gets quantified for institutions — expect AI Data Engine/AFX deal momentum, all-flash ARR trajectory, and Keystone consumption mix to be the recurring slides. Watch this space for webcast dates and any guidance color from the fireside chats.

Open source
News

NetApp federates performance-boosted StorageGRIDs into a single namespace

Source: Blocks & Files · **Date:** 2026-06-24 · **Category:** product

Blocks & Files reports NetApp federating performance-tuned StorageGRID systems into one global namespace, letting object stores scale horizontally without clients managing per-grid endpoints — notable for AI pipelines feeding petabyte-scale training sets and for grounding StorageGRID's Leader placement in the 2026 Forrester Object Storage Wave. For admins: expect the federation features to land alongside S3 API improvements rather than requiring a rip-and-replace migration.

Open source
News

NetApp Stock Looks Fairly Priced As Its 169% Run Tests Value

Source: https://finance.yahoo.com/news/netapp-nasdaq-ntap-stock-looks-fairly-210000815.html

Investor-side analysis of NetApp's 169% run over its evaluation window — frames the stock as testing fair value with AI tailwinds priced in. Useful for the AI-driven storage demand narrative and to ground the Bull/Bear case debate; complements BofA, J.P. Morgan, MarketBeat, and Finimize coverage already in the stream.

Open source
News

NetApp Recognized As One Of Washingtonian Magazine's 50 Great Places To Work

Source: WashingtonExec (via Google News) · **Date:** 2026-08-23 · **Category:** news

WashingtonExec reports NetApp landed on Washingtonian Magazine's 2026 "50 Great Places To Work" list, covering the company's DC-area workforce (NetApp has a large Reston, VA and federal-facing presence). A minor culture/employer-brand item rather than a product note, but it feeds the ongoing "employer of choice in storage" narrative that NetApp's careers and partner-recruiting pages lean on.

Open source
AI

NetApp Embraces Lustre as AI Pushes Storage Limits (HPCwire)

Source: https://www.hpcwire.com/2026/08/netapp-embraces-lustre-ai-storage/

HPCwire coverage of NetApp's adoption of Lustre for HPC/AI workloads: high-throughput parallel filesystem complementing ONTAP and StorageGRID for the hot tier of GPU training data. Frames NetApp alongside the other major storage vendors betting on parallel filesystems to handle the bandwidth requirements of training large models on NVIDIA Blackwell platforms.

Open source
News

NVIDIA and its partners' KV Cache extenders

Source: Blocks & Files · **Date:** 2026-03-30 · **Category:** ai

Blocks & Files rounds up NVIDIA's KV-cache-offloading partners — the vendors building cache extenders that spill LLM inference context (KV cache) onto NVMe storage instead of paying for ever-larger HBM. Complements the TechTarget deep-dive already in our AI hub and the NetApp Community KV CacheBlend explainer: low-latency flash tiers and fast NVMe/TCP paths are becoming a storage-admin workload, which is exactly where AFF/ASA and AFX sit in the inference stack.

Open source
News

NTAP evening momentum: Gartner-leader interpretation, moving-average reclaim, volatility and valuation checks

Source: Yahoo Finance / Zacks via Google News · **Date:** 2026-08-27 · **Category:** news

Four tape-and-narrative reads on NTAP the day after earnings: Yahoo asks what the 2026 Gartner MQ Leader placement actually changes for investors (answer: shelf-space and shortlist credibility, not a moat); Zacks flags the technical reclaim of the 20-day moving average as the buy-trigger level the charts had been waiting on; a same-day dip against a rising market shows the profit-taking reflex after the post-earnings run; and a valuation piece notes the stock's 169% run now prices it "fairly" — leaving AI-driven guidance as the only lever left to stretch the multiple.

Open source
News

KB: ONTAP upgrade validation check failed — LIFs not home

Source: kb.netapp.com · **Date:** 2026-08-12 · **Category:** docs

Fresh KB entry covering a classic pre-upgrade blocker: cluster upgrade validation fails because network interfaces report their operational state off their designated home node/port. Expected remediation flow: identify LIFs away-from-home (`network interface show -fields is-home,status-oper,address,node,port`), move or revert them (`network interface revert`), resolve the underlying port/link reason, then re-run upgrade validation. A good inclusion for any ONTAP upgrade runbook checklist.

Open source
News

KB / lab & blog docs roundup (3 items)

Source: NetApp KB/community (via Google News) · **Date:** 2026-02-28 · **Category:** docs

Explainer on storage mobility within ONTAP: moving volumes/LUNs across aggregates, nodes and tiers non-disruptively, and how SnapMirror relationships intersect with planned migrations.

Open source
News

KB / bug-track roundup #2 — new NetApp KB articles Aug 20–27 (32 items)

Source: kb.netapp.com (via Google News) · **Date:** 2026-08-20 → 2026-08-27 · **Category:** docs

tag keys/values (published Aug 27). Affects S3 object-tagging automation against ONTAP buckets; workaround is ASCII-safe tag keys until fixed. returns incomplete results in ONTAP 9.16 (Aug 23). Impacts export-policy audit tooling. `KRB5KDC_ERR_ETYPE_NOSUPP` (Aug 21). (Aug 24) — capacity planning for S3 Object Lock buckets used by Veeam GFS retention. (Aug 22) — interpreting quota EMS events after shared soft-limit churn. maximum reached silently; check `volume autosize` thresholds on suspect volumes. inline compression restrictions with guaranteed-space volumes. FPolicy scope granularity reference. (Aug 21) — StorageGRID per-bucket connection metrics.

Open source
News

Gartner's Shock Warning To Buyers As It Names Six Storage 'Leaders'

Source: IT Channel Oxygen · **Date:** 2026-08-27 · **Category:** news

Third and freshest take of the week on the 2026 Gartner Magic Quadrant for Enterprise Storage Platforms (NetApp among the six Leaders, alongside Dell, HPE, IBM, Pure and VAST). IT Channel Oxygen frames it as a buyer warning: Leader placement reflects completeness of vision and ability to execute at scale — not a procurement mandate — and shortlists should still be validated against audited benchmarks and workload-fit evidence. Sits alongside NetApp's official PR (No. 1 in Critical Capabilities for Hybrid Cloud Storage) and Blocks & Files' note that NetApp slipped from second place in this edition. For ONTAP estates the practical reading: MQ keeps NetApp on every enterprise shortlist, but the differentiators to actually verify are the AI-data claims (AI Data Engine, AFX) that Gartner weighs heavily.

Open source
News

FSx for ONTAP AWS how-to roundup (4 posts)

Source: AWS Storage Blog (via Google News) · **Date:** 2026-06-12 · **Category:** docs

AWS deep-dive on integrating this pattern directly with Amazon FSx for NetApp ONTAP — hands-on configuration detail administrators can replicate against their own FSx namespaces, useful as an alternative/extension to on-prem ONTAP procedure equivalents.

Open source
News

Evening flows: Legal & General opens NTAP stake; Man Group adds 142,261 shares

Source: MarketBeat via Google News · **Date:** 2026-08-27 · **Category:** news

The Thursday 13F-season flow tape stays one-directional: Legal & General Group Plc opened a fresh NTAP stake and Man Group plc bought 142,261 shares, extending the week's pattern of institutional accumulation into and after fiscal Q1 FY2027 earnings. Combined with today's earlier filings (Sanctuary Advisors, CIBC, Connor Clark & Lunn), the buyer base keeps broadening across quant and traditional managers — consistent with AI-storage-growth positioning rather than index-only drift.

Open source
AI

Domino Data Lab names Thomas Robinson CEO to lead AI solutions era

Source: PR Newswire via Google News · **Date:** 2026-08-27 (13:00 UTC) · **Category:** ai

Domino Data Lab — NetApp's enterprise-MLOps partner for hybrid data science platforms — promoted board chair Thomas Robinson to CEO with a mandate to scale its AI-solutions business. Domino's platform routinely rides NetApp storage backends (AIPod-adjacent reference designs, ONTAP data services for training sets and model artifacts), so leadership continuity with an AI-first strategy keeps the joint stack-to-platform motion intact. Relevant to NetApp watchers: partner-level execution is half the AI Data Engine story, and Domino remains one of the marquee software layers on top of it.

Open source
News

Community troubleshooting roundup (3 threads)

Source: NetApp Community (ZIJIAN ZHOU, Answered ✓) · **Date:** 2026-08-22 · **Category:** community/kb

Thread requests NetApp's retired KB covering DS4486 shelf H1/evacuation LED behavior after disk carrier swaps — resolved by the community pointing at archived access. Documents the classic DS4486 gotcha where carriers trigger shelf state churn post-replacement and why the KB was pulled into documentation retirement.

Open source
News

Community AI round-up: agentic workflows, lakehouses, agent-skill governance

Source: NetApp Community blogs/discussions · **Category:** community

NetApp's community team keeps producing genuinely useful agentic-AI material: the Part-3 series installment maps storage/data primitives onto agent runtime needs (tool grounding, governed retrieval, snapshot-backed rollback for agent actions); the AWS piece shows governed FSx/ONTAP file data feeding Amazon AI/analytics services without copying sprawl; the Starburst walkthrough designs federated lakehouse-on-ONTAP layouts for AI-scale queries; and the MCP-vs-Skills comparison decides when an MCP server or packaged skill is the right integration seam for ONTAP automation agents.

Open source
News

CGI taps NetApp Keystone to power block storage in its shared services platform

Source: StorageReview · **Date:** 2026-06-22 · **Category:** product

CGI adopted NetApp Keystone STaaS to deliver block storage through its shared-services platform, another proof point for subscription/consumption storage alongside the HCLTech-U4X AI storage pairing announced mid-August. Shows how integrators build multi-tenant offerings on NetApp hardware-as-a-service economics rather than buying arrays outright — relevant to MSP and hybrid-cloud sizing conversations.

Open source
News

AWS FSx for ONTAP how-to round-up #2

Source: AWS Storage Blog · **Category:** docs

Second batch of AWS Storage Blog FSx-for-ONTAP operations content: SSM/MGN-driven mount automation closes the post-migration gap most lift-and-shift guides leave open; quota management becomes the blunt-but-effective brake on shared-volume hoarding; the S&P Global DR writeup is the best recent public example of cross-region FSx snapshot replication doing real DR duty; Entra Domain Services integration documents the modern identity path for both FSx flavors side by side.

Open source
News

2026-08-28-oracle-goldengate-iceberg-netapp-s3

Source: Oracle Data Integration Blog · **Date:** 2026-08-27 · **Category:** ai

Oracle documents GoldenGate for Data AI 26ai replicating Apache Iceberg table data into NetApp S3 object storage — another sign Iceberg lakehouses are becoming a first-class target for enterprise replication pipelines, and a direct hook for NetApp's AI Data Engine / StorageGRID / ONTAP S3 story: governed Iceberg tables landing on NetApp object endpoints for downstream AI workloads.

Open source
News

2026-08-28-netapp-vs-vast-hybrid-cloud-ai

Source: NetApp Blog (via Google News) · **Date:** 2026-08-27 · **Category:** ai

NetApp's competitive positioning against VAST Data frames the choice as hybrid-cloud AI platform vs. scale-out flash appliance: ONTAP's universal data services, replication, governance and cloud-native integrations (plus AFX + AI Data Engine) versus VAST's DASE architecture. Useful competitive landscape context for the AI storage category and the enterprise AI data-layer debate.

Open source
News

2026-08-28-netapp-ai-data-engine-smart-data-blog

Source: NetApp Blog (via Google News) · **Date:** 2026-08-27 · **Category:** ai

A fresh NetApp Blog explainer on the AI Data Engine: discovering, securing, transforming and preparing enterprise data into AI-ready form across hybrid cloud — the pipeline-layer differentiator NetApp is betting on for enterprise AI, sitting on top of AFX/ONTAP storage and feeding NVIDIA-aligned training and inference stacks.

Open source
News

2026-08-28-nand-flash-2026-price-surge-strategies

Source: NetApp (via Google News) · **Date:** 2026-08-27 · **Category:** news

NetApp outlines six strategies for the 2026 NAND flash price surge — a practical capacity-planning piece for storage teams facing rising flash costs: tiering to capacity flash/object, dedupe/compression efficiency, reclaiming orphaned capacity, and procurement timing. Directly affects AFF/ASA refresh decisions and AI-storage budget planning.

Open source
News

2026-08-28-flex-unified-google-cloud

Source: NetApp Blog (via Google News) · **Date:** 2026-08-27 · **Category:** product

NetApp positions Flex Unified as its enterprise-grade storage offering for Google Cloud — extending the Flex brand (Flex Pod/axis) into Google Cloud with ONTAP data services underneath. Round out the hyperscaler picture: FSx for ONTAP (AWS), Azure NetApp Files (Azure), and now a Google Cloud storage play, relevant for multi-cloud AI estates that want consistent data services across all three clouds.

Open source
News

2026-08-27-techzine-sovereignty-cloud-ai

Source: Techzine Global · **Date:** 2026-03-23 · **Category:** ai

Techzine examines the tension AI creates between cloud economics and data sovereignty: regulated sectors want sovereign, audit-traceable AI pipelines, which favors hybrid deployments where ONTAP estates retain control while cloud resources burst for training — the positioning behind NetApp's sovereign-cloud partnerships.

Open source
News

2026-08-27-sktelecom-netapp-vms-ai

Source: Tech in Asia · **Date:** 2026-06-24 · **Category:** ai

Tech in Asia covers SK Telecom and NetApp jointly testing AI workloads inside virtual machines rather than bare-metal GPU clusters — validating that virtualized infrastructure can host AI training/inference where flexibility and consolidation matter more than peak GPU utilization, keeping AI data next to governed enterprise storage.

Open source
News

2026-08-27-register-exec-comp-34m

Source: The Register · **Date:** 2026-07-29 · **Category:** news

The Register reports NetApp's newest executive signing received a $34 million compensation package — part of ongoing leadership reshuffles as the company rides its AI-driven stock highs. Typical Register candor on executive pay trends across the storage industry's AI windfall period.

Open source
News

2026-08-27-openshift-vm-backup-speedup

Source: Blocks & Files · **Date:** 2026-05-13 · **Category:** product

Blocks & Files covers NetApp Astra Control/ONTAP tooling updates delivering faster virtual-machine backup and DR for Red Hat OpenShift (OpenShift Virtualization included). Tray-level VM consistency plus snapshot-backed restores target the growing KubeVirt crowd needing production-grade data protection without leaving their Kubernetes platform.

Open source
News

2026-08-27-goldman-top-hardware-picks

Source: finance.biggo.com citing Goldman research · **Date:** 2026-08-12 · **Category:** news

Goldman Sachs' analyst team names NetApp among its top hardware picks benefiting from the AI infrastructure spend cycle, alongside Dell and HPE — validation that sell-side sees AI-driven storage demand (all-flash, AI factories, inference capacity) translating into sustained NTAP revenue growth.

Open source
News

2026-08-27-everpure-public-cloud

Source: Techzine Global · **Date:** 2026-08-12 · **Category:** news

Competitive-watch piece: Everpure (top-ranked vendor in recent Gartner Magic Quadrant chatter) attacks the hyperscaler-native storage space where Azure NetApp Files previously gave NetApp its foothold. Notes both vendors chasing FSx-for-ONTAP-style native services and what pressure means for enterprise pricing on cloudy file shares.

Open source
News

2026-08-27-elastio-commvault-deals

Source: Blocks & Files · **Date:** 2026-03-25 · **Category:** news

Blocks & Files details two resilience deals: Elastio's malware-scanning-before-restore technology pairs with NetApp backup targets, while an expanded Commvault relationship tightens tape-integrated ransomware recovery workflows over ONTAP snapshots — both strengthen the case for NetApp arrays as the protected core of cyber-recovery architectures.

Open source
News

2026-08-27-crnasia-platform-update-ai

Source: CRN Asia · **Date:** 2026-04-15 · **Category:** product

CRN Asia recaps NetApp's data platform refresh aimed squarely at AI data problems: the updates bring wider data pipeline support, AFX/AI Data Engine integration steps, and expanded NVIDIA certifications across regions — giving channel partners in APAC the building blocks to stand up AI-ready unification on single namespace storage.

Open source
News

2026-08-27-crn-ceo-ai-interview

Source: CRN · **Date:** 2026-02-02 · **Category:** ai

Evergreen CRN interview with NetApp's CEO covering the company's biggest AI challenges: helping customers move AI projects from pilot to production, investment priorities around intelligent data infrastructure, NVIDIA-aligned partner motion (AIPod, AI Data Engine), and how partners should position storage as the unlock for enterprise GenAI.

Open source
News

2026-08-27-advisory-aug21-batch-ext

Source: security.netapp.com advisories API · **Date:** 2026-08-21 (surfaced today) · **Category:** advisory

The Aug 21 interim batch extends beyond the fifteen already recorded: five additional Samba vulnerabilities joined it — CVE-2026-58216, CVE-2026-58218, CVE-2026-58221, CVE-2026-58222, CVE-2026-58224, CVE-2026-6726, CVE-2026-6727, CVE-2026-6949, CVE-2026-73281, CVE-2026-73282, CVE-2026-73283 (CVE-2026-6949, CVE-2026-58224, CVE-2026-58222, CVE-2026-58221, CVE-2026-58218). All follow the same pattern: upstream Samba fixes affecting ONTAP integrations and tools shipping Samba; check each advisory for affected-product lists and workarounds. Administrators running SMB/CIFS shares with Samba-linked components should confirm their protection status via the API.

Open source
AI

Nutanix reports Q4 FY26: $757.1M revenue, $2.55B ARR, strong free cash flow - TradingView

Source: Google News RSS

Nutanix reports Q4 FY26: $757.1M revenue, $2.55B ARR, strong free cash flow - TradingView — coverage in the NetApp AI ecosystem: google news feed item dated 2026-08-26. Relevant to the NetApp AI priority: tracks AI infrastructure partnerships, AIPod deployments, BlueXP/AI Data Engine, NVIDIA integrations, and competitive AI storage market positioning (NetApp vs Nutanix, Pure, Vast). Adds to the NetApp Black Box AI knowledge base for cert exam context (NCIE-AI, NCDA) and site visitors researching NetApp's AI strategy.

Archive digest
AI

NetApp stock trades close to analyst fair value as AI guidance lifts long-term EPS outlook - AD HOC NEWS

Source: Google News RSS

NetApp stock trades close to analyst fair value as AI guidance lifts long-term EPS outlook - AD HOC NEWS — coverage in the NetApp AI ecosystem: google news feed item dated 2026-08-26. Relevant to the NetApp AI priority: tracks AI infrastructure partnerships, AIPod deployments, BlueXP/AI Data Engine, NVIDIA integrations, and competitive AI storage market positioning (NetApp vs Nutanix, Pure, Vast). Adds to the NetApp Black Box AI knowledge base for cert exam context (NCIE-AI, NCDA) and site visitors researching NetApp's AI strategy.

Archive digest
AI

NetApp PR: Leader in 2026 Gartner MQ — and No. 1 for Hybrid Cloud Storage in Critical Capabilities

Source: NetApp press release via TMCnet (ES mirror) — https://www.tmcnet.com/usubmit/2026/08/26/10436065.htm

NetApp's official statement confirms it was named a Leader in the 2026 Gartner Magic Quadrant for Enterprise Storage Platforms — a placement it has held since the report's first edition in 2025. The companion 2026 Gartner Critical Capabilities for Enterprise Storage Platforms ranks NetApp **first** in the Hybrid Cloud Storage use case and second in Hybrid Platform Services, which NetApp attributes to native integrations with the major public clouds plus a unified control plane. The AI angle: NetApp frames its platform as an intelligent, governed foundation that exposes AI-ready data where it lives — connecting to AI ecosystems via secure hybrid multicloud storage and feeding unstructured data to AI workloads "without costly data movement." President César Cernuda reinforced the consistency-of-leadership message. This fills out the official-PR side of the MQ story that Blocks & Files covered on Aug 24 (NetApp repositioned mid-quadrant behind Huawei/HPE while staying a Leader).

Open source
AI

NetApp Named a Leader in the 2026 Gartner® Magic Quadrant™ for Enterprise Storage Platforms - NTB Kommunikasjon

Source: Google News RSS

NetApp Named a Leader in the 2026 Gartner® Magic Quadrant™ for Enterprise Storage Platforms - NTB Kommunikasjon — coverage in the NetApp AI ecosystem: google news feed item dated 2026-08-26. Relevant to the NetApp AI priority: tracks AI infrastructure partnerships, AIPod deployments, BlueXP/AI Data Engine, NVIDIA integrations, and competitive AI storage market positioning (NetApp vs Nutanix, Pure, Vast). Adds to the NetApp Black Box AI knowledge base for cert exam context (NCIE-AI, NCDA) and site visitors researching NetApp's AI strategy.

Archive digest
News

NetApp AI evergreen items — batch 3 (NetApp.com source pages)

Source: AWS/NetApp guide (via Google News) · **Date:** 2026-04-24 · **Category:** ai

Hands-on config for exposing FSx for ONTAP file data through S3 Access Points so Bedrock/analysts' AI tooling can run against enterprise NAS datasets — bridging NFS/SMB admin territory to AI analytics consumers.

Open source
News

NetApp AI evergreen items — batch 2

Source: Original source

NetApp, 28 Mar 2026 — https://news.google.com/rss/articles/CBMiT0FVX3lxTE85M0I0RnNNbmVXbG9UNlBxT05DN21fTk1uaTBjdDhlbUthNkhJbjZXUldIdjJ3bGN2dVh4c0tpcW5OUkwwNGtxUjY1Mm9TNlU?oc=5 Competitive positioning piece arguing hybrid-cloud AI data platforms (ONTAP estates + cloud burst) beat all-cloud rivals on governance, cost, and data gravity.

Open source
News

Earnings-day preview roundup: NTAP fiscal Q1 FY2027 due today

Source: Original source

Three independent previews landed this morning ahead of today's quarterly report: - Yahoo Finance ("NetApp (NTAP) Earnings Expected to Grow"): analysts model year-over-year growth, consensus beat expected — https://news.google.com/rss/articles/CBMioAFBVV95cUxOUHpaR01Wb1l3STJIOC1XNW56R0JEdmNTM1hWN0NjcGVVaUJqcFd0WDRFRVF0M2xKVjBBNzdLWF9lQ2dobG1ZeGJfYTJsLUlQaVRFbTE1clVGREV5c0pjSlBFOUktcWdldUswVnJJZzhqdEU4QTE5SEVXVDlMVGFMc01ac2t6Qi1Gd3psRlF6SS1tRjVkZGk5QXFwWDhreU5V?oc=5 (2026-08-26 14:00 UTC) - Investing.com ("NetApp shares may move 9.7% on upcoming earnings report"): options/history imply a ~9.7% weekly move on the print — https://news.google.com/rss/articles/CBMiwAFBVV95cUxPaUxHekhkMk5sYnhwRUxMME1sTE8xR0d5bi1sdHdLc2pUdlBFS1A1UVRGSVJyTEI2QlhoNFNrVjlaT3FBV0NjYzJuaUdPYjgtbWo4bDRUdV9SODYzdVRoYzJNM1lOV1E4bjZvSDNMOGF1b1RfTVBScnJLaFFZNVE4NGRScUJSTEUxT2JzMkd1UnFmR0YyUm5JVTNqelI0b2NQRHRvUWVEVDdxaVBLU09YQmFaM3ppVkZvcWxmQ1RqVk4?oc=5 (14:32 UTC) - MarketBeat ("Expected to Post Quarterly Earnings on Wednesday"): confirms Wednesday-after-close timing — https://news.google.com/rss/articles/CBMiwAFBVV95cUxNNjhoZC1ud0UwdXlpTmRTRmY0UHY4VUdZQWstWndCRkJtS1JjVlp3dGYwZ3Zxd25EZHhmT1IwMGZsVGVURFNtTDNwZmxkR0lfYWUxc2pfWmNjMWNLUHJCUnFOQ2JkTHZQaGNlQjdYc1c4WF9WLXhTdkFzM3NjUlhLdlB0YXppMWVIZDQzNFBzYkZKeHVRZEVhRzhHYTExbTh4TnplaW5SbGRwdFpYMzNvcmZXa0ZBVWdDMWtLal9la04?oc=5 (06:19 UTC)

Open source
AI

Designing for agentic AI with open source tools (NetApp)

Source: https://www.netapp.com/blog/designing-agentic-ai-open-source-tools/

NetApp engineering blog on building agentic AI stacks with open-source components (LangChain, LlamaIndex, MCP servers, ONTAP) and where NetApp slots in: data layer, vector store, audit and governance. Includes a reference diagram showing how an agent can call ONTAP primitives (snapshots, clones, SnapMirror) through MCP without bespoke integrations.

Open source
Advisory

CVE-2026-3644 Python Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0020 (2026-08-26) (interim — details may evolve) covering CVE-2026-3644. The advisory affects Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Management Services for Element Software and NetApp HCI. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-34282 Java Platform Standard Edition Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260429-0011 (2026-08-26) (interim — details may evolve) covering CVE-2026-34282. The advisory affects Data Infrastructure Insights and Data Secure Storage Workload Security Agent, NetApp Console Agent, OnCommand Insight. Fix status: 1 fix entries. Impact: Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-33939 Handlebars.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0008 (2026-08-26) (interim — details may evolve) covering CVE-2026-33939. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-32597 PyJWT Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0010 (2026-08-26) (interim — details may evolve) covering CVE-2026-32597. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Docs

2026-09-05-kb-okm-passphrase-hardware-replacement

Source: https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/Misplaced_or_Forgotten_OKM_Passphrase_During_Hardware_Replacement

Recovery procedure for clusters whose Onboard Key Manager (OKM) passphrase was lost or never recorded during a controller / NVRAM / DIMM replacement. Walks through using `security key-manager onboard show-graphics` (modern) / `security key-manager onboard sync` and the OKM card / companion CLI to restore the passphrase against the OKM database, with explicit warnings that mis-typing the passphrase silently re-keys storage and locks out data access if fewer than the quorum of cards are still present. Important reference for any field engineer replacing an AFF/FAS head where NSE/NAE volumes exist — losing the OKM passphrase with no backup is unrecoverable without engaging NetApp TAC.

Open source
News

2026-09-03-netapp-named-leader-2026-gartner-mq-enterprise-storage

Source: https://news.google.com/rss/articles/CBMi8wFBVV95cUxQUWFtdTh2WWZuYUxHR055SzE4Y0hiUVdEY0Q1bDNSWlJBWGRJM1R6dVdXQ0FxMGoycU5aVUpWdDIxW

NetApp was positioned as a Leader in the 2026 Gartner Magic Quadrant for Enterprise Storage Platforms. Recognized for ONTAP One, all-flash AFF/AFF-C and ASA portfolios, BlueXP data management, and AI-ready storage capabilities (AIPod, DataPelago). Useful market-context citation for storage admins evaluating NetApp versus competitors in primary block/file/object storage selection.

Open source
AI

NetApp stock trades near 12-month high on AI-driven guidance and analyst targets

Source: Ad-hoc-news (via Google News)

NTAP trades near its 12-month high as guidance and a wave of analyst price-target increases point to strong AI-driven storage demand. The piece ties the momentum to enterprise AI infrastructure spending lifting NetApp's all-flash and AI Data Engine pipeline.

Archive digest
AI

NetApp and Cisco Expand FlexPod With Validated AI Architectures (StorageReview)

Source: https://www.storagereview.com/2026/08/netapp-cisco-expand-flexpod-validated-ai-architectures/

StorageReview coverage of the expanded FlexPod AI reference architectures co-developed by NetApp and Cisco: validated combinations of UCS X-Series, NVIDIA HGX/HGX-B200 GPU pods, ONTAP AI / EF-Series storage tiers, and Splunk SOAR storage-response automation. Adds new reference architectures for inference and RAG alongside the existing training architectures.

Open source
Advisory

CVE-2026-60005 NGINX Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260730-0010 (2026-08-25) (interim — details may evolve) covering CVE-2026-60005. The advisory affects NetApp Console Agent Container (static-file-server). Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-42533 NGINX Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260724-0001 (2026-08-25) (interim — details may evolve) covering CVE-2026-42533. The advisory affects NetApp Console Agent Container (static-file-server). Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-4046 GNU C Library (glibc) Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260422-0003 (2026-08-25) (interim — details may evolve) covering CVE-2026-4046. The advisory affects Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP tools for VMware vSphere 10. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-27448 pyOpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260717-0013 (2026-08-25) (interim — details may evolve) covering CVE-2026-27448. The advisory affects NetApp Data Classification. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
News

Pre-earnings stock chatter: NTAP outperforms, GF Value gap, AI-guidance optimism

Source: MarketWatch (via Bing News/MSN) · GuruFocus · Ad-hoc-news.de

Trailing items ahead of the fiscal Q1 FY2027 report due Wednesday after close: MarketWatch auto-trackers had NTAP outperforming sector peers on both Aug 24 and Aug 26 sessions. GuruFocus's valuation note flags a wide spread — price $193.85 after a 3.4% day versus its GF Value estimate of $121.17 — implying the market is paying well above historical value multiples on AI-storage growth expectations. Ad-hoc-news.de echoes the theme twice (Aug 25–26), saying analysts' fair-value models still sit below spot because guidance already embeds AI-driven EPS lifts into FY2027. No operational impact; watch for actual results in the next run.

Archive digest
News

Will NetApp (NTAP) Beat Estimates Again in Its Next Earnings Report?

Source: Yahoo Finance

Yahoo Finance previews NetApp's upcoming quarterly earnings, noting the company has beaten consensus estimates in recent quarters and examining whether accelerating AI-driven all-flash demand can sustain that streak. The piece highlights analyst expectations around enterprise AI storage deployments as a key growth driver heading into the print.

Open source
AI

NetApp unveils next-gen EF-Series arrays & AI data platform (SDxCentral)

Source: https://www.sdxcentral.com/news/netapp-unveils-next-gen-ef-series-arrays-ai-data-platform-to-solve-enterprise-bottlenecks/

SDxCentral coverage of NetApp's next-generation EF-Series all-flash arrays alongside the AI Data Engine orchestration layer: targets enterprise AI storage bottlenecks with GPUDirect Storage on EF for hot training data and AI Data Engine for embedding pipelines. Positions the combo against Pure Storage, VAST Data and WEKA in the enterprise AI primary-storage tier.

Open source
AI

NVIDIA and 121 firms form Open Secure AI Alliance — NetApp a founding member

Source: https://www.frontier-enterprise.com/nvidia-121-firms-form-open-secure-ai-alliance-for-ai-safety-and-security/

NVIDIA has formed the Open Secure AI Alliance for AI safety and security together with 121 companies, and NetApp is listed among the founding members alongside peers like HPE, IBM, Intel, Lenovo, Microsoft, Nutanix, Red Hat, Rubrik, SAP, and Snowflake. The alliance focuses on secure AI supply chains, safety standards, and interoperability for enterprise AI deployments. NetApp's inclusion underscores its positioning of ONTAP/AI Data Engine infrastructure as a trusted data foundation for regulated enterprise AI.

Open source
AI

NVIDIA + 121 Firms Form Open Secure AI Alliance — NetApp Among Founding Members

Source: Frontier Enterprise

NVIDIA and 121 companies have formed the Open Secure AI Alliance for AI safety and security, with NetApp listed alongside Nutanix, Palo Alto Networks, Okta, Nokia and others as a member. The alliance focuses on secure AI supply chains, safety standards, and cross-vendor guardrails — relevant to NetApp's secure enterprise AI data infrastructure positioning (AFX, AI Data Engine, ONTAP cyber resilience).

Open source
AI

Indian IT Leaders Shift Focus to Secure AI Integration

Source: Whalesbook

Whalesbook reports that Indian IT services leaders are pivoting toward secure AI integration, citing secure-by-design AI data infrastructure from vendors including NetApp. The piece reflects the same enterprise demand NetApp is targeting with its AI Data Engine and intelligent data infrastructure positioning in fast-growing markets like India (INSIGHT Xtra Mumbai).

Open source
News

Gartner Weaves Enterprise Storage Magic Spells — Again

Source: Blocks & Files

Blocks & Files reviews the latest Gartner Magic Quadrant for enterprise storage platforms, with NetApp positioned among the long-running Leaders alongside Pure Storage, Dell, and HPE. The piece discusses how AI data infrastructure demands and cyber resilience are reshaping vendor positioning in the quadrant.

Open source
News

Gartner Enterprise Storage MQ 2026: NetApp Still a Leader, But Repositioned

Source: Blocks & Files

Gartner's 2026 Enterprise Storage Magic Quadrant names six Leaders: Everpure (renamed Pure Storage), Huawei, HPE, NetApp, Dell and IBM, with no Challengers, Hitachi Vantara as a Visionary and IEIT Systems (ex-Inspur) as a Niche Player. Notably, NetApp — second place in 2025 — has been repositioned behind Huawei and HPE this year, with Everpure highest on both ability to execute and completeness of vision. NetApp remains a Leader despite the slide, keeping it in the top tier for enterprise block/file storage alongside its AI-infrastructure push.

Open source
News

Forrester Object Storage Wave: NetApp StorageGRID among Leaders

Source: Blocks & Files

Forrester's new object storage Wave names NetApp (StorageGRID), Everpure, Nutanix, and VAST Data as leaders, with Dell, Scality, AWS, Hitachi Vantara, HPE, and Huawei as strong performers; Cloudian and MinIO were left out entirely. A notable third-party validation point for StorageGRID as AI/data-lake object storage.

Open source
News

Dell, NetApp, HP Face Toughest Near-Term Earnings Setups, Morgan Stanley Says

Source: MarketScreener (citing Morgan Stanley)

Morgan Stanley flags Dell, NetApp, and HP as having the most challenging near-term earnings setups among hardware names, citing elevated expectations after strong runs. For NetApp this contrasts with other analysts' bullish AI-storage thesis — a useful counterweight data point for tracking sentiment around NTAP's next report.

Open source
Advisory

CVE-2026-42945 NGINX Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260522-0011 (2026-08-24) (interim — details may evolve) covering CVE-2026-42945. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22801 Libpng Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260130-0011 (2026-08-24) (interim — details may evolve) covering CVE-2026-22801. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
News

Building Powerful Solutions at World Wide Technology

Source: NetApp Newsroom

NetApp's newsroom spotlights its partnership with World Wide Technology (WWT), covering how the systems integrator builds joint solutions on NetApp storage for enterprise customers, including modern data infrastructure and AI-ready architectures. Useful background on NetApp's channel/go-to-market ecosystem.

Open source
News

NetApp at Morgan Stanley TMT Conference — Transcript Published

Source: GuruFocus

GuruFocus published the full transcript of NetApp's appearance at the Morgan Stanley Technology, Media & Telecom Conference. Useful primary-source material for management commentary on enterprise storage demand, AI infrastructure positioning, and all-flash momentum ahead of fiscal Q1 results.

Open source
AI

NetApp and Cisco Expand FlexPod AI Architecture for Enterprise Generative AI

Source: https://news.google.com/rss/articles/CBMifEFVX3lxTE93UU9DUzlZS2NwdEVPc2hGSkZlV1p3c1J0cFlwVnZzN2F0d0x4eGFzVmp6VG01cE9FSlZtdTRaWlA0bk5xRmhXSW9rNk1lNVZ5c0lXbENQYVFtS0t4c3dKVTl5QzI1dmFkdmR4a19xak1aRDRWUk82WVd6cFRJTXhEekl4R3Zkd3E2c3NfTEZ3?oc=5

NetApp and Cisco expanded their joint FlexPod portfolio with dedicated FlexPod AI validated designs tailored for enterprise generative AI and LLM model fine-tuning. Combining Cisco UCS servers, NVIDIA enterprise GPUs, Cisco Nexus networking, and NetApp AFF A-Series / C-Series storage running ONTAP, the validated reference architecture eliminates guesswork in provisioning high-throughput storage pipelines for GPU clusters. Enterprises gain end-to-end telemetry and lifecycle management across compute and storage fabrics.

Open source
News

NetApp Named a Washingtonian 50 Great Places to Work

Source: https://news.google.com/rss/articles/CBMiqwFBVV95cUxNY2NETTJqaUxnejRDcldJOXV1YUVTRXNPWjFKVWdNS2U4N0xLT1lCajZ4cmxIZzBGNTcwRDhPYXpYREhuUjdRaldzbmxXYmp1S1I3MEl5QTdZdC1VYm1pV3ByaGNDdFIxTlpUUVRaNC1Ha3hhS2xwTVRjdWFDOVA5Qk1zSjI1WnZTbUhGVUVWNHhTV0ZpNDhkNmlxaEtXbW9PNHIwMVNodGVfQkU?oc=5 (via WashingtonExec)

NetApp was recognized in Washingtonian Magazine's "50 Great Places to Work" list, reflecting on its corporate culture across its Reston, VA-area and broader US operations. A light employer-branding item rather than product news, but useful for the company-culture side of the story.

Open source
AI

NetApp Goes All-In on AI Infrastructure (iTWire)

Source: https://itwire.com/business-it-news/data/netapp-goes-all-in-on-ai-infrastructure%2C-and-the-numbers-back-it-up-202603201420

iTWire analysis of NetApp's AI infrastructure strategy: full-stack AI data infrastructure combining AIPod, EF-Series, ONTAP, AI Data Engine (post-DataPelago acquisition), and StorageGRID. Frames NetApp as a 'picks-and-shovels' play for the enterprise AI build-out, with the AI Data Engine orchestrator as the primary differentiator versus Pure Storage and VAST.

Open source
AI

NetApp Acquires DataPelago to Tackle Enterprise AI Data Engine Bottlenecks

Source: https://news.google.com/rss/articles/CBMioAFBVV95cUxQeVZDM0E5RV9BWGFQYXZua0loSVJsQjhmdk1sV0J3eFBkQkt5M0l2OUNmR19uM1pDNE9YOGdMckNnNXBjUXF0ekd6aHhaT295QldpSGl3c2k3UWl0N1VzRjV1dVRaRWRiY1Ezb2gxdlF4Yk4wZ1lJOGZ3Mkh1S1VnTW5pdkF6N2M3N2c?oc=5

NetApp announced the acquisition of DataPelago, integrating its sub-second data processing engine directly into NetApp Intelligent Data Infrastructure and AFX systems. By enabling hardware-accelerated, zero-copy data extraction and vector indexing at the storage layer, the technology eliminates GPU starvation and accelerates data preparation pipelines for enterprise RAG and agentic workflows.

Open source
AI

NetApp AIPod Mini with Intel: Simple and Secure Edge AI & RAG

Source: https://news.google.com/rss/articles/CBMipAFBVV95cUxNU3REMDNZWTE2OWNsaFMzelpPdEUwYzVHWXlzS0NXYVpWZlduVTlHVVVObmtQSUs0aHFjOFNNOVpOTm9lem5Nbkt3ZW41UVRiNEx2MWRlME56UlU4T3l1YmljR3dBcWtDLVd6ZmdPNEI4LXV4MnBPVFc2UXJpV3JOSVpscFRyV1J6VEhlUllJQTlIOXlqYThGeDh4Y2E3TkI4NnRtYw?oc=5

NetApp detailed its AIPod Mini with Intel architecture, designed to make generative AI inferencing and Retrieval-Augmented Generation (RAG) accessible, cost-effective, and secure for departmental and edge deployments. The turnkey stack pairs Intel Xeon processors and Gaudi accelerators with NetApp AFF all-flash arrays running ONTAP. Key benefits include unified data management via NetApp BlueXP, built-in ransomware protection with Autonomous Ransomware Protection (ARP), and seamless data synchronization from core data centers to edge locations.

Open source
News

NetApp AI evergreen blog/docs items (previously unswept)

Source: Original source

NetApp Blog, 16 Mar 2026 — https://news.google.com/rss/articles/CBMihAFBVV95cUxQWDJ3TEw5ZFNCNlFwLUp3dTR1VExqa0ZqUEJ4QlZlMHhJUXVhRVJNTmZxelVNS25nVUwxOWFFaUk5SnpLT0UxX0tGaldZbDdTb0JjMkxUaTlEVGs0RnpwSmxuRDlsSDRMRjRVN0pZUVZBcDhyeGtsLVBzZFVpaXVrSkN6aTY?oc=5 Explains how AI Data Engine metadata-driven indexing/curation activates enterprise data for RAG and agentic AI directly from ONTAP estates.

Open source
AI

NetApp AI Data Engine: Architecture for Enterprise Generative AI & Agentic Pipelines

Source: https://news.google.com/rss/articles/CBMirgFBVV95cUxPSDRpQ1JrQWZHdF9FX2UzYndjbGtUenNqYVRRUlkySE1OODN6QWF0Y3laT1VmdkZqU1pUcmM1cDVqUDFuM0l6OHQ0QkhfLWtfRHNyTk1uVkhkME9fN21PVE44VG5ZOW5pTG54QjV5QjRmd3p6YVlYblV1QkZhc2Uxb2t4QUZkSGt1Y0Mwb3Y4dw?oc=5

NetApp unveiled architectural blueprints for the NetApp AI Data Engine, integrating ONTAP multiprotocol storage (NFS, NVMe-oF, S3) with NVIDIA AI Enterprise and NeMo Retriever. The architecture provides automated metadata indexing, policy-based data cleansing, Autonomous Ransomware Protection snapshots, and secure vector store synchronization for enterprise multi-agent workflows.

Open source
AI

Iterate.ai Partners with NetApp for Turnkey Enterprise Private AI

Source: https://news.google.com/rss/articles/CBMi_gFBVV95cUxON2t6UUl6UnJXclVfTWdxZERXWG9Pb3ZqRVU2N3FfUzhPTTFFVnBSTUZGVHF2STdUOHVrZjZJa1BSeFhPdHQ2SkhoQ0tWUVVrZmo4a3FjVFRwNHhUVDd3VWkyT2NNWXJkemVxRy1VTGNXSVloVTk5SXV6Z2duSDM0TEZBWTN6NzhvdmtCTFBNSzdPNm5KcEpXNXFZSXpRQXQxSWRpUmtuYkxacnJWZFBHeF95czFvNm5OaHRINDNVanBIZEw4ZDBWdGlGYmNnQTJ5Zzh1X0hHcmY0NXJGaUFnUkFncnVMQ3JhOXE4UnREQXVXNnFYU0FZWC1ZUkZGdw?oc=5

Iterate.ai announced a strategic alliance with NetApp to deliver turnkey private AI solutions for enterprise environments. The collaboration integrates Iterate.ai's Generate low-code platform with NetApp's Intelligent Data Infrastructure, allowing organizations to deploy custom AI agents and enterprise RAG without exposing sensitive proprietary data to external cloud services. The combined stack leverages ONTAP's multi-protocol storage, snapshot immutability, and unified management through BlueXP.

Open source
AI

HCLTech Pairs NetApp Keystone With U4X to Sell Enterprise AI Storage by Consumption

Source: https://news.google.com/rss/articles/CBMiugFBVV95cUxNaU9McTNJZGtNeEFhMXhmY3JMTVNrcExmSnJpUjV2WHRXN3VFVVRtT0F3UWZ4bW90c2Fvd1F6cmtwcG9lWnFzNFFtQWd4S1lXWlVwTXB5cllWdEhhZ09jUGVqVzQ3TWZod3l3Z2l4bUZsMUpUa1d4T1hkcTF0T3ZDTm9lUXpQUkF3Z0lSNTFn?oc=5

HCLTech integrated NetApp Keystone STaaS (Storage-as-a-Service) with its U4X enterprise AI framework, delivering consumption-based storage for GPU clusters and generative AI inference workloads. The solution offers scalable ONTAP all-flash storage with zero upfront CapEx, providing automated QoS, tiering to object storage, and built-in cyber resilience for enterprise LLMs and agentic deployments.

Open source
News

Evercore ISI raises NetApp price target to $210 from $170

Source: MarketScreener

Evercore ISI lifted its NTAP price target to $210 from $170, extending a run of post-earnings analyst upgrades citing enterprise storage demand and NetApp's AI-adjacent all-flash momentum. Continues the bullish analyst streak already tracked this week (Citi, Oppenheimer).

Open source
AI

NetApp snaps up DataPelago to bolster AI data infrastructure (IT Pro)

Source: https://www.itpro.com/business/acquisition/netapp-snaps-up-datapelago-to-bolster-ai-data-infrastructure-portfolio

IT Pro coverage of NetApp's acquisition of DataPelago: positions the deal as accelerating NetApp's full-stack AI data infrastructure portfolio by adding DataPelago's GPU-accelerated unstructured data processing to the AI Data Engine. Frames the acquisition alongside Pure Storage's earlier moves and VAST Data's positioning as the new AI data infrastructure triad.

Open source
News

NetApp Stock Holds Near 52-Week High After Guidance

Source: Ad-hoc-news.de

NTAP continues to trade near its 52-week high following its raised fiscal 2027 outlook, with AI-driven storage demand cited as the key driver — consistent with the recent run of bullish analyst notes (Citi, Oppenheimer, Goldman Sachs).

Open source
AI

AI Data Volumes May Outweigh Revenue Deflation for IT Sector by FY30 — Report

Source: https://news.google.com/rss/articles/CBMi3wFBVV95cUxNUTZoYjB6TjhQYm1zanpEOG1NV3hLUW1iT1FzeFZMd0xPdGJiQ3c3dlRUS240WHJyVTlfTEl6MENKUWZwU1hpZ3c3UDBJTlo5X19oOHlnTDBKTFdXenNOd0VVUEU0Y1o0R0h6dENTRWVyYXpLMHBTNlhfdU5BQWVldTlCX2xzZ0x1SFJZb0dUQ1VnNFVOTlhYZm5vQ0pPYmRONjBFU21KUWIxVmJHZFZrNXNfTEgxb0xJd0RBSHBZVnJGXzNTNFBneFoyZGdXX0h4U01Xb3dObjhoQWcxMzBr?oc=5 (The Economic Times)

An Economic Times summary of an industry report argues that exploding AI data volumes will offset revenue deflation across the IT/storage sector by FY2030. Storage vendors with AI-oriented data platforms — NetApp's Intelligent Data Infrastructure and ONTAP AI positioning included — are cited as beneficiaries as enterprises stand up AI-ready storage estates. Reinforces the demand thesis behind NetApp's AI storage push.

Open source
News

What CIOs are learning with AI projects and AI outcomes (NetApp blog)

Source: https://news.google.com/rss/articles/CBMiYkFVX3lxTE12QW0yUTJsblBoSVlTbWtJSmZfWGo4b0wtTDF3di13V1JUS2d5V3ljYmFPMWJSeE5kX19VQnY4M2NMREZzZkpXYTR3SUprYmswNDdpU05YWUYtV2cwOHlVZ2hn?oc=5

NetApp blog post summarizing CIO lessons from enterprise AI projects: data readiness, infrastructure fit, and outcomes measurement. Useful context for the AI-storage angle (AFF/ASA, Azure NetApp Files, Keystone for AI pipelines).

Open source
AI

What CIOs are learning with AI projects and AI outcomes (NetApp Blog)

Source: NetApp Blog (Kris Cornwall)

NetApp blog piece arguing the gap between AI ambition and measurable impact is widening: enterprises remain stuck in pilots because programs aren't trusted, secure, or built to scale. Roundup of digital-transformation and AI-governance leaders on what CIOs must relearn — data readiness long before model deployment. Reinforces NetApp's intelligent-data-infrastructure-for-AI positioning.

Open source
AI

What CIOs Are Learning with AI Projects and AI Outcomes (NetApp Blog)

Source: NetApp Blog

NetApp blog post on what CIOs are learning as AI projects move from pilot to production: unified data, secure infrastructure, and scalable operating models drive AI success across industries. Covers lessons on data readiness, governance, and measuring AI outcomes — a good practitioner-oriented companion to the AFX/AI Data Engine story.

Open source
News

StorageReview on the 2026 Gartner MQ: Six Leaders Hold, NetApp Mid-Quadrant

Source: StorageReview — https://www.storagereview.com/news/gartner-magic-quadrant-for-enterprise-storage-2026-everpure-tops-both-axes-again-as-the-six-lea

StorageReview's analysis of the 2026 Gartner Magic Quadrant for Enterprise Storage (report dated Aug 19, positions as of July 2026) confirms the same six Leaders as last year — Everpure highest on both axes for a second straight year, Huawei second in ability to execute, HPE strongest of the rest — with NetApp and Dell clustered mid-quadrant and IBM rounding out the Leaders. Its NetApp year-in-review cites the extended FlexPod AI validated designs with Cisco (June 2026), sovereign air-gapped ONTAP deployments taken to Google Cloud, and its ASA block-only ONTAP deep dive as the platform's reference material. Site entry added to complete source coverage alongside the Blocks & Files and SDxCentral takes already collected.

Open source
AI

SAP, Progress and NetApp Race for AI Data Layer as Inference Spending Hits $23.3 Billion - InfotechLead

Source: Google News RSS

SAP, Progress and NetApp Race for AI Data Layer as Inference Spending Hits $23.3 Billion - InfotechLead — coverage in the NetApp AI ecosystem: google news feed item dated 2026-08-21. Relevant to the NetApp AI priority: tracks AI infrastructure partnerships, AIPod deployments, BlueXP/AI Data Engine, NVIDIA integrations, and competitive AI storage market positioning (NetApp vs Nutanix, Pure, Vast). Adds to the NetApp Black Box AI knowledge base for cert exam context (NCIE-AI, NCDA) and site visitors researching NetApp's AI strategy.

Archive digest
AI

SAP, Progress and NetApp Race for AI Data Layer as Inference Spending Hits $23.3 Billion

Source: https://infotechlead.com/artificial-intelligence/sap-progress-and-netapp-race-for-ai-data-layer-as-inference-spending-hits-23-3-billion-97914

SAP, Progress, and NetApp are all positioning as the enterprise "AI data layer" as worldwide inference spending reaches an estimated $23.3 billion. For NetApp this validates its Intelligent Data Infrastructure / AFX + AI Data Engine push: whoever governs and serves the data estate wins the AI workload.

Open source
AI

SAP, Progress and NetApp Race for AI Data Layer as Inference Spending Hits $23.3 Billion

Source: InfotechLead via Google News — https://news.google.com/rss/articles/CBMi2AFBVV95cUxPOUQ0N3JjMkdmWHVQVmdCSlRsMkdnNVhZV0Nqc2stVjJNaHZnZl9ZODlyQlRmdng2YURJRzBkR3pnSmVfQk9TLUJWQ3NUblBPS2VFRzFzNlM0TkVJWkxWZmtuZnd2aEszd2lMbWhOaWFjNW4zaTMxbzF0VUZZZVFxMDVOYnkwRm5PNThUVW1VQ3VsSkE2V05KM09YS3VPWnl6dGZlT1NnWEZ2ajNyV0NfM2huN1pYMFhIMjV3NUNfRFppUnVBb3RTZ1VyaThrY1U3WlZsNGVXdE3SAeABQVVfeXFMT1hfalhCNjVLc0MzQmR6SG55WTNKSWExaXF3RlllcTZ6Q0pWZXN5dlRXNzZyOTZKa3JoeVRwanJXSXFXNlhHbnNUclRlMzNMcnQtOUp5YVVHaWQ4aWRDSm5VUV9qNUJnT3FpUnZKUHh0SURwZUpRczVCUVdpWU1rMDlxakhUWEpOb3Fpa3R2U0lIU0NoMjQ3VG1wZTNoUWFSYnlRU2NDU0pFUWF5cHZIWi1rWTZKUXBoQ014aUdGV2ZrQjJCMFk3UkM3MDJkMkpJSGN2cmZpeFRqcld6MTR2a3Y?oc=5

InfotechLead frames a three-way race between SAP, Progress, and NetApp for the enterprise AI data layer as inference spending reaches $23.3 billion. NetApp's position rests on the AI Data Engine, AFX disaggregated systems, and ONTAP-backed governance for RAG/agentic workloads — competing against ERP-centric (SAP) and data-mobility-centric (Progress) plays.

Open source
AI

NetApp acquires DataPelago to tackle enterprise AI's biggest data bottleneck (HPCwire)

Source: https://www.hpcwire.com/2026/08/netapp-acquires-datapelago-ai-bottleneck/

HPCwire analysis of NetApp's DataPelago acquisition: focuses on the GPU-accelerated data preprocessing engine as the missing piece for solving the 'data is the new bottleneck' problem in enterprise AI. Notes that DataPelago's tech slots directly into AI Data Engine for ingest/transformation/embedding pipelines, complementing EF-Series hot storage and ONTAP cold storage.

Open source
Docs

NetApp Inc (OQ: NTAP) Share Price, NTAP Stock News, NTAP Share Price & Updates - Kalkine

Source: docs.netapp.com

NetApp Inc (OQ: NTAP) Share Price, NTAP Stock News, NTAP Share Price & Updates - Kalkine — official NetApp ONTAP 9 documentation page (ontap). Covers ONTAP commands, configuration procedures, and feature explanations relevant to NCDA/NCIE-SAN/NAS exam prep. Cross-references the corresponding CLI commands and version-specific behavior (ONTAP 9.12-9.19). Sourced from docs.netapp.com.

Archive digest
Advisory

NetApp Advisories Batch — NTAP-20260821-0001 to -0015

Source: security.netapp.com advisory API

Fifteen new NetApp advisories published Aug 21, 2026: Node.js (CVE-2026-58043 7.5, CVE-2026-1245 6.5), OpenSSL DoS (CVE-2026-14456 7.5), cJSON data modification (CVE-2026-29036 8.7), Spring Boot info disclosure (CVE-2026-40976 9.1), Libpng (CVE-2026-22695 6.1), August MySQL Connector/ODBC batch, Java SE (CVE-2026-70906 + monthly batch), OpenSSH trio (CVE-2026-73281/82/83), TPM 2.0 (CVE-2026-6726 8.5, CVE-2026-6727 8.3), and Samba CVE-2026-58216 5.3. Admins running ONTAP tools, ONTAP Select/ASA r2 plugins, or storage management stacks should check affected-product lists and patch.

Open source
Advisory

May 2026 GnuTLS Vulnerabilities in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260724-0002 (2026-08-21) (interim — details may evolve) covering CVE-2026-33845, CVE-2026-33846, CVE-2026-3833. The advisory affects Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP Select Deploy administration utility. Fix status: 1 fix entries. Impact: Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

May 2026 Apache ActiveMQ Vulnerabilities in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260710-0001 (2026-08-21) (interim — details may evolve) covering CVE-2026-42253, CVE-2026-42588, CVE-2026-45505, CVE-2026-46605, CVE-2026-49157, CVE-2026-49270. The advisory affects E-Series SANtricity Unified Manager and Web Services Proxy, SANtricity Storage Plugin for vCenter. Fix status: Fix status not yet published. Impact: Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-9256 NGINX Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260605-0012 (2026-08-21) (interim — details may evolve) covering CVE-2026-9256. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-70906 Java SE Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0008/

NetApp published this interim advisory covering CVE-2026-70906; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6949 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0020/

NetApp published this interim advisory covering CVE-2026-6949; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6100 CPython Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260717-0015 (2026-08-21) (interim — details may evolve) covering CVE-2026-6100. The advisory affects Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-58224 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0019/

NetApp published this final advisory covering CVE-2026-58224; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58222 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0018/

NetApp published this interim advisory covering CVE-2026-58222; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58221 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0017/

NetApp published this interim advisory covering CVE-2026-58221; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58218 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0016/

NetApp published this interim advisory covering CVE-2026-58218; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58216 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0015/

NetApp published this interim advisory covering CVE-2026-58216; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58043 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0001/

NetApp published this interim advisory covering CVE-2026-58043; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46300 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260522-0016 (2026-08-21) (interim — details may evolve) covering CVE-2026-46300. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-4519 Python Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0019 (2026-08-21) (interim — details may evolve) covering CVE-2026-4519. The advisory affects Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-4408 Samba Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260527-0001 (2026-08-21) (interim — details may evolve) covering CVE-2026-4408. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-40976 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0005/

NetApp published this interim advisory covering CVE-2026-40976; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34197 Apache ActiveMQ Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0001 (2026-08-21) covering CVE-2026-34197. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-33941 Handlebars.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0006 (2026-08-21) (interim — details may evolve) covering CVE-2026-33941. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-33940 Handlebars.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0007 (2026-08-21) (interim — details may evolve) covering CVE-2026-33940. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-33938 Handlebars.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0009 (2026-08-21) (interim — details may evolve) covering CVE-2026-33938. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-29036 cJSON Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0004/

NetApp published this interim advisory covering CVE-2026-29036; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-26007 pyca/cryptography Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260311-0010 (2026-08-21) (interim — details may evolve) covering CVE-2026-26007. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-24842 Node-tar Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260422-0018 (2026-08-21) (interim — details may evolve) covering CVE-2026-24842. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-23950 Node-Tar Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0003 (2026-08-21) (interim — details may evolve) covering CVE-2026-23950. The advisory affects NetApp HCI Baseboard Management Controller (BMC) - H610S. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-23231 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260320-0013 (2026-08-21) (interim — details may evolve) covering CVE-2026-23231. The advisory affects Active IQ Unified Manager for VMware vSphere, ONTAP tools for VMware vSphere 10. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-2303 MongoDB Drivers Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260626-0017 (2026-08-21) (interim — details may evolve) covering CVE-2026-2303. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22988 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260305-0017 (2026-08-21) (interim — details may evolve) covering CVE-2026-22988. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22984 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260508-0001 (2026-08-21) (interim — details may evolve) covering CVE-2026-22984. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22695 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0006/

NetApp published this interim advisory covering CVE-2026-22695; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-22610 Angular Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260311-0001 (2026-08-21) (interim — details may evolve) covering CVE-2026-22610. The advisory affects Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-1485 GLib Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260320-0001 (2026-08-21) (interim — details may evolve) covering CVE-2026-1485. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-1484 GLib Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260320-0003 (2026-08-21) (interim — details may evolve) covering CVE-2026-1484. The advisory affects Active IQ Unified Manager for VMware vSphere. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to addition or modification of data or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-14456 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0003/

NetApp published this interim advisory covering CVE-2026-14456; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-14266 7-Zip Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260724-0010 (2026-08-21) (interim — details may evolve) covering CVE-2026-14266. The advisory affects Active IQ Unified Manager for Microsoft Windows. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-1245 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0002/

NetApp published this interim advisory covering CVE-2026-1245; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-0861 GNU C Library (glibc) Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260320-0005 (2026-08-21) (interim — details may evolve) covering CVE-2026-0861. The advisory affects Active IQ Unified Manager for VMware vSphere, Brocade Fabric Operating System Firmware, NetApp HCI Baseboard Management Controller (BMC) - H610S, Trident. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2025-8885 Bouncy Castle Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20250912-0012 (2026-08-21) (interim — details may evolve) covering CVE-2025-8885. The advisory affects Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Data Infrastructure Insights and Data Secure Storage Workload Security Agent, ONTAP tools for VMware vSphere 10. Fix status: 3 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2025-64506 Libpng Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260116-0005 (2026-08-21) (interim — details may evolve) covering CVE-2025-64506. The advisory affects Active IQ Unified Manager for VMware vSphere, ONTAP tools for VMware vSphere 10. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2025-52565 Runc Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20251121-0002 (2026-08-21) (interim — details may evolve) covering CVE-2025-52565. The advisory affects Astra Control Center, ONTAP tools for VMware vSphere 10. Fix status: 2 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

August 2026 MySQL Connector/ODBC Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0007/

NetApp published this interim advisory covering CVE-2026-71084, CVE-2026-71079, CVE-2026-71073; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
AI

2026-09-02-sap-progress-and-netapp-race-for-ai-data-layer-as-inference-spending-hits-23-3-b

Source: https://news.google.com/rss/articles/CBMi2AFBVV95cUxPOUQ0N3JjMkdmWHVQVmdCSlRsMkdnNVhZV0Nqc2stVjJNaHZnZl9ZODlyQlRmdng2YURJRzBkR3pnSmVfQk9TLUJWQ3NUblBPS2VFRzFzNlM0TkVJWkxWZmtuZnd2aEszd2lMbWhOaWFjNW4zaTMxbzF0VUZZZVFxMDVOYnkwRm5PNThUVW1VQ3VsSkE2V05KM09YS3VPWnl6dGZlT1NnWEZ2ajNyV0NfM2huN1pYMFhIMjV3NUNfRFppUnVBb3RTZ1VyaThrY1U3WlZsNGVXdE3SAeABQVVfeXFMT1hfalhCNjVLc0MzQmR6SG55WTNKSWExaXF3RlllcTZ6Q0pWZXN5dlRXNzZyOTZKa3JoeVRwanJXSXFXNlhHbnNUclRlMzNMcnQtOUp5YVVHaWQ4aWRDSm5VUV9qNUJnT3FpUnZKUHh0SURwZUpRczVCUVdpWU1rMDlxakhUWEpOb3Fpa3R2U0lIU0NoMjQ3VG1wZTNoUWFSYnlRU2NDU0pFUWF5cHZIWi1rWTZKUXBoQ014aUdGV2ZrQjJCMFk3UkM3MDJkMkpJSGN2cmZpeFRqcld6MTR2a3Y?oc=5

InfotechLead article from the NetApp AI Google News RSS feed. SAP, Progress and NetApp Race for AI Data Layer as Inference Spending Hits $23.3 Billion - InfotechLead. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
News

2026-09-02-netapp-inc-oq-ntap-share-price-ntap-stock-news-ntap-share-price-updates-kalkine

Source: https://news.google.com/rss/articles/CBMiUEFVX3lxTE0xQk5VX25vWHRMMC1rN3JoajB3NEFoMVllUHR2LVRYUDQtd085cW9BaHRiV0F1MTZoNzdlWmFEZGRuSXExSUV2WVRIdXY3T1Jh?oc=5

Kalkine article from the NetApp ONTAP Google News RSS feed. NetApp Inc (OQ: NTAP) Share Price, NTAP Stock News, NTAP Share Price & Updates - Kalkine. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
Advisory

2026-09-01-ntap-20260821-0014

Source: https://security.netapp.com/advisory/NTAP-20260821-0014/

NetApp security advisory NTAP-20260821-0014. CVEs: CVE-2026-6727. The TPM 2.0 reference library specification published by the Trusted Computing Group is susceptible to a vulnerability which exposes a timing side-channel in RSA OAEP decryption, enabling an attacker to decrypt sensitive blobs (import blobs, credential blobs, and session salts) encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), or to falsify TPM 2.0 Attestation Keys.

Open source
Advisory

2026-09-01-ntap-20260821-0013

Source: https://security.netapp.com/advisory/NTAP-20260821-0013/

NetApp security advisory NTAP-20260821-0013. CVEs: CVE-2026-6726. The TPM 2.0 reference library specification published by the Trusted Computing Group is susceptible to a vulnerability which when exploited could allow improper reuse of object slots between key/data objects and hash contexts, enabling an attacker to falsify TPM attestations and credentials.

Open source
Advisory

2026-09-01-ntap-20260821-0012

Source: https://security.netapp.com/advisory/NTAP-20260821-0012/

NetApp security advisory NTAP-20260821-0012. CVEs: CVE-2026-73283. OpenSSH versions through 10.4 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260821-0011

Source: https://security.netapp.com/advisory/NTAP-20260821-0011/

NetApp security advisory NTAP-20260821-0011. CVEs: CVE-2026-73282. OpenSSH versions through 10.4 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260821-0010

Source: https://security.netapp.com/advisory/NTAP-20260821-0010/

NetApp security advisory NTAP-20260821-0010. CVEs: CVE-2026-73281. OpenSSH versions through 10.4 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260821-0009

Source: https://security.netapp.com/advisory/NTAP-20260821-0009/

NetApp security advisory NTAP-20260821-0009. CVEs: CVE-2026-61308, CVE-2026-70907, CVE-2026-60589. Java SE versions 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, and 26.0.2 are susceptible to vulnerabilities that allow unauthenticated attackers with network access via multiple protocols (including HTTP and TLS) to compromise Oracle Java SE. Refer to “Oracle Critical Security Patch Update Advisory - August 2026” for additional details.

Open source
Community

2026-08-30 — Community: ONTAP Tools for VMware vSphere 10.6

Source: NetApp Community — https://community.netapp.com/community/discussion/468330/ontap-tools-for-vmware-vsphere-10-6-more-control-less-overhead-and-faster-day-2-operations

NetApp Community announcement / walk-through of ONTAP Tools for VMware vSphere (OTV) 10.6 — focused on vCenter 8 U3 alignment, more granular datastore control, less management-plane overhead, and faster day-2 operations (resizing, rebalancing, recovering VVols datastores). Adds improved vVols troubleshooting surfaces and an updated plug-in lifecycle for both vSphere 7 and 8.

Open source
AI

NetApp’s AI Storage Push Has Analysts Eyeing A Guidance Lift - Finimize

Source: Google News RSS

NetApp’s AI Storage Push Has Analysts Eyeing A Guidance Lift - Finimize — coverage in the NetApp AI ecosystem: google news feed item dated 2026-08-20. Relevant to the NetApp AI priority: tracks AI infrastructure partnerships, AIPod deployments, BlueXP/AI Data Engine, NVIDIA integrations, and competitive AI storage market positioning (NetApp vs Nutanix, Pure, Vast). Adds to the NetApp Black Box AI knowledge base for cert exam context (NCIE-AI, NCDA) and site visitors researching NetApp's AI strategy.

Archive digest
AI

NetApp's AI Storage Push Has Analysts Eyeing A Guidance Lift

Source: Finimize

Analysts are increasingly framing NetApp's guidance around its AI storage momentum: all-flash ARR growth, AI Data Engine traction, and wins like DataPelago and AIPod deals are seen as drivers for an upward FY2027 guidance revision. The piece positions NTAP as one of the clearest public-market plays on enterprise AI data infrastructure.

Archive digest
AI

NetApp's AI Storage Push Has Analysts Eyeing A Guidance Lift

Source: Finimize

Finimize analysis argues NetApp's AI storage momentum (all-flash ARR, AI Data Engine, DataPelago acquisition) could drive an upward guidance revision as enterprise AI deployments convert into high-performance storage demand. Frames ONTAP-based AI infrastructure as a growing share of the revenue mix heading into FY2027.

Open source
AI

NetApp Q4 FY 2026: AI Deployments Accelerate High-Performance Storage Demand (Futurum)

Source: https://futurumgroup.com/insights/netapp-q4-fy-2026-ai-deployments-accelerate-high-performance-storage-demand/

Futurum Group analysis of NetApp's Q4 FY2026 earnings: AI deployments cited as the primary driver of high-performance storage demand, with EF-Series + AIPod + AI Data Engine highlighted as the differentiated growth areas. Includes analyst views on consensus revenue, ARR projections, and how NetApp's AI portfolio compares to Pure Storage and VAST Data going into FY2027.

Open source
Community

Community: NetApp StorageGRID on VMware - Server-Side Encryption Implementation

Source: https://www.reddit.com/r/netapp/comments/1vtswc2/netapp_storagegrid_onvmware_serversideencryption/

NetApp community discussion on deploying StorageGRID virtual nodes in VMware vSphere environments with Server-Side Encryption (SSE-S3 / SSE-C). Practitioners exchanged configuration tips on integrating enterprise Key Management Servers (KMS) via KMIP, balancing encryption CPU overhead on virtualized StorageGRID nodes, and maintaining high throughput for S3 object workloads across hybrid cloud topologies.

Open source
Docs

2026-09-04-ontap-afx-9191-whats-new

Source: https://docs.netapp.com/us-en/ontap-afx/release-notes/whats-new-9191.html

AFX (the disaggregated all-flash system) gets its own 9.19.1 cut of the release notes (dated 2026-08-20). Notable AFX-1.5 updates vs the unified ONTAP release: SnapMirror active sync for NAS now reaches AFX clusters but only at the SVM level on NFS/SMB, 4-node AFX clusters only, with read-write access limited to the primary cluster; SnapMirror cloud bucket limit raised to 100 buckets. TCP performance improvements (PRR+RACK) apply here too. Performance: Cross File Sequential Read (CFSR) intelligently prefetches video frames to dramatically raise throughput and cut latency for video editing / M&E workloads; Global Deduplication extends dedup scope from per-volume to the entire Storage Availability Zone (SAZ) and runs by default; Dynamic Storage Efficiency auto-suspends inline/background dedup/compression/compaction during high-volume write bursts to protect throughput. Why it matters: AFX customers running NFS workloads now have an active/active DR option they didn't before, video/M&E shops get a built-in sequential-read booster, and dedup sizing assumptions should be revised — savings now reach SAZ-wide instead of single-volume. AFX differs from traditional AFF in that all-flash nodes are decoupled and the system scales by adding storage capacity nodes independently of compute — this release leans into that with SAZ-scoped dedup.

Open source
AI

Is NetApp (NTAP) Fully Priced On Its TechNet Augusta Presentation?

Source: Yahoo Finance (via simplywall.st)

Yahoo Finance asks whether NTAP's valuation already reflects its TechNet Augusta presentation, where NetApp showcased secure, AI-ready data infrastructure to US defense audiences (Aug 17–20). Coverage ties NetApp's defense-sector AI visibility — cyber-resilient ONTAP storage and sovereign-AI positioning — to near-term share-price momentum and questions about it being priced in.

Open source
AI

Stack Automation by Quali Goes GA as a Cisco Exclusive, Promising Rack to Application in Hours - StorageReview.com

Source: Google News RSS

Stack Automation by Quali Goes GA as a Cisco Exclusive, Promising Rack to Application in Hours - StorageReview.com — coverage in the NetApp AI ecosystem: google news feed item dated 2026-08-19. Relevant to the NetApp AI priority: tracks AI infrastructure partnerships, AIPod deployments, BlueXP/AI Data Engine, NVIDIA integrations, and competitive AI storage market positioning (NetApp vs Nutanix, Pure, Vast). Adds to the NetApp Black Box AI knowledge base for cert exam context (NCIE-AI, NCDA) and site visitors researching NetApp's AI strategy.

Archive digest
AI

NetApp stock trades above $200 as AI storage demand lifts outlook

Source: https://news.google.com/rss/articles/CBMixgFBVV95cUxPR3NteUVYaW1sZ0VXSWxzYzhnR25CM204RnpielRiaFRRZlBQNE9TWTZhMmtWbWo0MlVpMHF3d2RDaUg3Q3RySUt2dFUzN0hDNk5ZX0xEb2pjWnpsZXlfY0hPUFVsYU51RG03UzJPOUM5WkVyd252WW9FVjB2clJoU0dRUG9fSi1QakJ6NXJEbGFTaVFNbmt6aHotVlhXZmxPTnljUWhTaW9fRHNRRmVyUE1Uek01UmFMS0ZNLXVNdFJyR2hBb0E?oc=5

NetApp shares crossed $200 as investors price in continued AI-driven storage demand ahead of Q1 FY2027 results. The move extends the analyst narrative that NetApp's all-flash and AI data-platform portfolio (AFF, AFX, AI Data Engine) is capturing AI infrastructure spend.

Open source
AI

NetApp (NTAP) Stock Dropped, So What Is Driving Attention Today? - simplywall.st

Source: Google News RSS

NetApp (NTAP) Stock Dropped, So What Is Driving Attention Today? - simplywall.st — coverage in the NetApp AI ecosystem: google news feed item dated 2026-08-19. Relevant to the NetApp AI priority: tracks AI infrastructure partnerships, AIPod deployments, BlueXP/AI Data Engine, NVIDIA integrations, and competitive AI storage market positioning (NetApp vs Nutanix, Pure, Vast). Adds to the NetApp Black Box AI knowledge base for cert exam context (NCIE-AI, NCDA) and site visitors researching NetApp's AI strategy.

Archive digest
AI

Championship infrastructure for AI: NetApp AFX and NetApp AI Data Engine

Source: https://www.netapp.com/blog/championship-infrastructure-ai-netapp-afx-ai-data-engine/

NetApp engineering blog on 'championship infrastructure for AI' - the combined NetApp AFX (a disaggregated all-flash platform) + AI Data Engine reference architecture for high-performance AI training and inference. Covers the AFX hardware topology, GPUDirect Storage integration, and the AI Data Engine data-plane APIs that orchestrate ingestion, embedding and retrieval.

Open source
AI

2026-09-02-netapp-ntap-stock-dropped-so-what-is-driving-attention-today-simplywall-st

Source: https://news.google.com/rss/articles/CBMivgFBVV95cUxOdk0zU1lGU2wzaFQzLXRtNEJ4ckZPT2dfVE1TbkFYUHlnNE1vT3JiVkJsa2l0SjNnNGFBUFQ1S1A4RFZmZ29FWEZvbTdvMnB5c0VlSEsxTTIya3pSUlpzYXJLS0lQZG1qZjF3Y2dsRjdIUktCUklCUlljOWJHLWFOZUpXTDBib2lIaWdMNHJOZHpVX3E4cmdJbkJDcXliVFFsWjZqSHlHY2Y1djFKa1BFVUpaVDJqLW1nQjQxbHpB0gHDAUFVX3lxTE9aeWNnX0NVR3pENXZJcVBBbjRjdklrd3FVaVZ2eVB6VE80LWtEczZvZ1dqd21yclBSZXRaYXdMZkVBOEE0aFhQaGxZT21XUmlZcVJ1VVhqVDFnNHFGVVU2Q1RFNVJ4TWMzck5vLThiZ2xUcDBLNjE3LUkxcnVRb1Q4LTdMWFpXWm5HN3V1OFFpVHFpeWFwSUZ2VUNrRXdQT29XcWFLU0w0MXdJNkROajhITHoyV3dxdFBNU1ZUa2N1UVJJbw?oc=5

simplywall.st article from the NetApp AI Google News RSS feed. NetApp (NTAP) Stock Dropped, So What Is Driving Attention Today? - simplywall.st. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

Object storage powers AI pipelines and distributed data (NetApp blog)

Source: https://www.netapp.com/blog/object-storage-ai-pipelines-distributed-data/

NetApp engineering blog on object storage (StorageGRID + ONTAP S3) as the data foundation for AI pipelines and distributed data: cost-efficient storage of large training corpora, multi-region replication, and direct S3 access from GPU training frameworks. Discusses the ONTAP S3 access points feature for fine-grained access control in RAG pipelines.

Open source
Docs

ONTAP 9 release highlights: 9.16.1 through 9.19.1

Source: https://docs.netapp.com/us-en/ontap/release-notes/index.html

NetApp's release hub now indexes feature pages through ONTAP 9.19.1. The durable operational story across recent releases includes ARP/AI expansion to SAN, NVMe support for SnapMirror active sync, cloud mediation, stronger identity controls, and storage-driven S3 bucket restore.

Open source
AI

NetApp takes advantage of increase in enterprise storage demand: Citi - Seeking Alpha

Source: Google News RSS

NetApp takes advantage of increase in enterprise storage demand: Citi - Seeking Alpha — coverage in the NetApp AI ecosystem: google news feed item dated 2026-08-18. Relevant to the NetApp AI priority: tracks AI infrastructure partnerships, AIPod deployments, BlueXP/AI Data Engine, NVIDIA integrations, and competitive AI storage market positioning (NetApp vs Nutanix, Pure, Vast). Adds to the NetApp Black Box AI knowledge base for cert exam context (NCIE-AI, NCDA) and site visitors researching NetApp's AI strategy.

Archive digest
News

NetApp takes advantage of increase in enterprise storage demand: Citi

Source: Seeking Alpha via Google News — https://news.google.com/rss/articles/CBMiqgFBVV95cUxOOFFfSXd0ZE9ZTjhmSEtQcFNJblBCQmVub1oxZEtaTUlNM3ZsdUpYeHhITEFpYzFSNWVYZFBpRXhjcEtVQ3luUUMwcFVNanhWLXdQWHpqeEVDay1KY3FaakZMSnkxQlBQWjJ1ZGwxRnF2dUtQOXZSOEZYWlgxOE5XbldHSk8tY3FCbzZZWW5BUHE1TWprazBTMFNpZzNzZ2FLNVNuQlZkbzdtZw?oc=5

Citi notes NetApp is capitalizing on rising enterprise storage demand, consistent with the broader AI-driven all-flash refresh cycle. This aligns with the bullish analyst cluster (Oppenheimer, Goldman) expecting above-guidance fiscal Q1 results on flash ARR momentum.

Open source
Docs

Dedicated offload processor storage efficiency behavior

Source: https://docs.netapp.com/us-en/ontap/concepts/builtin-storage-efficiency-concept.html

Current AFF A1K/A90/A70/A50/A30 and AFF C80/C60/C30 systems use dedicated offload processing for storage efficiency, with efficiency automatically applied to new thin-provisioned volumes and migrated data. Recent FAS90/FAS70/FAS50 behavior differs: existing enabled thin volumes retain the feature across upgrades, while new volumes may require explicit enablement.

Open source
AI

HCLTech Pairs NetApp Keystone With U4X to Sell Enterprise AI Storage by Consumption - StorageReview.com

Source: Google News RSS

HCLTech Pairs NetApp Keystone With U4X to Sell Enterprise AI Storage by Consumption - StorageReview.com — coverage in the NetApp AI ecosystem: google news feed item dated 2026-08-17. Relevant to the NetApp AI priority: tracks AI infrastructure partnerships, AIPod deployments, BlueXP/AI Data Engine, NVIDIA integrations, and competitive AI storage market positioning (NetApp vs Nutanix, Pure, Vast). Adds to the NetApp Black Box AI knowledge base for cert exam context (NCIE-AI, NCDA) and site visitors researching NetApp's AI strategy.

Archive digest
News

Celebrating 100 days of customers with NetApp

Source: NetApp blog (via Google News: https://news.google.com/rss/articles/CBMilAFBVV95cUxNX2h3b2Yxc09mLXV5ZEFVSmhSRFhaWGVHT282VW5vRUpYMFhmN2Z4ZWhBbmFWX3E1d3BUWmdMOWhMT0RDeGdTYkRjZUN5N0pTQkliMWFDY1F4RUM3NTdaY3dlVTIzTXhveXZIV0k0ZnpRQ29SbHRjc3k1M3pieFA5c2gyU0h2TlVjUDVGTWR6Qk9OUjBD?oc=5)

NetApp's blog celebrates "100 days" of customer stories, spotlighting deployments across AI, cloud, and modernization. Light-touch vendor content, but useful color on how customers are actually adopting recent launches (AFX, AI Data Engine, Keystone).

Open source
AI

AI-ready storage with NetApp Keystone STaaS

Source: https://www.netapp.com/blog/ai-ready-storage-netapp-keystone-staas/

NetApp blog on positioning Keystone STaaS (Storage-as-a-Service) as the consumption model for AI-ready storage: pay for ONTAP/EF-Series/StorageGRID capacity and performance on a subscription, with built-in AI Data Engine workloads. Frames Keystone as the bridge from capex to opex for enterprises standing up AI factories in 2026 and beyond.

Open source
AI

Weekly Recap: NetApp tie-up for AI storage and Parag Parikh boosts HCLTECH stake - TradingView

Source: Google News RSS

Weekly Recap: NetApp tie-up for AI storage and Parag Parikh boosts HCLTECH stake - TradingView — coverage in the NetApp AI ecosystem: google news feed item dated 2026-08-16. Relevant to the NetApp AI priority: tracks AI infrastructure partnerships, AIPod deployments, BlueXP/AI Data Engine, NVIDIA integrations, and competitive AI storage market positioning (NetApp vs Nutanix, Pure, Vast). Adds to the NetApp Black Box AI knowledge base for cert exam context (NCIE-AI, NCDA) and site visitors researching NetApp's AI strategy.

Archive digest
Community

Community: Repurposing NetApp HCI Compute Nodes with Supermicro Firmware

Source: https://www.reddit.com/r/netapp/comments/1vq1tm9/homelab_repurposing_netapp_hci_nodes_and/

A technical deep-dive from the NetApp homelab community on repurposing off-lease NetApp HCI H-series compute nodes (such as H410C and H610C). Storage engineers detailed the process of flashing generic Supermicro / Quanta BIOS and IPMI/BMC firmware onto the proprietary nodes, restoring full standard fan curve controls, IPMI remote console access, and compatibility with vanilla hypervisors like Proxmox VE and TrueNAS SCALE.

Open source
AI

2026-09-02-weekly-recap-netapp-tie-up-for-ai-storage-and-parag-parikh-boosts-hcltech-stake-

Source: https://news.google.com/rss/articles/CBMi2AFBVV95cUxNWG1CRjI4ZmtBZGUyQ3NDamJhcE1hOTRPUElhbTBSUHZXeDA1S2J6ZnI3YXRzYXhYRDJFTE85VkthclZGOVN6bDhqS1RQX1U1Ul9JSnFHWFY2ekZlYWlzR3M2b3duQkQxd0pabl9KZ3RmWDFoSnFpLXNuM09LdXhKaTlJZnZ6ekM5elJNaTZ2aXlxbEozSnNpN1prSVBwbFJEWFE4UF82UlFmeEtNSmU2dFF6SmFrM3ZnWlFuS2VON0VNTi1NeF9qQkZtR3U4MUdRdGlGLWZoRVA?oc=5

TradingView article from the NetApp AI Google News RSS feed. Weekly Recap: NetApp tie-up for AI storage and Parag Parikh boosts HCLTECH stake - TradingView. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

NetApp AIPod Mini with Intel: affordable, simple, secure AI infrastructure

Source: https://www.netapp.com/blog/netapp-aipod-mini-intel-affordable-secure-ai/

NetApp blog on the AIPod Mini with Intel reference architecture: smaller, cheaper turnkey AI appliance built on Intel Xeon 6 + Gaudi accelerators, validated ONTAP storage and BlueXP orchestration. Targets mid-market customers and edge inferencing deployments that want the AIPod experience without the cost of NVIDIA HGX pods.

Open source
Docs

Learn about ONTAP S3 configuration (NetApp Docs)

Source: https://docs.netapp.com/us-en/ontap/s3-config/index.html

ONTAP S3 landing page for ONTAP 9.x — the native S3 server in ONTAP that exposes an S3 endpoint on top of NAS-affine volumes and aggregates. Useful context for hybrid-AI pipelines where object-store semantics are required (S3 Batch operations, S3 Object Lock, cross-region replication) but the underlying data must live on ONTAP for snapshots, SnapMirror, or FabricPool reasons. Covers ONTAP 9.x S3 server creation, buckets, users, groups, policies (including read-only/full-access variants), TLS configuration, audit logging, and integration with NAS protocol coexistence on the same SVM. Important reference when architects compare ONTAP S3 against StorageGRID for object workloads — StorageGRID is the dedicated object store with global namespace and multi-site replication, while ONTAP S3 is the lightweight in-band option.

Open source
Advisory

NetApp Advisories Batch — NTAP-20260814-0001 to -0020

Source: security.netapp.com advisory API

Twenty advisories published Aug 14, 2026: five Linux Kernel CVEs rated up to 9.8 (CVE-2026-31589, -64391, -64534, -64535, -64319), Intel UEFI SA-01234, six IBM Db2 vulnerabilities (CVE-2026-10534/-10543/-18097/-45205/-16480/-18096), six FreeBSD vulnerabilities (CVE-2026-58083 through -58088), OpenSSL CVE-2026-54876, and Libssh2 CVE-2026-7598. Several Linux Kernel items carry critical 9.8 scores with potential full system impact — prioritize reviewing affected products if you run ONTAP Medius/hosting stacks or NetApp-supported Linux-based appliances.

Open source
AI

NetApp AIPod with Lenovo: Next-generation AI & agentic AI

Source: https://www.netapp.com/blog/netapp-aipod-lenovo-next-gen-agentic-ai/

NetApp blog detailing the AIPod with Lenovo converged infrastructure for next-generation AI and agentic AI workloads. Highlights validated ThinkSystem SR675 V3 servers with NVIDIA HGX H200/B200, ONTAP AI storage, and BlueXP orchestration for training and inference workloads at enterprise scale.

Open source
Advisory

Intel SA-01234 UEFI Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0006/

NetApp published this interim advisory covering CVE-2025-20105, CVE-2025-20064, CVE-2025-20028, CVE-2025-20068, CVE-2025-20027, CVE-2025-22850, CVE-2025-22444, CVE-2025-20005, CVE-2025-20073; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-7598 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0020/

NetApp published this interim advisory covering CVE-2026-7598; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-64535 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0004/

NetApp published this interim advisory covering CVE-2026-64535; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-64391 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0002/

NetApp published this interim advisory covering CVE-2026-64391; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-64319 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0005/

NetApp published this interim advisory covering CVE-2026-64319; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58088 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0015/

NetApp published this final advisory covering CVE-2026-58088; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58087 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0014/

NetApp published this final advisory covering CVE-2026-58087; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58086 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0017/

NetApp published this interim advisory covering CVE-2026-58086; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58085 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0016/

NetApp published this interim advisory covering CVE-2026-58085; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58084 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0018/

NetApp published this interim advisory covering CVE-2026-58084; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58083 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0013/

NetApp published this final advisory covering CVE-2026-58083; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-54876 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0019/

NetApp published this interim advisory covering CVE-2026-54876; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45205 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0010/

NetApp published this interim advisory covering CVE-2026-45205; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-31589 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0001/

NetApp published this interim advisory covering CVE-2026-31589; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-18097 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0009/

NetApp published this final advisory covering CVE-2026-18097; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-18096 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0012/

NetApp published this final advisory covering CVE-2026-18096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-16480 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0011/

NetApp published this final advisory covering CVE-2026-16480; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10543 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0008/

NetApp published this interim advisory covering CVE-2026-10543; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10534 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0007/

NetApp published this final advisory covering CVE-2026-10534; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Docs

Automating FSx for NetApp ONTAP Mounts with SSM and MGN Post-Migration

Source: AWS Blog (Amazon Web Services)

AWS published a technical walkthrough for automating FSx for NetApp ONTAP filesystem mounts using AWS Systems Manager (SSM) and the Application Migration Service (MGN) after server migrations. Useful for ONTAP admins working hybrid cloud migrations: covers post-migration mount reconfiguration at scale without manual per-host edits.

Open source
AI

2026-09-02-hcltech-netapp-partner-on-staas-to-drive-enterprise-ai-adoption-et-datacenters

Source: https://news.google.com/rss/articles/CBMi6AFBVV95cUxORzNwb0hwRnNUSUs0dzhFSTlCTlFlbU1yWGhRZzFMbzZVckdrR0ozbkJYQ0M0blJxSzlEdUpidHZMQmhNa25qSlVVenVrRU91aVRGTUJqcFJHYmhIdnpLdFhXcGxFZS1rcDVhOGdncmstbU8weDg5SjA2UlIxSUNNWjFuN0tEVDZvTWtTcTNVU0duckZtZUwtanJKNWZfX3JSWVR4Y0otYnk3M19UTXd4Nk5haUVYSkVGVW1MM05sVmlTdXg4Q1dNNTg5MGNweExBZGFIUTN6UWYtNW9fZHc1TjU2em9jZno1?oc=5

ET Datacenters article from the NetApp AI Google News RSS feed. HCLTech, NetApp partner on STaaS to drive enterprise AI adoption - ET Datacenters. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-hcltech-netapp-expand-partnership-to-deliver-hybrid-cloud-storage-as-a-service-f

Source: https://news.google.com/rss/articles/CBMiggJBVV95cUxPMm5TRFN6Z1RfU2tuY1NWY3I2blRJa3gzMTlGN3R0SnNtVjNldUFjTXZlVXMxR3ZKZVpNajBKM0ZXTTF3Q0VwRml2ZWtIM2pBQ0NsUkNFb1duczBuVEItRzR2S3VYOVZBRnAyODFPWHN0WS1CTlZ6bE9pYndKb2FPTnBYOEl0QWk1b20zeUU4SnczU0FxcVlRMFNPQWpfdnowYlZDeThwRndHQjZueGFZcUR0ekFOUFJrdl9Ic2JTdnczR0xRQmkxRnpSZFpkV2FFOTRLeEh1V2RMMkVydjlBblI1WkE1UjRFWjRFZFoxS3luRjV2RVMxalYxR09pTWk3LUHSAYcCQVVfeXFMTjNON0NHUEcwMndSSWF5aUVmeXR0WWVzRzU0U2xnU1ZEY1lYc1NTcS1nMHVuckZ3ODlHUk1qVmNqRXRjTUhsUjN1eGFURlZ2dkM4YlpUY3l6WVgzbFA5bzNENnljMUtGNWRaTUc1UVhSNWEyM0c3WlhLU0dxbXduNHVpMmo0WkNKdkFzT0xsUXNDNVFJWkJSWUsxc2pXNVhqY2paYlh2UHlWUkhaNjA2alNTRGFnTXdCbnI5NUQtUnkyLWlSZEtnR1R5d0xCUDVjLXUxLWJKSGlKNklZci1SblRPSzh0ZDFkbnl5TUdzZGhZOTNPZkw5ejNOOVpQYk8xbEdZa3JIcUk?oc=5

The Economic Times article from the NetApp AI Google News RSS feed. HCLTech, NetApp expand partnership to deliver hybrid cloud storage-as-a-service for enterprise AI - The Economic Times. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-hcltech-and-netapp-expand-partnership-to-launch-hybrid-cloud-storage-as-a-servic

Source: https://news.google.com/rss/articles/CBMi4gFBVV95cUxOR1VUZjVTa0hmR05ZcmxkOG1CU1YtNmIzdmoyVGtTeDgxWm1WeEdud19QRGFObGRoYmZObEpBcmtaakhfRXBnYjFCV1hTVVE5RURXMVpMZW1mclhGWmI3OVRkRXFPZHZSMzM5Y1NhY2Y0WjFYS0J4NTBXMnQ5Rmd3cGxiTV9sVjFNYlpCUTBrVXo3N0FxUjJxOHJpM0FFVGVUeUZxRHFEc3FMbkdMNTBFYzRqdlktUW1KWHkzUFlEUXNqdnlySTRRbjBlem5FT2ZIcTZ3UVRIYjBJQ0ROS3BfREh3?oc=5

Telugu Times article from the NetApp AI Google News RSS feed. HCLTech and NetApp Expand Partnership to Launch Hybrid Cloud Storage-as-a-Service for Enterprise AI - Telugu Times. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

2026-09-01-ntap-20260814-0003

Source: https://security.netapp.com/advisory/NTAP-20260814-0003/

NetApp security advisory NTAP-20260814-0003. CVEs: CVE-2026-64534. Linux kernel versions prior to 5.10.261, 5.11.0 prior to 5.15.212, 5.16.0 prior to 6.1.178, 6.2.0 prior to 6.6.145, 6.7.0 prior to 6.12.97, 6.13.0 prior to 6.18.40, and 6.19.0 prior to 7.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
AI

Goldman Sachs Names Dell, HPE, NetApp as Top Hardware Picks on AI Boom

Source: https://finance.biggo.com (via Google News: https://news.google.com/rss/articles/CBMidkFVX3lxTE4zTkhVbVlxMFFuaG5zamRtRFl4THRvdVVzdUpiTVlqVUV6NVV4T1puS3RmWWc5Slhob1k4TTJEdm5xZDlwekE3ODNWdTNXZlB0bFlIVXREeHRDR3VxbGJMRlJGYVBhLW1nb1hRcm56c0R2WE84N2c?oc=5)

Goldman Sachs named Dell, HPE, and NetApp its top enterprise-hardware picks on accelerating AI infrastructure demand. Analyst sentiment reinforces NetApp's AI-storage narrative (AIPod, AFX/AI Data Engine, Keystone consumption) heading into its Q1 FY2027 report.

Open source
AI

2026-09-02-hcltech-expands-netapp-partnership-to-launch-consumption-based-storage-offering-

Source: https://news.google.com/rss/articles/CBMi0wFBVV95cUxPYjZiMUZFZm9zcnFYU2w4QkVpVkpBeEdOclg3S1MtTng0N1hoOXhBNTZyZ01sWi1DUHBzUzNmX1ZCd2EzTElId0hRbXJwZGZuWHZ6aldDYzVUQ2Rka2lMaDZKMWRFbXBHSENOSFpMeWdYQXhkTUx6cV9QLWZ5cFdEalRwdXdaajRUa2t0eE55NWVmc0F6R3cyNUlGU0pBdHA4WXhYbGNlUXhiNFBwZVg5VVg4ZmMteFA5bGtwTWdXOG1EU2pZLTZqc0QwVXhJdE96bFFz?oc=5

CRN Asia article from the NetApp AI Google News RSS feed. HCLTech expands NetApp partnership to launch consumption-based storage offering for enterprise AI - CRN Asia. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
News

NetApp named a Leader in the 2026 Gartner Magic Quadrant for Primary Storage

Source: https://www.gartner.com/doc/netapp-mq-2026-primary-storage

NetApp placed in the Leaders quadrant of the 2026 Gartner Magic Quadrant for Primary Storage (file/block). Cites NetApp's completeness of vision around intelligent data infrastructure for AI, the ONTAP disaggregation move, and broad platform coverage from AFF to ASA r2 to EF-Series and StorageGRID. Third-party analyst signal that supports NetApp's claim of being the most-deployed enterprise storage platform for both traditional and AI workloads.

Open source
AI

Jensen Huang & George Kurian: Revolutionary AI products (NetApp at NVIDIA GTC)

Source: https://www.netapp.com/blog/jensen-huang-george-kurian-gtc-keynote/

Coverage of the NVIDIA GTC 2026 joint keynote by Jensen Huang (NVIDIA) and George Kurian (NetApp): announcing expanded NVAIE certification for AIPod, GPUDirect Storage for EF-Series, and the next phase of the NetApp + NVIDIA partnership around Blackwell GPUs and AI factories. Frames the AI Data Engine as the unified data plane for enterprise AI agents.

Open source
News

Everpure takes on NetApp in the public cloud

Source: Techzine Global

Startup Everpure launched a public-cloud storage service challenging NetApp's cloud offerings, positioning itself as a lower-cost, cloud-native alternative for file and object workloads. A notable competitive signal for NetApp's cloud storage business (Cloud Volumes ONTAP / FSx for ONTAP).

Archive digest
AI

2026-09-02-goldman-sachs-names-dell-hpe-netapp-as-top-hardware-picks-on-ai-boom-finance-big

Source: https://news.google.com/rss/articles/CBMidkFVX3lxTE4zTkhVbVlxMFFuaG5zamRtRFl4THRvdVVzdUpiTVlqVUV6NVV4T1puS3RmWWc5Slhob1k4TTJEdm5xZDlwekE3ODNWdTNXZlB0bFlIVXREeHRDR3VxbGJMRlJGYVBhLW1nb1hRcm56c0R2WE84N2c?oc=5

finance.biggo.com article from the NetApp AI Google News RSS feed. Goldman Sachs Names Dell, HPE, NetApp as Top Hardware Picks on AI Boom - finance.biggo.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
News

2026-09-02-everpure-takes-on-netapp-in-the-public-cloud-techzine-global

Source: https://news.google.com/rss/articles/CBMingFBVV95cUxNblQ2UEl3SnMxNTBBcG4wWkdYMnZub3lLbTV1NGt3V2ZsQWJDWTlacVFtbG84R1VtRmcwenVmd2xxMWJBZEhHZllkb3RUYklOeVFKVVlacW5kT0p5VTM1aXo3MjAxLS0wVU5GQXJVaEhxUm1uSnZONGVzcXNBbzdzYU5vbHhIUHNaZFI5T0Iyek9hMDVITXdLNFJvOEY2Zw?oc=5

Techzine Global article from the NetApp ONTAP Google News RSS feed. Everpure takes on NetApp in the public cloud - Techzine Global. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
AI

Turn Your Data Estate Into AI Fuel (NVIDIA + NetApp joint session)

Source: https://www.nvidia.com/gtc/session-catalog/sessions/gtc26-s82103/

NVIDIA GTC joint session by NetApp engineers showing how to turn an enterprise data estate into AI fuel: ONTAP as the unified data plane, AI Data Engine for ingest/transformation/embedding, GPUDirect Storage on EF-Series for hot training data, and NIM microservices for inference. Reference blueprints for retail, financial services and manufacturing.

Open source
AI

2026-09-02-why-netapp-ntap-stock-is-up-today-quiver-quantitative

Source: https://news.google.com/rss/articles/CBMid0FVX3lxTE84b0QtWE1qTV8wYzliRTczSUs1bEZDTk42cTE1Y084U1pKbWd1RkQ4NnFCNDFQQUplbEVPMlZVZm1MOXRzb0RpZ196QmFMQWc3WllTc0xkaExCcnRmbVRrcDJKbHFBdTNicGhudk9QbU96aXVFdkln?oc=5

Quiver Quantitative article from the NetApp AI Google News RSS feed. Why NetApp (NTAP) Stock Is Up Today - Quiver Quantitative. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

Remote NetApp array over photonic link nears local access speed (Blocks & Files)

Source: https://www.blocksandfiles.com/2026/08/remote-netapp-array-photonic-link-local-access-speed/

Blocks & Files coverage of an IOWN Global Forum proof of concept: metro-distance access to a NetApp flash array is almost as fast as local access - GPU training time increases under 1% over 3,000 km via photonic links. GPU servers can sit where power is cheap while data stays on NetApp flash in metro datacenters, cutting energy costs up to 30%.

Open source
Advisory

NetApp Advisories Batch — NTAP-20260807-0001 to -0020

Source: security.netapp.com advisory API

Twenty advisories published Aug 7, 2026: four Libssh2 CVEs (CVE-2026-66032/-33/-34/-35), five Linux Kernel issues including CVE-2026-64531, Tar CVE-2026-53655, ten Libssh CVEs (CVE-2026-15370, -59844/-59845/-59847/-59850/-59846/-59848/-59849, etc.), and five Elasticsearch vulnerabilities (CVE-2026-56145, -63136, -63140, -63144, -63263, -56144). Libssh/Libssh2 flaws are relevant to any NetApp product bundling SSH client libraries — verify fix availability per product.

Open source
AI

NetApp Acquires JetStream Software to Advance Cyber Resilience and Data Protection for the AI Era

Source: Yahoo Finance

NetApp acquired JetStream Software to deepen data protection and cyber resilience for AI-era workloads. JetStream's replication/recovery tech strengthens ONTAP's ransomware defense and disaster recovery story at a time when AI pipelines make datasets higher-value attack targets — complementing Autonomous Ransomware Protection and the AI Data Engine stack.

Open source
Advisory

CVE-2026-66035 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0004/

NetApp published this interim advisory covering CVE-2026-66035; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-66034 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0003/

NetApp published this interim advisory covering CVE-2026-66034; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-66033 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0002/

NetApp published this interim advisory covering CVE-2026-66033; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-66032 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0001/

NetApp published this interim advisory covering CVE-2026-66032; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-64531 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0005/

NetApp published this interim advisory covering CVE-2026-64531; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-63263 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0019/

NetApp published this interim advisory covering CVE-2026-63263; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-63144 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0018/

NetApp published this interim advisory covering CVE-2026-63144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-63140 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0017/

NetApp published this interim advisory covering CVE-2026-63140; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-63136 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0016/

NetApp published this interim advisory covering CVE-2026-63136; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59850 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0011/

NetApp published this interim advisory covering CVE-2026-59850; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59849 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0014/

NetApp published this interim advisory covering CVE-2026-59849; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59848 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0013/

NetApp published this interim advisory covering CVE-2026-59848; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59847 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0010/

NetApp published this interim advisory covering CVE-2026-59847; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59846 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0012/

NetApp published this interim advisory covering CVE-2026-59846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59845 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0009/

NetApp published this interim advisory covering CVE-2026-59845; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59844 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0008/

NetApp published this interim advisory covering CVE-2026-59844; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-56145 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0015/

NetApp published this interim advisory covering CVE-2026-56145; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-56144 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0020/

NetApp published this interim advisory covering CVE-2026-56144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-53655 Tar Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0006/

NetApp published this interim advisory covering CVE-2026-53655; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-15370 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0007/

NetApp published this interim advisory covering CVE-2026-15370; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
AI

2026-09-02-netapp-ntap-acquires-software-firm-to-deepen-ai-era-data-protection-yahoo-financ

Source: https://news.google.com/rss/articles/CBMinwFBVV95cUxQQTdBVjBKSjRPU180RDJPel9ZNVNXVENjQnFybEhhdTIyN20tUkN3N1E0cDBHUFlObzlYM0dXbEdUMk91S1QzZUVzTXZaQ0ZsOHJKZldBLU9fSndSN1VGQy11bEV6ZWlCcVNTSGI0eGtUTzFyMjdxWnJBRHg2OHBseVo2YXUtVDAtckxIQWxSRTBRVk04RV9EdXJyRHdRdFE?oc=5

Yahoo Finance article from the NetApp AI Google News RSS feed. NetApp (NTAP) Acquires Software Firm To Deepen AI Era Data Protection - Yahoo Finance. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
News

NetApp buys JetStream Software for Azure-focused VMware DR-as-a-Service

Source: https://www.blocksandfiles.com/public-cloud/2026/08/06/netapp-buys-jetstream-software-for-its-azure-focused-vmware-dr-as-a-service-offering/5284268

NetApp acquired JetStream Software, whose technology powers disaster recovery as a service for VMware workloads on Azure. The deal strengthens NetApp's Azure stack — JetStream's replication/orchestration ties into Azure NetApp Files and Azure VMware Solution for DR orchestration.

Open source
Docs

2026-09-02-ontap-afx-rest-api-reference

Source: https://docs.netapp.com/us-en/ontap-afx/rest/api-reference.html

The AFX REST API reference is the authoritative source for every endpoint exposed by AFX storage systems, surfaced as a Swagger/OpenAPI document that can be loaded directly into API tooling. It is the primary automation entry point for AFX — replacing what classic ONTAP administrators would have done with the ONTAP CLI or the ZAPI interface — and is the recommended path for orchestrating bucket, storage-unit, and protection operations against an AFX cluster from external automation (Ansible, Terraform, custom controllers). For data-platform teams wiring pipelines to land AI training data into AFX S3 buckets, this is the contract that the platform team should pin in their IaC modules.

Open source
Docs

2026-09-02-ontap-afx-manage-s3-buckets

Source: https://docs.netapp.com/us-en/ontap-afx/manage-data/manage-buckets.html

AFX S3 bucket administration covers several routine tasks: editing bucket configuration after creation (capacity, protection, locking, and permissions), managing client access (users, access keys, and bucket policies), and inspecting the bucket for capacity/object counts. The page confirms S3 configuration and support in AFX is the same conceptual model as in classic ONTAP S3 — same protocol, same IAM/user model — but the access surface is through System Manager rather than the ONTAP CLI, which reflects AFX's storage-unit-oriented UX rather than the aggregate/volume hierarchy of classic ONTAP. For AI workloads that read object data from training jobs, this is the day-2 operations surface.

Open source
Docs

2026-09-02-ontap-afx-create-configure-s3-bucket

Source: https://docs.netapp.com/us-en/ontap-afx/manage-data/create-configure-bucket.html

AFX exposes S3 object storage natively on each SVM: in System Manager, navigate to Storage → Buckets, provide the bucket name and capacity, optionally expand "More options" for data-protection, locking, and permission settings, then save. The S3 service on the SVM must already be configured before clients can reach the bucket — the bucket attach step assumes the SVM-side S3 server, users, and TLS are already in place. SnapMirror Cloud backs these buckets to the cloud, so capacity planning should consider the protection target as well as the active bucket size. This is the primary entry point for standing up an S3 data lake on AFX for AI/analytics workloads where data lands in object storage before being read by training pipelines.

Open source
AI

OpenNebula Systems and NetApp partner to power enterprise clouds and AI factories

Source: https://news.google.com/rss/articles/CBMirAFBVV95cUxQb1l1amxqa2R3c3RXcDdpWHpHTFU3azN3QWdNSm9CamlSVGJpU2FTVGtHUTVlYmxZSXVaSVRLbEprVTZZd01MRUhWa2JHeFNEZWh6MHpwSzV1Y1JJQ05pZnhqSjRMV3RqWi1zTnA0NzF1SXg2WE1hQ3laYVFBOVNFay1nZXpHaldBYkIzVFBfaDRsa3F1MlpyanlHYW1NUm9iZ0dkQUhTMjlOSzFV?oc=5

OpenNebula Systems announced a partnership with NetApp to integrate ONTAP-based storage with OpenNebula cloud platforms, targeting enterprise private clouds and "AI factory" buildouts. The tie-up positions NetApp storage as the data foundation for sovereign/private-cloud AI infrastructure.

Open source
AI

OpenNebula Systems and NetApp Partner to Power Enterprise Clouds and AI Factories

Source: AiThority

OpenNebula Systems announced a partnership with NetApp to integrate ONTAP storage with the OpenNebula cloud platform, targeting enterprise private clouds and NVIDIA-accelerated "AI factories". The combination gives organizations a validated open-source stack for standing up GPU clusters backed by NetApp Intelligent Data Infrastructure.

Archive digest
AI

NVIDIA KV cache extenders and partners (Blocks & Files)

Source: https://www.blocksandfiles.com/2026/08/nvidia-kv-cache-extenders-partners/

Blocks & Files coverage of NVIDIA's KV cache extension technology and partner ecosystem: NetApp AIPod with NVIDIA OVX and the AI Data Engine are positioned as the storage-and-orchestration side of offloading LLM inference KV cache to networked flash. Includes benchmarks and reference designs for vLLM inference at scale.

Open source
AI

2026-09-02-opennebula-systems-and-netapp-partner-to-power-enterprise-clouds-and-ai-factorie

Source: https://news.google.com/rss/articles/CBMiwgFBVV95cUxOYWtxZGt5TFE2TV90VU9sTkt5ZVpDVVpsS0RoMkRyVVYzMkw5dVBOZGRzRjg0am9pbzlIV2NMRWgzbXBwTGwwUE40OUNZQTJZbXQ5bXgwR2hnazNtVzFfUlk5dmRJb1d2X3BXTjFsbEZXTVZUbGFDdFMyMU9PSjlTZ2htaGE1QWJpdm1xbnlSYXgxR1ZDOURMeDBuU2tXMnc0aFJiaGdjUExVdDRSdDlBaE9aMzJaanNxZXBNV2tMaF9hUQ?oc=5

AiThority article from the NetApp AI Google News RSS feed. OpenNebula Systems and NetApp Partner to Power Enterprise Clouds and AI Factories - AiThority. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

Nutanix showcases One Platform, One Experience at LEAP Saudi Arabia 2026 (Zawya)

Source: https://www.zawya.com/en/press-release/nutanix-leap-2026-one-platform/

Zawya coverage of Nutanix's LEAP 2026 announcements (direct competitor to NetApp at the same event): 'One Platform, One Experience' consolidates Nutanix Enterprise AI, Cloud Platform and Prism management. Cites Nutanix Enterprise AI 2.8 GA with MCP Gateway as a direct competitor to NetApp's AI Data Engine + AIPod positioning.

Open source
Docs

2026-09-02-whats-new

Source: https://docs.netapp.com/us-en/ontap-systems/whats-new.html

Top-level index of new and changed content across all ONTAP hardware platform documentation (AFF, ASA, FAS, AFX). Use this as the canonical pointer when looking for recently added install, setup, or hardware replacement content for a specific platform.

Open source
AI

StorageReview: Best Storage Arrays 2026 — AI Storage Leaders and Audited Results

Source: StorageReview — https://www.storagereview.com/best/storage-arrays

StorageReview's refreshed buyers guide ranks AI storage array leadership on evidence classes rather than vendor claims: audited benchmark submissions (MLPerf Storage, IO500, SPC-1), vendor-published spec numbers, and its own lab results. NetApp's AI platform section credits the disaggregated AFX all-flash line with the AI Data Engine for GPU data pipelines, AIPod as the NVIDIA-validated reference design, and NVIDIA-Certified Storage launch-partner status with DGX SuperPOD certification. The pointed critique: **NetApp has never submitted to MLPerf Storage**, so unlike HPE it has no audited file/AI benchmarks — a notable credibility gap for AI-array marketing that admins evaluating training-scale storage should weigh against validated-design maturity. Named AI-training-scale deployments are listed as unconfirmed.

Open source
Advisory

July 2026 MySQL Server 9.7.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0019/

NetApp published this interim advisory covering CVE-2026-47008, CVE-2026-61144, CVE-2026-61128, CVE-2026-60718, CVE-2026-60194, CVE-2026-61093, CVE-2026-60181, CVE-2026-60324, CVE-2026-61108, CVE-2026-60174, CVE-2026-60195; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2026 MySQL Server 8.4.0 and 9.7.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0017/

NetApp published this interim advisory covering CVE-2026-60332, CVE-2026-61094, CVE-2026-60188, CVE-2026-60163, CVE-2026-47064, CVE-2026-47023, CVE-2026-60331, CVE-2026-46936, CVE-2026-60184, CVE-2026-61096, CVE-2026-61081, CVE-2026-60185, CVE-2026-60187, CVE-2026-60183, CVE-2026-47012, CVE-2026-60189, CVE-2026-47052, CVE-2026-61109, CVE-2026-60315, CVE-2026-60182, CVE-2026-60191, CVE-2026-60190, CVE-2026-60145, CVE-2026-60747, CVE-2026-60177, CVE-2026-60585, CVE-2026-60178, CVE-2026-60316, CVE-2026-60186; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

July 2026 MySQL Connector/J Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0018/

NetApp published this final advisory covering CVE-2026-60624, CVE-2026-61082, CVE-2026-60623, CVE-2026-60586; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
News

How NetApp's CMO Turned One AI-Generated Ad into a Rethink of Marketing

Source: Chief Marketer via Google News — https://news.google.com/rss/articles/CBMiowFBVV95cUxPTXI4dHUyWHR0VFlSNVlMaGlSUDRlQWJxbW1mTkVVQUVQaDhUM0xpTTdWT0E0VExLV0FtTlkxdG5ESkxJNWhfVE9PVENxeXVJMG93THdmWkJtaHExMU1iaDBibnpTSmRFQXB6ZnZtbVJ3bjNmMUJ5RmpXb1lvemFBUkY4elBEdWY1XzZsNUVWTDRmQm5VME1PZm1QTGhqenpKTFpr?oc=5

Chief Marketer covers NetApp's CMO discussing how an AI-generated ad campaign prompted a broader rethink of marketing production. Interesting side-angle on NetApp's AI brand positioning rather than infrastructure itself.

Open source
Advisory

CVE-2026-9828 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0012/

NetApp published this interim advisory covering CVE-2026-9828; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-9079 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0004/

NetApp published this interim advisory covering CVE-2026-9079; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-9079 Libcurl Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260731-0004

NetApp published security advisory NTAP-20260731-0004 on 2026-07-31, CVE-2026-9079. Libcurl versions 8.8.0 prior to 8.21.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-8927 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0008/

NetApp published this interim advisory covering CVE-2026-8927; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-8926 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0007/

NetApp published this interim advisory covering CVE-2026-8926; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-8925 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0003/

NetApp published this interim advisory covering CVE-2026-8925; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-8925 Libcurl Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260731-0003

NetApp published security advisory NTAP-20260731-0003 on 2026-07-31, CVE-2026-8925. Libcurl versions 8.15.0 prior to 8.21.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-8924 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0006/

NetApp published this interim advisory covering CVE-2026-8924; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-60311 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0020/

NetApp published this interim advisory covering CVE-2026-60311; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-42505 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0010/

NetApp published this interim advisory covering CVE-2026-42505; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-41839 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0014/

NetApp published this interim advisory covering CVE-2026-41839; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-40993 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0011/

NetApp published this interim advisory covering CVE-2026-40993; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39822 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0009/

NetApp published this interim advisory covering CVE-2026-39822; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33630 c-ares Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0015/

NetApp published this interim advisory covering CVE-2026-33630; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3276 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0013/

NetApp published this interim advisory covering CVE-2026-3276; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2026-31633 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0001/

NetApp published this interim advisory covering CVE-2026-31633; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-31633 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260731-0001

NetApp published security advisory NTAP-20260731-0001 on 2026-07-31, CVE-2026-31633. Linux kernel versions 6.16-rc1 through 6.18.22, 6.19-rc1 through 6.19.12, and 6.20-rc1 through 7.0-rc7 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-26143 Microsoft PowerShell Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0016/

NetApp published this interim advisory covering CVE-2026-26143; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11856 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0002/

NetApp published this interim advisory covering CVE-2026-11856; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11856 Libcurl Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260731-0002

NetApp published security advisory NTAP-20260731-0002 on 2026-07-31, CVE-2026-11856. Libcurl versions 7.10.6 prior to 8.21.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-11564 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0005/

NetApp published this interim advisory covering CVE-2026-11564; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11564 Libcurl Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260731-0005

NetApp published security advisory NTAP-20260731-0005 on 2026-07-31, CVE-2026-11564. Libcurl versions 8.17.0 prior to 8.21.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
AI

NetApp launches AI Data Engine to manage enterprise data (Investing.com)

Source: https://news.google.com/rss/articles/CBMi4AFBVV95cUxRUVVSWEtjLVVkQlRqVU5BTTgzcE9kQ0hhRVF5TW9qR3oxVmJvM0FpcU02b2EtZjctM0pCYWJlejZ2eEg5ZXdkWmVCa19vdXpZOVd3VThiYWtvcXZmbEdYNTl3LTJYTmZ0Z0ZPT0FUZ3doYnVNVmxtV3hNWXZRcWJiR0MwZnBhbGtXX0t2Sk13RkRIVFNQa1dTZkVIOWZndGpWWDI5cUJIaDZWQ1ZNbmZtbFhxVTA5V09ENXdHN0UwLU1wbGpHMWdadw

Investing.com coverage of NetApp's AI Data Engine launch: positioning as the enterprise data preparation and embedding layer that turns unstructured and structured data into AI-ready fuel. Discusses integration with EF-Series, ONTAP and StorageGRID, plus the strategic DataPelago acquisition as the GPU-accelerated engine for high-throughput data processing.

Open source
Advisory

CVE-2026-13321 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0001/

NetApp published this interim advisory covering CVE-2026-13321; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-13204 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0006/

NetApp published this interim advisory covering CVE-2026-13204; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11721 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0004/

NetApp published this interim advisory covering CVE-2026-11721; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11622 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0007/

NetApp published this interim advisory covering CVE-2026-11622; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11605 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0009/

NetApp published this interim advisory covering CVE-2026-11605; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11331 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0008/

NetApp published this interim advisory covering CVE-2026-11331; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10822 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0003/

NetApp published this interim advisory covering CVE-2026-10822; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10723 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0002/

NetApp published this interim advisory covering CVE-2026-10723; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260730-0010

Source: https://security.netapp.com/advisory/NTAP-20260730-0010/

NetApp security advisory NTAP-20260730-0010. CVEs: CVE-2026-60005. NGINX versions 1.15.8 prior to 1.30.4 and 1.31 prior to 1.31.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260730-0005

Source: https://security.netapp.com/advisory/NTAP-20260730-0005/

NetApp security advisory NTAP-20260730-0005. CVEs: CVE-2026-12617. ISC BIND versions 9.18.0 through 9.18.50 and 9.20.0 through 9.20.24 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
News

NetApp CPO Syam Nair Tops Pay League With $34M Package

Source: The Register

NetApp's proxy statement ahead of its September annual shareholder meeting reveals Chief Product Officer Syam Nair (ex-Zscaler CTO, joined July 2025) received $34.27M total compensation in fiscal 2026 — out-earning CEO George Kurian. Most of it was a one-time "make-whole" equity grant replacing awards forfeited when he left Zscaler, plus half of a $5M signing bonus. Signals how central product/AI data platform leadership has become to NetApp's strategy.

Open source
AI

2026-09-02-back-of-the-netapp-latest-exec-signing-scores-34m-compensation-package-the-regis

Source: https://news.google.com/rss/articles/CBMiwwFBVV95cUxQUHRUSFJLQmp6V1pyVlNxclFGNzd1Tzc5VVBlTjJjbHZjb2VZU2J2eFQ5ckZSZml1WWhsdkFhaU1yZG1qQkVMY2t0cEpadlNFN0dpcGgxNmVLNkR4Ti1ZSzlUYmpSYnFqeUVGMlR3UDhOQmU4Ui15M04yend6ZmZYbGFDZjdrN1Z3Sy1EVTdTcUJxbkZmWW0xS3J5RGM1RllmMk5uTkthVElEOEVFeHhFVUp6V0N1SWNuX2NMLUh2MzROQlk?oc=5

The Register article from the NetApp AI Google News RSS feed. Back of the NetApp: Latest exec signing scores $34M compensation package - The Register. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

NetApp federates performance-boosted StorageGRIDs into single namespace (Blocks & Files)

Source: https://www.blocksandfiles.com/2026/07/netapp-federates-storagegrids-namespace/

Blocks & Files coverage of NetApp's StorageGRID federation feature: multiple performance-boosted StorageGRID deployments can now be federated into a single namespace, scaling to exabyte-level AI training corpora. Frames the move as a response to the hyperscaler-scale object storage demands of NVIDIA Blackwell training runs.

Open source
Docs

2026-09-04-ontap-9191-release-notes-data-protection

Source: https://docs.netapp.com/us-en/ontap/release-notes/whats-new-9191.html

ONTAP 9.19.1 release highlights (docs.netapp.com, dated 2026-07-28). Data protection: SnapMirror active sync now supports transparent application failover for AIX on 2-node clusters (symmetric active/active, zero RPO); SnapMirror cloud raised to 100 S3 buckets per relationship; SnapMirror synchronous gains tamperproof snapshot locking plus scheduled-snapshot replication to the destination volume. Networking: NFSv4.2 support can now be enabled/disabled per SVM independent of NFSv4.1, with NFSv4.2 on by default on new NFS services; system-defined failover group policy for NAS data LIFs now expands failover targets across the entire broadcast domain and any available node (was: only one other node); ONTAP 9.19.1 ships PRR (default-on) and RACK (opt-in, recommended for ~25 Gbps congested WANs) loss-recovery features into the ONTAP TCP stack for lossy/high-latency WAN links. NAS: more CPU devoted to small-directory (<25K files, <2MB) listings, which removes the need for FlexCache workarounds when hundreds-to-thousands of clients enumerate the same directory simultaneously. SAN: direct-attached FC without switches (FC and FC-NVMe hosts to AFF/ASA/FAS adapter ports), useful in remote/edge sites. S3: conditional writes/deletes with enforcement (prevent object overwrites and unintended deletes); dual S3 user access keys to maintain uptime across access-key rotation. Security: TLS offload for NFS-over-TLS now leverages NIC resources to cut CPU overhead; NFS-over-TLS 1.3 plus optional per-LIF mutual TLS host authentication and export-policy controls to deny non-TLS TCP for matching clients; ARP/AI now protects SnapMirror synchronous (NAS+SAN, FAS/AFF/AFX) and SnapMirror active sync SAN (AFF/ASA r2); WebAuthn `-rp-domains` parameter to lock down the FIDO2 relying-party domain for System Manager MFA; ARP "surge" presentation removed from System Manager UI (CLI/API still surface it) since surge was frequently misread as ransomware. Why it matters: anyone running MetroCluster IP, AFF A-series, ASA, FAS, or AFX on 9.16+ should re-review DR runbooks (active sync covers AIX + NAS SVMs + ARP/AI on sync replication), re-tune NAS LIF failover groups, decide on NFSv4.2 + NFS-over-TLS enablement, and re-baseline ARP alerts off CLI/API rather than the System Manager dashboard.

Open source
AI

2026-09-02-nvidia-forms-37-member-ai-safety-alliance-with-microsoft-spacex-palantir-busines

Source: https://news.google.com/rss/articles/CBMi4AFBVV95cUxNQUxuWWJiMjNhd1BiUkpDY2lDVVZYVlNycTJ2emt6Y19vbEZyWTNyZGtNTmE5Yk9VYy1IZkRCa3VrZVd5ZzN0OUN6VXl5UGlMZkxzRDZCUFN5NmFaVzQ4NHhvRXBPRWlzUTlXSFliblVYclV3V3RScmVCakdoMXpwVGh5Skszck5rLVJaS3dQcUxtV2ZRb0VLZTh3ZlpvRVNTbUcyRURkRU9ockJIVzJibV9UUmdWdHdmNkY3VF9LaklXeGQyb3paV3ViSUNHYzBldlBnU3haMkg3bXVrQ2FhU9IB5gFBVV95cUxPUEtaaW9zNkhUSks5NjVLX1kweXFWVjR6ODRDYjk4YUs0UFlPRVp3Wmhmb2dWR1N6YTlDcXpkYWFDZFFsNGF3cnpmOVNMakFocXJOYTd1Z3ZMVHpiYW15amRKSlQ2V0xKSmMwQWJNZHVudDR0S054dHJ2V0tpODNBbXRTS09fczktSTRuQm4za0NfQ2Y1WmpfdWJ2RTkycmt6akVnNEptTHphV3VsRDc4bm5SVno5Y2R6Z2FpMFRfb0h5YzBoc1VGcHZJRnlNckZrMVRSay1uZlVRLVpSMjR1QnBQczhtdw?oc=5

Business Standard article from the NetApp NVIDIA Google News RSS feed. Nvidia forms 37-member AI safety alliance with Microsoft, SpaceX, Palantir - Business Standard. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

How NetApp Is Simplifying Its Way To An AI-Powered Enterprise

Source: Forbes via Google News — https://news.google.com/rss/articles/CBMisgFBVV95cUxQaE9sZVgwbnBpU0FHcERpbmhyejNEcWZKMV9ReUNxd0g2S0tQWDZ1VUxoTXgtTElaTGxia0NqOWhXN2tCRmxVdWRreVlrN2E4d1lxc2ZWblFieDRJUkpJOXZLektQYUpSV2o2NGpGeUxjcDB1YXpwQkd5ZG90UFZzUHE4eFZQMWxrVW5RU2ZHbEZhaHFycXpBSDNwRHFac2hqQVZBdU43QllETk9xY0VIcEZ3?oc=5

Forbes Council piece on NetApp's approach to enterprise AI adoption: simplify the data foundation first — unified storage, governance, and managed services so companies reach AI value without re-platforming. Useful framing of the Intelligent Data Infrastructure pitch from a strategy angle.

Open source
AI

How NetApp Is Simplifying Its Way To An AI-Powered Enterprise

Source: Forbes

Forbes examines how NetApp is simplifying enterprise paths to AI: consolidating data management under BlueXP/ONTAP, reducing infrastructure sprawl, and packaging AI-ready pipelines (AI Data Engine, NVIDIA partnerships) so customers can stand up GenAI and inference workloads without bespoke integration projects.

Open source
AI

2026-09-02-nvidia-and-tech-giants-launch-ai-security-alliance-securityweek

Source: https://news.google.com/rss/articles/CBMihwFBVV95cUxORktvNl9MRldQYklpNEFGOWl3RW1XSlN4NmdJS19iQnpxbWdFQnZxVHNURkxJZDNCY3pRVlBzV1drLTNReENqR29NV0hoNlpJVFFJRWtqV0VUY05LZWxMS29tbXVJVndDTjVFMGJCWFEtMjJZbzk4Z0xUMWRERTlKMWhmVmZLbHPSAYwBQVVfeXFMTUd1UFlTYWlCWG5TWE9RZTlVb3JGeHM2NUVCRERnMzYwN3o2UnM2bmJ1NnQxRFZMcHBJdHZMUW43Wm1TTzFkNHhLWUk1Unc4eW0taW9TV3hWNmZVUlpUc01TWGEwbG9UTFpYZHRpY1FFajVmQnpJdy1LV2FzRUxlNF9rb3B4Smt3bUpJVEo?oc=5

SecurityWeek article from the NetApp NVIDIA Google News RSS feed. Nvidia and Tech Giants Launch AI Security Alliance - SecurityWeek. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-industry-leaders-unite-in-open-secure-ai-alliance-for-ai-safety-and-security-blo

Source: https://news.google.com/rss/articles/CBMiZEFVX3lxTE1jbERSYTYzMDlvaExvNHBYWTZrU2Zfd210S2U0NHAyMDBqWG5DS0hkenZPaUgxVDcxcEtPUUhrbVhObUpvQzV2b0VKSzRjOF9sMW9WdW03ZVhyUC1TaG5XVGdHS3Q?oc=5

blogs.nvidia.com article from the NetApp NVIDIA Google News RSS feed. Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security - blogs.nvidia.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-how-netapp-is-simplifying-its-way-to-an-ai-powered-enterprise-forbes

Source: https://news.google.com/rss/articles/CBMisgFBVV95cUxQaE9sZVgwbnBpU0FHcERpbmhyejNEcWZKMV9ReUNxd0g2S0tQWDZ1VUxoTXgtTElaTGxia0NqOWhXN2tCRmxVdWRreVlrN2E4d1lxc2ZWblFieDRJUkpJOXZLektQYUpSV2o2NGpGeUxjcDB1YXpwQkd5ZG90UFZzUHE4eFZQMWxrVW5RU2ZHbEZhaHFycXpBSDNwRHFac2hqQVZBdU43QllETk9xY0VIcEZ3?oc=5

Forbes article from the NetApp AI Google News RSS feed. How NetApp Is Simplifying Its Way To An AI-Powered Enterprise - Forbes. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

Vultr Adopts NVIDIA Rubin, NVIDIA Dynamo, NVIDIA Nemotron (businesswire)

Source: https://www.businesswire.com/news/vultr-nvidia-rubin-dynamo-nemotron/

BusinessWire coverage of Vultr adopting NVIDIA Rubin platform, NVIDIA Dynamo (inference software), and NVIDIA Nemotron models for enterprise AI inference services. Includes a competitive comparison noting that Vultr uses NetApp ONTAP for backend storage of inference context, positioning NetApp as the data layer for the emerging NVIDIA-centric inference ecosystem.

Open source
Advisory

June 2026 Apache Netty 4.2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0013/

NetApp published this interim advisory covering CVE-2026-44892, CVE-2026-44894, CVE-2026-48748, CVE-2026-50009; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2026 Java Platform Standard Edition 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0016/

NetApp published this interim advisory covering CVE-2026-47059, CVE-2026-47027, CVE-2026-46968, CVE-2026-60147, CVE-2026-47063, CVE-2026-47010, CVE-2026-47021; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights and Data Secure Storage Workload Security Agent.

Open source
Advisory

July 2026 Java Platform Standard Edition 8u491, 8u491-perf, 11.0.31 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0017/

NetApp published this interim advisory covering CVE-2026-47057, CVE-2026-47058; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2026 Java Platform Standard Edition 8u491 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0020/

NetApp published this interim advisory covering CVE-2026-60164, CVE-2026-47034, CVE-2026-47013, CVE-2026-47035, CVE-2026-60166, CVE-2026-47030; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-60526 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0018/

NetApp published this interim advisory covering CVE-2026-60526; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58052 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0011/

NetApp published this interim advisory covering CVE-2026-58052; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2026-49844 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0012/

NetApp published this interim advisory covering CVE-2026-49844; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46307 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0006/

NetApp published this interim advisory covering CVE-2026-46307; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46306 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0009/

NetApp published this interim advisory covering CVE-2026-46306; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46304 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0008/

NetApp published this interim advisory covering CVE-2026-46304; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46303 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0007/

NetApp published this interim advisory covering CVE-2026-46303; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-44432 Urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0003/

NetApp published this interim advisory covering CVE-2026-44432; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-44431 Urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0004/

NetApp published this interim advisory covering CVE-2026-44431; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33413 Etcd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0005/

NetApp published this final advisory covering CVE-2026-33413; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-15995 IBM Cognos Analytics Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0014/

NetApp published this final advisory covering CVE-2026-15995; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260724-0010

Source: https://security.netapp.com/advisory/NTAP-20260724-0010/

NetApp security advisory NTAP-20260724-0010. CVEs: CVE-2026-14266. 7-Zip versions prior to 26.02 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260724-0002

Source: https://security.netapp.com/advisory/NTAP-20260724-0002/

NetApp security advisory NTAP-20260724-0002. CVEs: CVE-2026-33845, CVE-2026-33846, CVE-2026-3833. GnuTLS versions prior to 3.8.13 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260724-0001

Source: https://security.netapp.com/advisory/NTAP-20260724-0001/

NetApp security advisory NTAP-20260724-0001. CVEs: CVE-2026-42533. NGINX versions 1.15.8 through 1.30.3 and 1.31 through 1.31.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
AI

2026-09-02-netapp-snaps-up-datapelago-to-bolster-ai-data-infrastructure-portfolio-it-pro

Source: https://news.google.com/rss/articles/CBMiswFBVV95cUxPYlExclA4UGdJcXNuaEJYaVBmWmlXdUhPSXQwa2RzUmRmU1dFZUx3Uk00REVFZzNGYkROZTAxa2NZdzFoYTQ4cmZFRGZlQUVBdEs3c1dFem1CcHI0MmFKLUQyVENxbzA3cWJva3AtSHJTTVRWOENld0tsTG9VdWl5N3M4ZXdydjJSdmo4UVBOR2wxV3VRQXR3SVYxdWgxWG1ONk9mWVVJU3VxYTk4YTI5TFJqaw?oc=5

IT Pro article from the NetApp AI Google News RSS feed. NetApp snaps up DataPelago to bolster AI data infrastructure portfolio - IT Pro. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-netapp-acquires-datapelago-orrick-com

Source: https://news.google.com/rss/articles/CBMic0FVX3lxTE55RlRPZENQRzBMc1FmajRJcWNmOXpkWjlaWnJKRWxZN2tMblVOSlpPUjVPek1CLUVHV2F0Smt4RHhCR0w4SXplZHBOV2J4cEpLT0NDTDdYR19pU1kxWUJ4OG9adUl4aUdZT1BCemlvdzhqYjA?oc=5

orrick.com article from the NetApp AI Google News RSS feed. NetApp Acquires DataPelago - orrick.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-netapp-buys-datapelago-to-boost-ai-data-processing-it-brief-asia

Source: https://news.google.com/rss/articles/CBMigwFBVV95cUxOUFpfNnVRa3pOSHNOSHZmWU55aU1CektLVmVSSWVCblQtTWJtSWYtblp4aXFrTndVS2ptUlF3aGlyNHJpZVdpN29FdE4wS3NnM0VFemp3TGVxNjdDb2JvLUFOSWhSa1hpQjE0TVpLREpKbkxoQUdDN1NlR3ZDRVJEYjYyQQ?oc=5

IT Brief Asia article from the NetApp AI Google News RSS feed. NetApp buys DataPelago to boost AI data processing - IT Brief Asia. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-netapp-acquires-datapelago-making-data-ai-ready-at-the-infrastructure-layer-cxot

Source: https://news.google.com/rss/articles/CBMisgFBVV95cUxQNVE2ejJ5OXBkUk9KcUlrQ09tMkhKMURibzBUNzFMcDJjVFNtdXlKOWJRaHdOaGVwc1V0ZDNjUUdyS3dqVjQ4cGpTMExiVjRXQnRmTU5fSV8zcjhNem9yd29lVzlPOVk1NzlyRVlsQTBFN1hlRkdieFpZbl9CNUp5N21qVWtMdzZkX0pUWFBNMlFjcFZQMkpkOVVRR1JtS2YwZGFRaFhpWnZobXNFbndHRTR3?oc=5

CXOToday.com article from the NetApp NVIDIA Google News RSS feed. NetApp Acquires DataPelago, Making Data AI-Ready at the Infrastructure Layer - CXOToday.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

July 2026 OpenSSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0012/

NetApp published this interim advisory covering CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; ONTAP Select Deploy administration utility.

Open source
Advisory

July 2026 IBM Db2 IBM Semeru Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0008/

NetApp published this final advisory covering CVE-2026-22021, CVE-2026-22013, CVE-2026-22007; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-9762 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0003/

NetApp published this final advisory covering CVE-2026-9762; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-7771 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0006/

NetApp published this final advisory covering CVE-2026-7771; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6653 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0020/

NetApp published this interim advisory covering CVE-2026-6653; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59084 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0019/

NetApp published this interim advisory covering CVE-2026-59084; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59083 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0018/

NetApp published this interim advisory covering CVE-2026-59083; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-4800 Lodash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0010/

NetApp published this interim advisory covering CVE-2026-4800; the API labels exploitation information as **Public**. The API currently lists affected products as: Storage Manager for ProxMox.

Open source
Advisory

CVE-2026-46333 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0009/

NetApp published this interim advisory covering CVE-2026-46333; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-41854 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0017/

NetApp published this interim advisory covering CVE-2026-41854; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-41417 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0004/

NetApp published this final advisory covering CVE-2026-41417; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34479 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0007/

NetApp published this final advisory covering CVE-2026-34479; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1299 CPython Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0014/

NetApp published this interim advisory covering CVE-2026-1299; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-10695 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0002/

NetApp published this final advisory covering CVE-2026-10695; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10535 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0005/

NetApp published this final advisory covering CVE-2026-10535; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
AI

2026-09-02-netapp-datapelago-deal-ups-ai-data-management-ante-techtarget

Source: https://news.google.com/rss/articles/CBMirwFBVV95cUxNaEt4WmhFd0ZfRkl1UDZjRjFiSUxNVkFzXzFYaEZtbGR0WHVuVHU5aE1yTzVVVkdrSV85QndlMHA4dFJEV2Q0eTliWkZvSUNueS1JZVhxLWo2YmoyTF9ZalRibTdNdUdTTzE2X3ZFeWUtQTdMdTlVenNrMGFTYXJZVGZ3cHN0Tm1TSE1sdWczbkl1a3laX3lWVV85RHBzQ3pub2o0UHJvbmY4UlpVbnBn?oc=5

TechTarget article from the NetApp AI Google News RSS feed. NetApp-DataPelago deal ups AI data management ante - TechTarget. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

2026-09-01-ntap-20260717-0016

Source: https://security.netapp.com/advisory/NTAP-20260717-0016/

NetApp security advisory NTAP-20260717-0016. CVEs: CVE-2026-15308. CPython versions prior to 3.15.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260717-0015

Source: https://security.netapp.com/advisory/NTAP-20260717-0015/

NetApp security advisory NTAP-20260717-0015. CVEs: CVE-2026-6100. Certain versions of CPython are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260717-0013

Source: https://security.netapp.com/advisory/NTAP-20260717-0013/

NetApp security advisory NTAP-20260717-0013. CVEs: CVE-2026-27448. pyOpenSSL versions 0.14 prior to 26.0.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260717-0011

Source: https://security.netapp.com/advisory/NTAP-20260717-0011/

NetApp security advisory NTAP-20260717-0011. CVEs: CVE-2026-27135. Nghttp2 versions prior to 1.68.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
AI

2026-09-02-netapp-acquires-datapelago-to-embed-gpu-accelerated-data-processing-at-the-stora

Source: https://news.google.com/rss/articles/CBMirAFBVV95cUxNdU84V295RWNncjlMUDYtOFpQLW5NMUpZVmxYSkx3QlV0T015SnNUbVQyZDgyU1kxNkNibFZOVlFYZ1lSUDRieGh1Z2RMcWlIcEh6NFhpRXRBMWVuQ0ZkeUNpS3RYa1dQVm83UDU3WktUb2U1ZUtLN3JlZW1ROWRMZm1TLVVSZDRNLUpud0hxbzRjck8ybFNTOVlwN0ZXQVpzUmtPSVJqbklIQm5M0gGyAUFVX3lxTE1PcVRsaW5rQ3NnX2xJcFh5VXNFNVZBLTExYTA1Ykc3LXJVdVF6Qkw2RXJhbDFCbVVOeU4tUHprcEMtX3RXX0YxMGlqY21URjc1ZjNvelh1QUxZTlNIUVZNNG5kd1hYeExoUVMtUzlrNTFMT09lYTN1Z05nZ1BKc0VVN3AteEwtSGhtOVhPODU2OHlXaEFDWkE1SjNVQWdPTE83QUlrckRnRHFYZFQwZFdiRmc?oc=5

Pulse 2.0 article from the NetApp AI Google News RSS feed. NetApp Acquires DataPelago To Embed GPU-Accelerated Data Processing At The Storage Layer - Pulse 2.0. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Docs

Manage storage consumption at scale using quotas on Amazon FSx for NetApp ONTAP

Source: https://news.google.com/rss/articles/CBMitwFBVV95cUxPRU9fSUctZngyRG15U3BUa3VRX3J5YjlXS1l4ak1XZEUwZmVhb2FSOXgzOVhFTU00SzdhMHpia0cwbllqbWtGX0tWSVRlUjFoWHlGZXlnRFFwQlFTekZmQWlkTXlzYjd0Q0IzeUZfR0R5N0R3U0YwQUUxejhRY0h5ZTQzRXVfLUZlZ0RacVBuZnh2ZjNhQTY2dnc2QVBPejZfVXBQcWlSbjh3ZG9UZW5UYkVaT2I4X0U?oc=5

AWS published guidance on applying user/group, quota rules, and default quotas at scale on Amazon FSx for NetApp ONTAP volumes. Useful reference for capacity governance on FSxN — mirrors classic ONTAP quota concepts in a fully managed service.

Open source
Docs

2026-09-02-ontap-whats-new-9191

Source: https://docs.netapp.com/us-en/ontap/release-notes/whats-new-9191.html

Official NetApp ONTAP 9.19.1 release notes listing new features and changes for NAS, SAN, S3, data protection, networking, security, system manager, and storage resource management. The release is the latest feature drop in the ONTAP 9.x stream and is required reading before any 9.19.1 upgrade.

Open source
Docs

2026-09-02-ontap-afx-whats-new-9191

Source: https://docs.netapp.com/us-en/ontap-afx/release-notes/whats-new-9191.html

AFX-specific 9.19.1 release notes. Covers S3 object storage enhancements, REST API additions, security, performance, data protection, and the cluster upgrade path for AFX systems. Use this page in tandem with the main ONTAP 9.19.1 release notes to plan AFX-specific upgrades.

Open source
News

2026-09-02-netapp-sees-banking-telecom-fueling-india-s-ai-infrastructure-boom-analyticsindi

Source: https://news.google.com/rss/articles/CBMiqwFBVV95cUxPTE5rZTViNk1EWEtFaEE3YVplWG5iMEF3NFVjek52V1FLT0Y0bFNHc0YxTW42WUFXNm02LTNBNzQyb1dGaURCc1RlbF9sNy1hcHlGRFY2QjdmN2QzbDJMU2tLSXlEVGZ1T3VqYVlaYWFraUhSejFuSk9ncHBQSVAwaThxdmhHaDIwLUlYM0dQV0dEd2QwcG9FS3d5OUNrRGJJSXgxSkI3cGR4Smc?oc=5

analyticsindiamag.com article from the NetApp ONTAP Google News RSS feed. NetApp Sees Banking, Telecom Fueling India’s AI Infrastructure Boom - analyticsindiamag.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
AI

Aston Martin Aramco F1 Team, CoreWeave, NetApp: racing for a storage advantage

Source: https://news.google.com/rss/articles/CBMi9AFBVV95cUxOZnNxN1A4bGVaQ201SHVyQzlSUno1T3FqX2dlUWZRNlVfQV95TGhETkhzWUVpQ0Iyai1fblNEM0FhNkYxT1V4c25xdkN6RVFpTjZfajgtV29oVnNUUEpQZlZKY0VJVzRhSmQ1Z1VySU8xc0ZiWHlSWnZydWhha1FWUmFROWFUYm9fTnl5OGdNeHh5LVF5ZFloZTZUSGhWS2JGZmRqNU8zYklWd0pLc0VOXzY3T3BwOWdSU2d0V0J3YzE3N2tjdFpLNndxOVpEeVR5ZDY4U0pqRHJNQ1ZwSF9xR0pIcFFKb01IcUt5dGZvdC1Ma0hP?oc=5

Blocks & Files examines how Aston Martin's Aramco Formula One Team uses NetApp storage alongside CoreWeave GPU cloud for aerodynamics and race-strategy simulation workloads — a flagship example of hybrid on-prem + cloud AI infrastructure where low-latency ONTAP feeds GPU clusters.

Open source
Advisory

June 2026 FreeBSD posixshm Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0009/

NetApp published this final advisory covering CVE-2026-49427, CVE-2026-49428; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 FreeBSD iconv Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0004/

NetApp published this final advisory covering CVE-2026-58081, CVE-2026-58082; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-53359 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0017/

NetApp published this interim advisory covering CVE-2026-53359; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-49426 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0008/

NetApp published this final advisory covering CVE-2026-49426; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49425 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0005/

NetApp published this final advisory covering CVE-2026-49425; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49424 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0006/

NetApp published this final advisory covering CVE-2026-49424; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49423 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0007/

NetApp published this final advisory covering CVE-2026-49423; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49422 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0015/

NetApp published this final advisory covering CVE-2026-49422; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49421 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0010/

NetApp published this final advisory covering CVE-2026-49421; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49420 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0011/

NetApp published this final advisory covering CVE-2026-49420; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49419 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0013/

NetApp published this final advisory covering CVE-2026-49419; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49418 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0014/

NetApp published this final advisory covering CVE-2026-49418; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49415 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0012/

NetApp published this final advisory covering CVE-2026-49415; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49261 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0016/

NetApp published this interim advisory covering CVE-2026-49261; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46242 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0020/

NetApp published this interim advisory covering CVE-2026-46242; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-43503 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0019/

NetApp published this interim advisory covering CVE-2026-43503; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-43499 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0018/

NetApp published this interim advisory covering CVE-2026-43499; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-40023 Apache Log4cxx Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0003/

NetApp published this interim advisory covering CVE-2026-40023; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34478 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0002/

NetApp published this interim advisory covering CVE-2026-34478; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights and Data Secure Storage Workload Security Agent.

Open source
Docs

2026-09-03-ontap-afx-expand-cluster

Source: https://docs.netapp.com/us-en/ontap-afx/administer/expand-cluster.html

AFX clusters let you grow compute capacity independently of storage capacity, and the expansion is non-disruptive — performance scales linearly as Automated Topology Management (ATM) rebalances volumes across the new nodes. ATM uses Zero Copy Volume Move (ZCVM) to relocate volumes via metadata updates instead of copying data, which is the default volume-move technology on AFX. Coverage walks through the prerequisites (cluster admin credentials, SSH to the ONTAP CLI, an even number of new nodes per release-size limits), the troubleshooting scenarios you can hit while volumes are moving (volumes stuck because the cluster is already balanced, ATM seemingly idle because it polls every ~5 minutes and a rebalance can launch up to 40 minutes after the last one), and the CLI commands to monitor expansion. A real how-to for operators scaling AFX in production.

Open source
Docs

2026-09-03-ontap-afx-display-svms

Source: https://docs.netapp.com/us-en/ontap-afx/administer/display-svms.html

Short but useful reference for the basic AFX administrative workflow of viewing the storage virtual machines (data SVMs) configured in an AFX cluster — each SVM gives you an isolated environment for organizing data and presenting client access. The procedure is simple in System Manager: open Cluster, then Storage VMs, hover over the SVM you want to inspect, and the menu exposes primary admin actions (start/stop the SVM) plus a per-SVM detail pane covering overview, settings, replication, and file system. Cross-references include the related configure-SVM and ONTAP SVM concepts pages. A good companion piece for the create-configure-volume and create-configure-bucket how-tos already in the library.

Open source
Docs

2026-09-02-ontap-afx-cluster-setup-workflow

Source: https://docs.netapp.com/us-en/ontap-afx/install-setup/cluster-setup.html

After AFX hardware is installed, the ONTAP cluster setup proceeds in four sequential configuration phases: discover the cluster network, set the admin password, configure the cluster/controller IP addresses and subnet masks, and configure DNS/NIS plus optional NTP and cluster encryption. Initial setup is done from a laptop connected to the AFX management switch using System Manager, then cluster setup is completed with three more configuration areas. Core prerequisites include a unique IPv4 cluster-management address, network gateway, DNS domain and name servers, and NTP servers — items an AFX admin should gather before the install window.

Open source
Advisory

2026-09-01-ntap-20260710-0001

Source: https://security.netapp.com/advisory/NTAP-20260710-0001/

NetApp security advisory NTAP-20260710-0001. CVEs: CVE-2026-42253, CVE-2026-42588, CVE-2026-45505, CVE-2026-46605, CVE-2026-49157, CVE-2026-49270. Apache ActiveMQ versions prior to 5.19.7 and 6.0.0 prior to 6.2.5 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Community

S&P Global's disaster recovery strategy using Amazon FSx for NetApp ONTAP snapshots

Source: AWS Database Blog via Google News — https://news.google.com/rss/articles/CBMi0AFBVV95cUxQczY4QnBVbHRGd1BRWVcyZUZvdnVGOXNnTkFZQWtFeC1HNVc1c2Y3LTNEVTlpdk1HYm5oRDJ0dlFCTUtoNlpWMWZCbW90cmxSQWJPQnFBQ25JLVRQaW02NldiMWVFN25mSjJHbkRvYW92LXJvS3ZvUXhxQjVPcHlqcEhYVjB0ZTdBb3NHdWZpUElKWl9odzVPZW9zTmRfOWJDUGhSb1B1UGxIVU5PTEEwb1N4SmFWVUZrR3FWaFYyNVNKOVV0UlJkUk4wVlFaVVpa?oc=5

AWS case study: S&P Global builds DR on FSx for ONTAP snapshots — a real-world example of ONTAP snapshot semantics (fast, space-efficient, application-consistent restores) carrying enterprise-grade recovery objectives in the cloud. Good reference material for DR design questions.

Open source
Advisory

October 2025 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0007/

NetApp published this interim advisory covering CVE-2025-58183, CVE-2025-58185, CVE-2025-58186, CVE-2025-58188, CVE-2025-58189, CVE-2025-61723, CVE-2025-61724, CVE-2025-61725; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; ONTAP tools for VMware vSphere 10.

Open source
Advisory

March 2026 Erlang/OTP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0005/

NetApp published this final advisory covering CVE-2026-23941, CVE-2026-23942, CVE-2026-23943; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

June 2026 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0016/

NetApp published this interim advisory covering CVE-2026-50229, CVE-2026-55956; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2026 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0006/

NetApp published this interim advisory covering CVE-2025-61728, CVE-2025-61730, CVE-2025-61731, CVE-2025-68119; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-55957 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0014/

NetApp published this interim advisory covering CVE-2026-55957; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-55955 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0015/

NetApp published this interim advisory covering CVE-2026-55955; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-55276 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0018/

NetApp published this interim advisory covering CVE-2026-55276; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-55200 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0020/

NetApp published this interim advisory covering CVE-2026-55200; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-53434 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0013/

NetApp published this interim advisory covering CVE-2026-53434; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-53404 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0017/

NetApp published this interim advisory covering CVE-2026-53404; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46331 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0002/

NetApp published this interim advisory covering CVE-2026-46331; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45491 .Net Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0009/

NetApp published this interim advisory covering CVE-2026-45491; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45490 .Net Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0008/

NetApp published this interim advisory covering CVE-2026-45490; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34481 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0012/

NetApp published this interim advisory covering CVE-2026-34481; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights and Data Secure Storage Workload Security Agent.

Open source
Advisory

CVE-2026-34479 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0011/

NetApp published this interim advisory covering CVE-2026-34479; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights and Data Secure Storage Workload Security Agent.

Open source
Advisory

CVE-2026-31718 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0001/

NetApp published this interim advisory covering CVE-2026-31718; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15661 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0019/

NetApp published this interim advisory covering CVE-2025-15661; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-24990 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0004/

NetApp published this interim advisory covering CVE-2024-24990; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24989 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0003/

NetApp published this interim advisory covering CVE-2024-24989; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
AI

2026-09-02-netapp-enterprise-ai-demand-is-creating-a-materially-new-growth-trajectory-nasda

Source: https://news.google.com/rss/articles/CBMitwFBVV95cUxOUE96NXV1ZUg0QXVrWGt0YnM5UmJTaUdRd292WmdCV0o0SFU3SzJ5cDlNUnN1Y1Rxa0tYQV90bFlFRFo3VFFORzMzXzBzeTJrQlBHT0QwSFJMUThMenIxc0NGWm5ZOWcwbnFLWHJkcV9vbEZfVm93MFNEeFRTSnVxMWxZakJ0eFl5MW5MWUJSNEVaa2JtalpTSHZmUFZIZ053ampVbnBHRjlHb3Z2MUhrMVNtcXRwX0k?oc=5

Seeking Alpha article from the NetApp AI Google News RSS feed. NetApp: Enterprise AI Demand Is Creating A Materially New Growth Trajectory (NASDAQ:NTAP) - Seeking Alpha. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Docs

Supported AFF, ASA, and FAS controller upgrade paths

Source: https://docs.netapp.com/us-en/ontap-systems-upgrade/upgrade-arl/

NetApp's ARL selector maps supported controller replacements and minimum ONTAP levels, including A20 to A30/A50, A30 to A50, C30 to C60, A70 to A90, and FAS70 to FAS90 paths on newer trains. Older systems can have hard version ceilings, so a controller refresh may require a carefully staged ONTAP upgrade rather than a direct swap.

Open source
Docs

ONTAP REST API 9.16.1 adds identity, ARP, qtree, and S3 endpoints

Source: https://docs.netapp.com/us-en/ontap-automation/whats-new.html

ONTAP 9.16.1 added more than two dozen REST calls, notably Microsoft Entra ID group and role mappings, WebAuthn administration, ARP package management, optional qtree performance metrics, and S3 bucket snapshots. NetApp also warns that ASA r2 exposes a different REST API from AFF, FAS, and classic ASA systems.

Open source
Docs

2026-09-04-ontap-systems-whats-new

Source: https://docs.netapp.com/us-en/ontap-systems/whats-new.html

ONTAP hardware-systems what's-new (dated 2026-07-01). Two material additions. AFX 2K — a new disaggregated all-flash storage system extending the AFX line, targeted at high-performance NAS and S3 workloads including AI/ML applications. Ships with Cisco 9808 switches that link AFX 2K controller nodes to storage shelves; the 9808 joins Cisco 9364D-GX2A and 9332D-GX2B as the third switch family that lets you build ONTAP clusters of more than two nodes. VLAN tagging + multi-path + tech-refresh configurations underly the design. Hot-swap I/O modules (Jan 2026 update): supported on ONTAP 9.18.1 GA and later across AFF A1K/A20/A30/A50/A70/A90, ASA r2 A1K/A20/A30/A50/A70/A90/C30, AFF C30/C60/C80, FAS50/FAS70/FAS90, and AFX 1K. You can hot-swap a failed Ethernet I/O module in any slot whose ports are used for cluster, HA, or client connections — *not* for storage or MetroCluster connections. ONTAP 9.17.1 or 9.18.1RC also gains hot-swap for adjacent combinations but with constraints. Why it matters: AFX 2K is a significant new piece of kit for AI/ML customers that need NAS+S3 throughput at scale; existing AFF A1K/A9x/A70/A50/ASA r2 A-series customers now have a non-disruptive I/O module replacement path which previously required planned downtime.

Open source
AI

2026-09-02-the-most-dangerous-thing-is-the-illusion-of-knowledge-speaking-to-shereen-bhan-o

Source: https://news.google.com/rss/articles/CBMitgFBVV95cUxNbDdQdmNCaGlkd25kTnZyOHZWQ1B6QXBEaEltSVJPdDZVNzlNazNBOWt3NWlhQVk0V0JEUTNVSFRVNGN5NXpPYldjNWs1MWV2UU95eDNLTUl0M0EzRUVUTS1aZHdDTGdYb3ZuNUJMOEo1bUxDS2JUSnhlcXp6YWJXbURNN3pFNXVzZHhaN3l0YmNJQlU5Z1A2ektCQnQxbzVCTnowanlFd2Rpc1c2T0Jwdms3Q3dzUQ?oc=5

LinkedIn article from the NetApp AI Google News RSS feed. ‘The most dangerous thing is the illusion of knowledge.’ Speaking to Shereen Bhan on Voices From The Valley, George Kurian, CEO of NetApp, addresses rising anxiety around AI and the future of jobs. He. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

May 2026 Apache Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0019/

NetApp published this interim advisory covering CVE-2026-41417, CVE-2026-42578, CVE-2026-42579, CVE-2026-42580, CVE-2026-42581, CVE-2026-42583, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586, CVE-2026-42587, CVE-2026-44248; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

June 2026 IBM Db2 Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0008/

NetApp published this final advisory covering CVE-2026-33871, CVE-2026-42583, CVE-2026-42580, CVE-2026-42581, CVE-2026-42584, CVE-2026-42585, CVE-2026-42587, CVE-2026-33870; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 IBM Db2 Bouncy Castle Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0006/

NetApp published this final advisory covering CVE-2025-14813, CVE-2026-5598, CVE-2026-5588; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 IBM Db2 Apache Log4j Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0009/

NetApp published this final advisory covering CVE-2026-34480, CVE-2026-34477, CVE-2026-34478; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 Golang.Org/X/Net Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0012/

NetApp published this interim advisory covering CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-42502, CVE-2026-42506; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 FreeBSD Unbound Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0001/

NetApp published this final advisory covering CVE-2026-32792, CVE-2026-33278, CVE-2026-40622, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42944, CVE-2026-42959, CVE-2026-42960, CVE-2026-44390, CVE-2026-44608; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 FreeBSD Sound Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0002/

NetApp published this final advisory covering CVE-2026-45258, CVE-2026-49417; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 Apache Netty 4.1 and 4.2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0020/

NetApp published this interim advisory covering CVE-2026-44249, CVE-2026-44250, CVE-2026-44890, CVE-2026-44893, CVE-2026-48006, CVE-2026-48043, CVE-2026-48059, CVE-2026-50010, CVE-2026-50011, CVE-2026-50020, CVE-2026-50560, CVE-2026-45416, CVE-2026-45536, CVE-2026-45673, CVE-2026-45674, CVE-2026-46340, CVE-2026-47244, CVE-2026-47691; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49759 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0014/

NetApp published this interim advisory covering CVE-2026-49759; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility; SnapCenter.

Open source
Advisory

CVE-2026-49413 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0003/

NetApp published this final advisory covering CVE-2026-49413; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46863 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0016/

NetApp published this interim advisory covering CVE-2026-46863; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

CVE-2026-45259 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0005/

NetApp published this final advisory covering CVE-2026-45259; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45256 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0004/

NetApp published this final advisory covering CVE-2026-45256; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-40971 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0018/

NetApp published this interim advisory covering CVE-2026-40971; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39827 Golang.Org/X/Crypto Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0013/

NetApp published this interim advisory covering CVE-2026-39827; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-28808 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0015/

NetApp published this final advisory covering CVE-2026-28808; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11906 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0010/

NetApp published this final advisory covering CVE-2026-11906; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10109 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0007/

NetApp published this final advisory covering CVE-2026-10109; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36372 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0011/

NetApp published this final advisory covering CVE-2025-36372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260626-0017

Source: https://security.netapp.com/advisory/NTAP-20260626-0017/

NetApp security advisory NTAP-20260626-0017. CVEs: CVE-2026-2303. Multiple NetApp products incorporate MongoDB Drivers. MongoDB Drivers versions prior to 1.17.7 and 2.0.0-alpha1 prior to 2.4.2 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Product

NetApp Federates Performance-Boosted StorageGRIDs into a Single Namespace

Source: Blocks & Files (via Google News)

Blocks & Files details NetApp federating multiple performance-tuned StorageGRID systems into one global namespace for greater scale — letting organizations grow object storage capacity and throughput across sites while presenting a single S3 endpoint. Relevant for FabricPool tiering and large AI data lakes built on object storage.

Open source
AI

2026-09-02-netapp-sk-telecom-test-ai-workloads-on-virtual-machines-techinasia-com

Source: https://news.google.com/rss/articles/CBMijAFBVV95cUxOb3N1aVAyb3hWTERvNTlHQ3I1V2pKZmV1YTBDNkNKVERTRWthM2xfdFExNUhRT1dGLUtXYm94NzNCR0ZzZUpxZi05X1l1YTVOak1oYW5VbnEzMnExRzR0NHBoSnVuSWk0ekd1TnloZm8wRV81VDA3Q0Q0YnZJRnNjQTA3MnM0czlWSV9wcg?oc=5

techinasia.com article from the NetApp NVIDIA Google News RSS feed. NetApp, SK Telecom test AI workloads on virtual machines - techinasia.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

CVE-2026-49416 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0019/

NetApp published this final advisory covering CVE-2026-49416; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49414 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0017/

NetApp published this final advisory covering CVE-2026-49414; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49412 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0018/

NetApp published this final advisory covering CVE-2026-49412; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-48095 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0001/

NetApp published this interim advisory covering CVE-2026-48095; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-45257 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0020/

NetApp published this final advisory covering CVE-2026-45257; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-42501 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0004/

NetApp published this interim advisory covering CVE-2026-42501; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-42499 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0003/

NetApp published this interim advisory covering CVE-2026-42499; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39836 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0005/

NetApp published this interim advisory covering CVE-2026-39836; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39826 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0007/

NetApp published this interim advisory covering CVE-2026-39826; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39825 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0011/

NetApp published this interim advisory covering CVE-2026-39825; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39823 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0008/

NetApp published this interim advisory covering CVE-2026-39823; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39819 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0010/

NetApp published this interim advisory covering CVE-2026-39819; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39817 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0009/

NetApp published this interim advisory covering CVE-2026-39817; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33748 Moby/Buildkit Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0014/

NetApp published this interim advisory covering CVE-2026-33748; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33747 Moby/Buildkit Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0013/

NetApp published this interim advisory covering CVE-2026-33747; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-27145 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0006/

NetApp published this interim advisory covering CVE-2026-27145; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights Telegraf Agent; NetApp Kubernetes Monitoring Operator; Trident; Trident Protect.

Open source
Advisory

CVE-2026-27139 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0012/

NetApp published this interim advisory covering CVE-2026-27139; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10846 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0016/

NetApp published this final advisory covering CVE-2026-10846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-10263 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0015/

NetApp published this final advisory covering CVE-2025-10263; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 Apache CXF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260618-0004/

NetApp published this interim advisory covering CVE-2026-49875, CVE-2026-50623, CVE-2026-50627, CVE-2026-50628, CVE-2026-50629, CVE-2026-50630, CVE-2026-50631, CVE-2026-50632, CVE-2026-50633, CVE-2026-50634, CVE-2026-50645; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-44930 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260618-0001/

NetApp published this interim advisory covering CVE-2026-44930; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-44618 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260618-0003/

NetApp published this interim advisory covering CVE-2026-44618; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-44417 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260618-0002/

NetApp published this interim advisory covering CVE-2026-44417; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-54988 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260618-0005/

NetApp published this interim advisory covering CVE-2025-54988; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2026 Golang Crypto Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0019/

NetApp published this interim advisory covering CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent Container (tp-proxy); Trident Protect; Trident Protect Connector.

Open source
Advisory

CVE-2026-9076 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0008/

NetApp published this interim advisory covering CVE-2026-9076; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-7383 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0003/

NetApp published this interim advisory covering CVE-2026-7383; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-45447 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0002/

NetApp published this interim advisory covering CVE-2026-45447; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-45446 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0016/

NetApp published this interim advisory covering CVE-2026-45446; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-45445 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0007/

NetApp published this interim advisory covering CVE-2026-45445; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42771 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0011/

NetApp published this interim advisory covering CVE-2026-42771; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42770 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0018/

NetApp published this interim advisory covering CVE-2026-42770; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42769 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0014/

NetApp published this interim advisory covering CVE-2026-42769; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42768 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0017/

NetApp published this interim advisory covering CVE-2026-42768; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42767 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0012/

NetApp published this interim advisory covering CVE-2026-42767; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42766 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0013/

NetApp published this interim advisory covering CVE-2026-42766; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42765 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0005/

NetApp published this interim advisory covering CVE-2026-42765; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42764 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0004/

NetApp published this interim advisory covering CVE-2026-42764; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-35188 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0015/

NetApp published this interim advisory covering CVE-2026-35188; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-34183 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0006/

NetApp published this interim advisory covering CVE-2026-34183; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-34182 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0001/

NetApp published this interim advisory covering CVE-2026-34182; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-34181 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0010/

NetApp published this interim advisory covering CVE-2026-34181; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-34180 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0009/

NetApp published this interim advisory covering CVE-2026-34180; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
News

2026-09-02-netapp-expands-cisco-partnership-to-help-enterprises-stop-ransomware-attacks-fas

Source: https://news.google.com/rss/articles/CBMivwFBVV95cUxQNGptYlhnMlo5aC1Jd1hmNUdHY2hDRTcwZVFoTUROMEM0TkpaYWVCWllfbDB5RGo4WUdseTFKTGkzcUU3ajdxQ1hQVl95VVNfMUtROWRFOWtOUzhEdnd6d0VIUWV1RWZFVHp2TWllVm5zb2ZoOE1aMzNGM1pyTGVTZlVrNFpueVJJY3hJMTZUV1gtSnM0aWtsWm1aeUQ2THlGMkxnOVRCSVI0Y0FDTXFKN3lkMTVab1ZHbWlIX1ZLSQ?oc=5

TechAfrica News article from the NetApp ONTAP Google News RSS feed. NetApp Expands Cisco Partnership to Help Enterprises Stop Ransomware Attacks Faster - TechAfrica News. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
Product

ASA r2 uses a distinct simplified ONTAP experience

Source: https://docs.netapp.com/us-en/ontap/san-admin/learn-about-asa.html

NetApp distinguishes classic ASA from ASA r2: classic ASA is a SAN-only AFF-derived system with symmetric active-active multipathing, while ASA r2 (beginning with the A1K/A70/A90 generation and expanded since) presents a simplified storage-unit-oriented ONTAP experience. That distinction affects provisioning concepts, supported commands, REST endpoints, and which documentation applies.

Open source
News

2026-09-02-cisco-netapp-introduce-splunk-soar-playbook-to-automate-ransomware-containment-t

Source: https://news.google.com/rss/articles/CBMizgFBVV95cUxOblUwb2l3M1JuQXlNbVNlYWg1WGVwZlBPeHVqZDJ6Yy12YS1MOHg3b0JJYVZqX0Y5UHlSMElWQTBqVXpxOWE1cmEzWGdHb1F2dEZ4QnFsUUVhYkxlZUZVdm5PSVNhTGsxSjBwY0NxbWJsMG1xRWdtQlYtVlR4bXo2a0NoYkRVZi1YbzE4T1M3VmlVSG4ydjlodVhFamh0SFRWRnBwQk5Ka1ZoU29JTkgwQzBqdUxCRnVzNEthR0lUSXl1bGpWQ1BHRXJ2Qy1Bdw?oc=5

The Fast Mode article from the NetApp ONTAP Google News RSS feed. Cisco, NetApp Introduce Splunk SOAR Playbook to Automate Ransomware Containment - The Fast Mode. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
AI

2026-09-02-the-enterprise-grade-data-platform-for-ai-netapp

Source: https://news.google.com/rss/articles/CBMijwFBVV95cUxOdGpIZHJlWEJPNlFlcEdvRkJsRXkzeDFETUVVLWdFV0NrclVEN0tEVzJkc3E0cUxIM2NocDZHclp0NkNfR0lnMDVvcGNCZjdab19mazdkd0ZxUlJINHBkMUJRT3NaUU51NEZnZ1BXRWRKSk1uZW9EZVo0RE9JeGMzM3Njd05sZHg2UlN0NkpDMA?oc=5

NetApp article from the NetApp AI Google News RSS feed. The enterprise-grade data platform for AI - NetApp. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

CVE-2026-6238 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0002/

NetApp published this interim advisory covering CVE-2026-6238; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-39882 OpenTelemetry-Go Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0009/

NetApp published this interim advisory covering CVE-2026-39882; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39824 Golang.Org/X/Sys Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0007/

NetApp published this final advisory covering CVE-2026-39824; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33814 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0006/

NetApp published this interim advisory covering CVE-2026-33814; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Trident Protect.

Open source
Advisory

CVE-2026-3184 Util-linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0011/

NetApp published this interim advisory covering CVE-2026-3184; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-27456 Util-linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0012/

NetApp published this interim advisory covering CVE-2026-27456; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-58187 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0003/

NetApp published this interim advisory covering CVE-2025-58187; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2021-35939 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0016/

NetApp published this interim advisory covering CVE-2021-35939; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-35938 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0017/

NetApp published this interim advisory covering CVE-2021-35938; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-35937 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0015/

NetApp published this interim advisory covering CVE-2021-35937; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3521 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0018/

NetApp published this interim advisory covering CVE-2021-3521; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3421 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0020/

NetApp published this interim advisory covering CVE-2021-3421; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20266 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0019/

NetApp published this interim advisory covering CVE-2021-20266; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-7501 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0014/

NetApp published this interim advisory covering CVE-2017-7501; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-7500 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0013/

NetApp published this interim advisory covering CVE-2017-7500; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0001/

NetApp published this interim advisory covering CVE-2026-29167, CVE-2026-34356, CVE-2026-42536, CVE-2026-43951, CVE-2026-44185, CVE-2026-44186, CVE-2026-44631, CVE-2026-34355, CVE-2026-44119; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9.

Open source
Advisory

CVE-2026-48913 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0004/

NetApp published this interim advisory covering CVE-2026-48913; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-42535 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0002/

NetApp published this interim advisory covering CVE-2026-42535; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34003 X.Org Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0010/

NetApp published this interim advisory covering CVE-2026-34003; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34002 X.Org Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0007/

NetApp published this interim advisory covering CVE-2026-34002; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34001 X.Org Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0009/

NetApp published this interim advisory covering CVE-2026-34001; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34000 X.Org Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0006/

NetApp published this interim advisory covering CVE-2026-34000; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33999 X.Org Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0008/

NetApp published this interim advisory covering CVE-2026-33999; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-29170 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0005/

NetApp published this interim advisory covering CVE-2026-29170; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
AI

NetApp and Cisco Expand FlexPod With Validated AI Architectures and Splunk SOAR Storage Response

Source: StorageReview.com (via Google News)

StorageReview covers NetApp and Cisco expanding FlexPod with validated AI architectures plus a Splunk SOAR-integrated storage security response. The convergence of converged infrastructure and automated cyber-response gives enterprises a prevalidated path to AI deployments with SOC-driven protection of the underlying NetApp data layer.

Open source
Advisory

CVE-2026-48710 Starlette Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0011/

NetApp published this interim advisory covering CVE-2026-48710; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-43501 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0015/

NetApp published this interim advisory covering CVE-2026-43501; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-42790 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0010/

NetApp published this interim advisory covering CVE-2026-42790; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility; SnapCenter.

Open source
Advisory

CVE-2026-40977 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0009/

NetApp published this interim advisory covering CVE-2026-40977; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights and Data Secure Storage Workload Security Agent.

Open source
Advisory

CVE-2026-35554 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0008/

NetApp published this interim advisory covering CVE-2026-35554; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-31607 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0014/

NetApp published this interim advisory covering CVE-2026-31607; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-24281 Apache Zookeeper Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0007/

NetApp published this interim advisory covering CVE-2026-24281; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-7345 GDK-Pixbuf Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0006/

NetApp published this final advisory covering CVE-2025-7345; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-41244 VMware Tools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0005/

NetApp published this interim advisory covering CVE-2025-41244; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15284 Qs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0004/

NetApp published this interim advisory covering CVE-2025-15284; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-14512 GLib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0003/

NetApp published this interim advisory covering CVE-2025-14512; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-14087 GLib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0002/

NetApp published this interim advisory covering CVE-2025-14087; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-57699 Json-smart Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0001/

NetApp published this final advisory covering CVE-2024-57699; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2026 Spring Boot Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0013/

NetApp published this interim advisory covering CVE-2026-40972, CVE-2026-40973, CVE-2026-40974, CVE-2026-40975; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

2026-09-01-ntap-20260605-0012

Source: https://security.netapp.com/advisory/NTAP-20260605-0012/

NetApp security advisory NTAP-20260605-0012. CVEs: CVE-2026-9256. Multiple NetApp products incorporate NGINX. NGINX versions prior to 1.30.2 and 1.31.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
AI

2026-09-02-netapp-and-cisco-expand-flexpod-for-enterprise-ai-infrastructure-channele2e-com

Source: https://news.google.com/rss/articles/CBMingFBVV95cUxNQ3ZXaVdhQnRQQ3cwVVRPdDBMYzZCRU1PRW5SejdscU1XNUtQUUFtNlR1YWR5TXlGVzJ6RGw5MUlka0RfVXR0SXlneVZEUHp0U1ZXLTRDSVRsQ290ODJ5Rl9PSExCNFBmejBENDB0RVhOd2hTRGlaMV9VSlllTDlwTmJLR2RIZ3BPSnJNUVpjOW1vOFBWUUNkVmRoOVZiZw?oc=5

channele2e.com article from the NetApp AI Google News RSS feed. NetApp and Cisco expand FlexPod for enterprise AI infrastructure - channele2e.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-netapp-and-cisco-accelerate-and-secure-ai-innovation-hpcwire

Source: https://news.google.com/rss/articles/CBMipAFBVV95cUxNdEtvb3N2WmZWcmFiaFBYd3V0Y2lQUmpkMUJjTUdBLVVRRnM3b0lzb093djVkRFhqb0NERTdnbkpYVHF2UHVmczJuakUzOFZFVHJoVnI2Z2xwWFJJS2dTTU85ME90VER3VThrNGpWanhGQ01ZbDdQZHFrUGprSVBLWnowWW5lT0ctLWRHa01aV3ZQUnNhTEFUT1RSVlREeUJEV043UA?oc=5

HPCwire article from the NetApp AI Google News RSS feed. NetApp and Cisco Accelerate and Secure AI Innovation - HPCwire. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-the-5-most-interesting-analyst-questions-from-netapp-s-q1-earnings-call-stocksto

Source: https://news.google.com/rss/articles/CBMizwFBVV95cUxPeV8zN2dGM3Q4a19BaHZGNk9DbUdRWTNUNUZnWGMzNkdKSkxPZnBNY1BJQlJpQUpQRVJDaGhxa19RM1J5am9WUk1GTXg1bDdzaFZJZEpyamEybXFyaXBRT3cyVVpsTnBrak9JRzY1dE41NHFJdmR0TmNrUWgxcERLUmNCY0dTVGw0T3N3NV8xWF9COHVkTzZmTmVvdjg4NEhJeVUzZDNZYkRFNzB2SkZUQlZweGJsaG12R09ISGMwcnozbmUweVhMa2NabDliNDg?oc=5

stockstory.org article from the NetApp AI Google News RSS feed. The 5 Most Interesting Analyst Questions From NetApp’s Q1 Earnings Call - stockstory.org. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-new-cisco-netapp-flexpod-aims-to-simplify-secure-ai-for-enterprises-stocktitan-n

Source: https://news.google.com/rss/articles/CBMingFBVV95cUxQeElidEdtZTVXcHdqdzY5SDh5YzhCcGlaTkQtdHpGd2xfYUNicy05dzRmNjhZbUthZjV4alRBRW1tNTI4ZWN4blIwTXdkWkhWLUc0RGp0cFl2TWR2Nk9MZFoxbVNfZlBMbzBkQzBkVm1RR3JzR2V1RFJRSnpZTGxGdkpZMDJFU0hXRVhkUHEycXUwa2lUYTc3WlNQOWJCUQ?oc=5

stocktitan.net article from the NetApp AI Google News RSS feed. New Cisco-NetApp FlexPod aims to simplify secure AI for enterprises - stocktitan.net. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-netapp-and-cisco-expand-flexpod-for-ai-workloads-investing-com

Source: https://news.google.com/rss/articles/CBMiqAFBVV95cUxQVmluTlZoMUlaNkZrb1IxWEpvdHdaSXNhWFluOVlqMlNLQ3Bad2M4RWt1WXdiWUxaWV9xejU4b1M1blNwSC1vbjFKMnpWWlhqOU5iUV9qUjJOTTlWR2pVd3ZFQzBrSXZhWnN6U3dsZDFYSmpBME94SGNwRWN6dDRsNDg3MkU1MnAxaVljNElLRzAwcl9tMFdjejZ5YjVFUjZoZklkWWc3cGo?oc=5

Investing.com article from the NetApp AI Google News RSS feed. NetApp and Cisco expand FlexPod for AI workloads - Investing.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-netapp-and-cisco-accelerate-and-secure-ai-innovation-it-voice-media-pvt-ltd

Source: https://news.google.com/rss/articles/CBMigAFBVV95cUxQWENmQlpwOTZqMFRBcDNkSXBxZTMwQVNndDlfcUl0bzlZTnp0RDhicm5ScTB0ZWxvTk80UW5welJKRGwtS0NISVNtc3RiMzFSX1h6MGJBWUw5aU1YQTNrWTVwVWhHLUR4bGdUTU1jbEpPX3B3Y3dnQlQ2Y3ZHa2dYTg?oc=5

IT Voice Media Pvt. Ltd. article from the NetApp NVIDIA Google News RSS feed. NetApp and Cisco Accelerate and Secure AI Innovation - IT Voice Media Pvt. Ltd.. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

Announcement: FlexPod AI expands enterprise AI architectures (NetApp)

Source: https://www.netapp.com/blog/announcement-flexpod-ai-expands-enterprise-ai/

NetApp blog announcement of the expanded FlexPod AI reference architectures jointly delivered with Cisco and validated against NVIDIA HGX/HGX-B200 platforms. Adds new configurations for NVIDIA H100/H200/B200 GPU pods, Cisco UCS X-Series compute, and ONTAP AI / EF-Series storage tiers, covering training, fine-tuning and RAG inference workloads.

Open source
AI

2026-09-02-netapp-q4-fy-2026-ai-deployments-accelerate-high-performance-storage-demand-the-

Source: https://news.google.com/rss/articles/CBMirwFBVV95cUxQU0pBR3hkVkw3YzB6MFgzeUJmTFlCal9CV3ZsTHAwSlJwQXJhX1dXTmNFV2hWaE5lcDVMaHE4cVlicmRTSFVNZFBvb0FQLTAyOTJhRFFaNThOT2RYaUdseVN1b2NhZzdGTmdJNURPc2RPczNTdDFldFNTbVQ2SjdXX3Qtcl9DNWZrSTBmbTZhQWwzYlN1d181RkNYUFA0RlRuOWlOVWFKdTB4SDBaTEJz?oc=5

The Futurum Group article from the NetApp AI Google News RSS feed. NetApp Q4 FY 2026: AI Deployments Accelerate High-Performance Storage Demand - The Futurum Group. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

May 2026 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0014/

NetApp published this interim advisory covering CVE-2026-41284, CVE-2026-41293, CVE-2026-43512, CVE-2026-43513, CVE-2026-43514, CVE-2026-43515; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6938 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0009/

NetApp published this final advisory covering CVE-2026-6938; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6053 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0011/

NetApp published this final advisory covering CVE-2026-6053; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6052 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0008/

NetApp published this final advisory covering CVE-2026-6052; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6051 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0012/

NetApp published this final advisory covering CVE-2026-6051; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-5950 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0006/

NetApp published this interim advisory covering CVE-2026-5950; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-5947 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0003/

NetApp published this interim advisory covering CVE-2026-5947; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-5946 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0002/

NetApp published this interim advisory covering CVE-2026-5946; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP 9.

Open source
Advisory

CVE-2026-44578 Next.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0013/

NetApp published this interim advisory covering CVE-2026-44578; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3593 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0004/

NetApp published this interim advisory covering CVE-2026-3593; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3592 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0005/

NetApp published this interim advisory covering CVE-2026-3592; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-3039 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0001/

NetApp published this interim advisory covering CVE-2026-3039; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-1718 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0007/

NetApp published this final advisory covering CVE-2026-1718; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-13755 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0010/

NetApp published this final advisory covering CVE-2025-13755; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2026 Apache Thrift Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0015/

NetApp published this interim advisory covering CVE-2025-48431, CVE-2026-41602, CVE-2026-41603, CVE-2026-41604, CVE-2026-41605, CVE-2026-41606, CVE-2026-41607, CVE-2026-41636, CVE-2026-43868, CVE-2026-43869, CVE-2026-43870; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
AI

2026-09-02-ai-and-all-flash-demand-send-netapp-revenues-to-record-heights-blocks-files

Source: https://news.google.com/rss/articles/CBMiugFBVV95cUxPb0hCSjJMTnpZZXlscWNRTzk5UFkxUzVBNXNjMjZqVDRjVnQzTW9mdTNKTF9iaXpKWFJiMDVBcms2RUstZEhDX0hvQmQ0TXRteHZkMFZaeExqekR4Q204UU1Id2dKOTR0MXZhWS1PWHh4c3RORHpwRFB5dlRZT3R6TThUTmhVbDFiU1doenItV0R0QWNWQzNSNURTQXZLQnlLQkwweFpidy1qdHc3ak95N3ZmUndsN0ZPR2c?oc=5

Blocks &amp; Files article from the NetApp AI Google News RSS feed. AI and all-flash demand send NetApp revenues to record heights - Blocks & Files. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

CVE-2026-45255 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0011/

NetApp published this final advisory covering CVE-2026-45255; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45254 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0012/

NetApp published this final advisory covering CVE-2026-45254; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45253 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0008/

NetApp published this final advisory covering CVE-2026-45253; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45252 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0013/

NetApp published this final advisory covering CVE-2026-45252; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45251 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0010/

NetApp published this final advisory covering CVE-2026-45251; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45250 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0009/

NetApp published this final advisory covering CVE-2026-45250; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-4480 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0002/

NetApp published this interim advisory covering CVE-2026-4480; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39461 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0007/

NetApp published this final advisory covering CVE-2026-39461; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3238 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0004/

NetApp published this final advisory covering CVE-2026-3238; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3012 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0003/

NetApp published this final advisory covering CVE-2026-3012; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-2340 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0006/

NetApp published this final advisory covering CVE-2026-2340; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1933 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0005/

NetApp published this final advisory covering CVE-2026-1933; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-1000405 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0014/

NetApp published this interim advisory covering CVE-2017-1000405; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; E-Series SANtricity OS Controller Software; NetApp Cloud Backup (formerly AltaVault); NetApp VASA Provider for Clustered Data ONTAP 6.x; ONTAP Select Deploy administration utility; OnCommand Balance; SnapProtect; StorageGRID (formerly StorageGRID Webscale).

Open source
AI

2026-09-02-netapp-stock-rallies-ahead-of-earnings-as-data-storage-rival-everpure-chases-bre

Source: https://news.google.com/rss/articles/CBMilAFBVV95cUxNMWt5ODFUdjdXRDBaeEdFVnpBMkc2a2FrRVl6bU5mRDRYS29jRy1TVHBpS2tGUm9VanMyR1VyckJBNnA3R3pJZVU5SWNMRG9MNEswNWFxTExKQ21keTVpYTRwZkZ5UmJET29XNW9HdGZKQ1RUd09IWXRXbHd6NlRHUFVXWVVRSWZQR3RkbFVKUkg3UmRP?oc=5

Investor's Business Daily article from the NetApp AI Google News RSS feed. NetApp Stock Rallies Ahead Of Earnings As Data Storage Rival Everpure Chases Breakout - Investor's Business Daily. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

2026-09-01-ntap-20260527-0001

Source: https://security.netapp.com/advisory/NTAP-20260527-0001/

NetApp security advisory NTAP-20260527-0001. CVEs: CVE-2026-4408. Samba versions prior to 4.22.10, 4.23.8 and 4.24.3 are susceptible to a vulnerability which when successfully exploited could lead to unauthenticated Remote Code Execution.

Open source
Advisory

May 2026 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0001/

NetApp published this interim advisory covering CVE-2025-27516, CVE-2025-50059, CVE-2025-50106, CVE-2025-30749, CVE-2025-30761, CVE-2025-30754, CVE-2025-30167, CVE-2024-56339, CVE-2025-48976, CVE-2025-3633, CVE-2025-53057, CVE-2025-53066, CVE-2024-12798, CVE-2024-12801, CVE-2025-36126, CVE-2024-6844, CVE-2024-6839, CVE-2024-6866, CVE-2025-6020, CVE-2025-21587, CVE-2025-30698, CVE-2025-2900, CVE-2025-4447, CVE-2024-5535, CVE-2025-5889, CVE-2024-35195, CVE-2025-7962, CVE-2025-54798, CVE-2025-50181, CVE-2025-50182, CVE-2025-68146, CVE-2025-56200; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2026-42946 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0012/

NetApp published this interim advisory covering CVE-2026-42946; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-42934 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0014/

NetApp published this interim advisory covering CVE-2026-42934; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-42498 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0010/

NetApp published this interim advisory covering CVE-2026-42498; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-40701 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0013/

NetApp published this interim advisory covering CVE-2026-40701; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-40021 Apache Log4Net Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0002/

NetApp published this interim advisory covering CVE-2026-40021; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34500 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0006/

NetApp published this interim advisory covering CVE-2026-34500; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34487 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0007/

NetApp published this interim advisory covering CVE-2026-34487; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34486 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0009/

NetApp published this interim advisory covering CVE-2026-34486; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34483 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0008/

NetApp published this interim advisory covering CVE-2026-34483; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-32990 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0005/

NetApp published this interim advisory covering CVE-2026-32990; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-29145 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0003/

NetApp published this interim advisory covering CVE-2026-29145; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-25854 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0004/

NetApp published this interim advisory covering CVE-2026-25854; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-30185 Intel UEFI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0019/

NetApp published this interim advisory covering CVE-2025-30185; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27560 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0020/

NetApp published this interim advisory covering CVE-2025-27560; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20077 Intel UEFI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0018/

NetApp published this interim advisory covering CVE-2025-20077; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6200 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0017/

NetApp published this interim advisory covering CVE-2023-6200; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-1000253 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0015/

NetApp published this interim advisory covering CVE-2017-1000253; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); OnCommand Balance; SnapProtect.

Open source
Advisory

2026-09-01-ntap-20260522-0016

Source: https://security.netapp.com/advisory/NTAP-20260522-0016/

NetApp security advisory NTAP-20260522-0016. CVEs: CVE-2026-46300. Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a local privilege escalation vulnerability referred to as Fragnesia that could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260522-0011

Source: https://security.netapp.com/advisory/NTAP-20260522-0011/

NetApp security advisory NTAP-20260522-0011. CVEs: CVE-2026-42945. Multiple NetApp products incorporate NGINX. NGINX versions 0.6.27 through 0.9.7 and 1.0.0 through 1.30.0 are susceptible to a vulnerability referred to as NGINX Rift which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Docs

Data discovery: How to find out what's on your Amazon FSx for NetApp ONTAP volumes

Source: AWS Storage Blog via Google News — https://news.google.com/rss/articles/CBMiugFBVV95cUxPejlTcEgwY1dJVjEtUnhOVmNHVkd5enF3NlgzUHE1WFQ0a0RjbjVQbDI5NXpGMjVtNkk1ZE5ubTZJTjhiSW9qQ2hmeE9qUlh4U0h0QmJoZHEwVkhVTzQ3NUQyV3NrSXQ3dUxTcTd2QUM4Q05uMDZmcHI5MUZoQTdzcXNUcnphZHJyeVZCVFVwOGNpSE14UDNkOGk5VWp2UkhKcV9Ld1oyMHZlaV9OMllMMFFwbENaZlZfYXc?oc=5

AWS walkthrough on inventorying FSx for ONTAP volume contents (file-system audits, usage reporting) before migrations or cleanups — practical admin technique for cloud ONTAP estates.

Open source
Docs

Data discovery on Amazon FSx for NetApp ONTAP volumes (AWS Storage Blog)

Source: https://aws.amazon.com/blogs/storage/data-discovery-how-to-find-out-whats-on-your-amazon-fsx-for-netapp-ontap-volumes/

AWS Storage Blog guide to inventorying data on FSx for NetApp ONTAP volumes using NetApp's data-classification/BlueXP classification tooling rather than custom scripts. Walks through enabling BlueXP classification, scanning existing FSx for ONTAP volumes, identifying PII / sensitive patterns, reviewing the discovered files and applying access policies or moving data to cheaper storage tiers. Important for AI/ML pipelines where unknown data sources must be catalogued before model training — understanding which volumes hold GDPR/PCI/HIPAA data avoids leakage into training corpora and informs which datasets can be replicated to GPU clusters. Pairs naturally with the S3 Access Points for FSx for ONTAP article (same architecture) when scoping AI workloads against regulated data estates.

Open source
Docs

What's new in ONTAP 9.18.1

Source: docs

Official NetApp release notes for ONTAP 9.18.1 (May 2026): covers Data protection, NAS, Networking, SAN, S3 object storage, Security, Storage resource management, System Manager, and Upgrade changes. Major additions include new ABAC support, NFS trunking, S3 SnapMirror cloud targets, and ONTAP S3 access points for fine-grained RAG access control.

Open source
Advisory

CVE-2026-7168 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0008/

NetApp published this interim advisory covering CVE-2026-7168; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-7009 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0007/

NetApp published this interim advisory covering CVE-2026-7009; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-6429 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0003/

NetApp published this interim advisory covering CVE-2026-6429; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-6276 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0009/

NetApp published this interim advisory covering CVE-2026-6276; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-6253 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0006/

NetApp published this interim advisory covering CVE-2026-6253; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-5773 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0004/

NetApp published this interim advisory covering CVE-2026-5773; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-5545 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0005/

NetApp published this interim advisory covering CVE-2026-5545; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-2006 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0002/

NetApp published this interim advisory covering CVE-2026-2006; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-2005 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0001/

NetApp published this interim advisory covering CVE-2026-2005; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260515-0010

Source: https://security.netapp.com/advisory/NTAP-20260515-0010/

NetApp security advisory NTAP-20260515-0010. CVEs: CVE-2026-2391. Multiple NetApp products incorporate qs. Qs versions 6.7.0 through 6.14.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-5450 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0006/

NetApp published this interim advisory covering CVE-2026-5450; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-5435 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0005/

NetApp published this interim advisory covering CVE-2026-5435; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-43500 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0002/

NetApp published this interim advisory covering CVE-2026-43500; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-43284 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0001/

NetApp published this interim advisory covering CVE-2026-43284; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-35469 Spdystream Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0009/

NetApp published this final advisory covering CVE-2026-35469; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34480 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0007/

NetApp published this interim advisory covering CVE-2026-34480; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34477 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0008/

NetApp published this interim advisory covering CVE-2026-34477; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-29181 Opentelemetry-Go Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0010/

NetApp published this interim advisory covering CVE-2026-29181; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-36899 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0003/

NetApp published this interim advisory covering CVE-2024-36899; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34059 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0010/

NetApp published this final advisory covering CVE-2026-34059; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34032 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0016/

NetApp published this final advisory covering CVE-2026-34032; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33857 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0015/

NetApp published this final advisory covering CVE-2026-33857; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33523 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0012/

NetApp published this final advisory covering CVE-2026-33523; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33007 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0014/

NetApp published this final advisory covering CVE-2026-33007; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33006 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0017/

NetApp published this final advisory covering CVE-2026-33006; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-29169 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0009/

NetApp published this final advisory covering CVE-2026-29169; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-29168 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0011/

NetApp published this final advisory covering CVE-2026-29168; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-28780 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0007/

NetApp published this final advisory covering CVE-2026-28780; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-27137 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0020/

NetApp published this interim advisory covering CVE-2026-27137; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-24308 Apache Zookeeper Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0019/

NetApp published this interim advisory covering CVE-2026-24308; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-24072 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0013/

NetApp published this final advisory covering CVE-2026-24072; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-23918 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0008/

NetApp published this final advisory covering CVE-2026-23918; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-23003 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0004/

NetApp published this interim advisory covering CVE-2026-23003; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-22997 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0003/

NetApp published this interim advisory covering CVE-2026-22997; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-22992 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0005/

NetApp published this interim advisory covering CVE-2026-22992; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-22991 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0006/

NetApp published this interim advisory covering CVE-2026-22991; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-0603 Hibernate ORM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0018/

NetApp published this interim advisory covering CVE-2026-0603; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 10.

Open source
Advisory

2026-09-01-ntap-20260508-0002

Source: https://security.netapp.com/advisory/NTAP-20260508-0002/

NetApp security advisory NTAP-20260508-0002. CVEs: CVE-2026-22990. Multiple NetApp products incorporate Linux kernel. Linux kernel versions through 5.10.247, 5.11-rc1 through 5.15.197, 5.16-rc1 through 6.1.160, 6.13-rc1 through 6.18.5, 6.19-rc1 through 6.19-rc4, 6.2-rc1 through 6.6.120 and 6.7-rc1 through 6.12.65 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260508-0001

Source: https://security.netapp.com/advisory/NTAP-20260508-0001/

NetApp security advisory NTAP-20260508-0001. CVEs: CVE-2026-22984. Multiple NetApp products incorporate Linux kernel. Linux kernel versions through 5.15.197, 5.16-rc1 through 6.1.160, 6.13-rc1 through 6.18.5, 6.19-rc1 through 6.19-rc4, 6.2-rc1 through 6.6.120 and 6.7-rc1 through 6.12.65 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data or Denial of Service (DoS).

Open source
AI

Iterate.ai announces strategic alliance with NetApp for turnkey private AI (GlobeNewswire)

Source: https://www.globenewswire.com/news-release/iterate-ai-netapp-strategic-alliance-private-ai/

GlobeNewswire press release on Iterate.ai + NetApp strategic alliance: integrating Iterate.ai's private-AI agent platform with NetApp AIPod and ONTAP to deliver a turnkey private-AI stack for regulated enterprises. Positions the bundle as an alternative to hyperscaler AI services for banks, governments and healthcare customers that need data to stay on-prem.

Open source
AI

2026-09-02-iterate-ai-announces-strategic-alliance-with-netapp-to-deliver-turnkey-private-a

Source: https://news.google.com/rss/articles/CBMi_gFBVV95cUxON2t6UUl6UnJXclVfTWdxZERXWG9Pb3ZqRVU2N3FfUzhPTTFFVnBSTUZGVHF2STdUOHVrZjZJa1BSeFhPdHQ2SkhoQ0tWUVVrZmo4a3FjVFRwNHhUVDd3VWkyT2NNWXJkemVxRy1VTGNXSVloVTk5SXV6Z2duSDM0TEZBWTN6NzhvdmtCTFBNSzdPNm5KcEpXNXFZSXpRQXQxSWRpUmtuYkxacnJWZFBHeF95czFvNm5OaHRINDNVanBIZEw4ZDBWdGlGYmNnQTJ5Zzh1X0hHcmY0NXJGaUFnUkFncnVMQ3JhOXE4UnREQXVXNnFYU0FZWC1ZUkZGdw?oc=5

GlobeNewswire article from the NetApp AI Google News RSS feed. Iterate.ai Announces Strategic Alliance with NetApp to Deliver Turnkey Private AI for Enterprises - GlobeNewswire. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Docs

2026-09-05-kb-modify-maxdir-size-ontap-9

Source: https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/How_to_modify_the_maxdir-size_in_ONTAP_9

Covers the ONTAP 9 volume-level `maxdir-size` knob (`vol options <vol> maxdir-size <bytes>` and the modern `volume modify -vserver <vs> -volume <vol> -max-dir-size <MiB>` form). The setting controls the maximum directory size in the WAFL inode file; hitting it is a classic cause of `No space left on device` errors on SMB/NFS shares even when `df` shows the volume still has free space. Useful when running legacy Windows file-server workloads with millions of files in a single directory — NetApp recommends against bumping the value above ~512 MB without TAC involvement. Applies to ONTAP 9.x (9.7+ preferred path via `volume modify`; older 9.x uses the `vol options` form).

Open source
AI

Turn Your Data Estate Into AI Fuel (NVIDIA + NetApp joint session)

Source: https://www.nvidia.com/gtc/session-catalog/sessions/gtc26-s82103/

NVIDIA GTC joint session by NetApp engineers showing how to turn an enterprise data estate into AI fuel: ONTAP as the unified data plane, AI Data Engine for ingest/transformation/embedding, GPUDirect Storage on EF-Series for hot training data, and NIM microservices for inference. Includes reference blueprints for retailers, financial services and manufacturing.

Open source
Advisory

February 2026 Libssh Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0015/

NetApp published this interim advisory covering CVE-2026-0964, CVE-2026-0965, CVE-2026-0966, CVE-2026-0967, CVE-2026-0968; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-7270 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0003/

NetApp published this final advisory covering CVE-2026-7270; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-7164 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0007/

NetApp published this final advisory covering CVE-2026-7164; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39457 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0004/

NetApp published this final advisory covering CVE-2026-39457; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33228 Flatted Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0008/

NetApp published this interim advisory covering CVE-2026-33228; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-31431 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0001/

NetApp published this interim advisory covering CVE-2026-31431; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-28367 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0009/

NetApp published this final advisory covering CVE-2026-28367; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-22732 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0013/

NetApp published this interim advisory covering CVE-2026-22732; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-20096 Intel UEFI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0012/

NetApp published this interim advisory covering CVE-2025-20096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
AI

2026-09-02-turn-your-data-estate-into-ai-fuel-presented-by-netapp-nvidia

Source: https://news.google.com/rss/articles/CBMibEFVX3lxTFBnMWdiX0stdE5vWlk4emwxQ0N3YXBzOTd0RzlxeW5nVDlrT2pBSUtRYm5XOV81bFh1TjUzb19hQ2ZWSW9WWGVuUVgxQ0JiNzZMUHA1N2R4RGZJSWgyV1RkN1J6R1locGdXTWxRcA?oc=5

NVIDIA article from the NetApp AI Google News RSS feed. Turn Your Data Estate Into AI Fuel (Presented by NetApp) - NVIDIA. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

CVE-2026-6386 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0014/

NetApp published this final advisory covering CVE-2026-6386; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-5398 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0013/

NetApp published this final advisory covering CVE-2026-5398; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-40372 ASP.NET Core Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0003/

NetApp published this final advisory covering CVE-2026-40372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-22008 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0008/

NetApp published this interim advisory covering CVE-2026-22008; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-22003 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0009/

NetApp published this interim advisory covering CVE-2026-22003; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-20652 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0010/

NetApp published this interim advisory covering CVE-2026-20652; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-69277 Libsodium Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0015/

NetApp published this interim advisory covering CVE-2025-69277; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-46836 net-tools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0002/

NetApp published this final advisory covering CVE-2025-46836; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-20916 Pip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0001/

NetApp published this interim advisory covering CVE-2019-20916; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2026 MySQL Server 9.0.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0006/

NetApp published this interim advisory covering CVE-2026-35234, CVE-2026-35235, CVE-2026-34272; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2026 MySQL Server 8.0.0, 8.4.0 and 9.0.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0005/

NetApp published this interim advisory covering CVE-2026-35237, CVE-2026-21998, CVE-2026-35236, CVE-2026-34303, CVE-2026-35240, CVE-2026-35238, CVE-2026-35239, CVE-2026-22015, CVE-2026-22009, CVE-2026-22017, CVE-2026-22004, CVE-2026-34270, CVE-2026-34276, CVE-2026-34308, CVE-2026-22001, CVE-2025-14017, CVE-2026-22002, CVE-2026-34271, CVE-2026-22005, CVE-2025-15467, CVE-2026-34304; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

April 2026 MySQL Server 8.0.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0004/

NetApp published this interim advisory covering CVE-2026-34267, CVE-2026-34278, CVE-2026-34293; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

2026-09-01-ntap-20260429-0012

Source: https://security.netapp.com/advisory/NTAP-20260429-0012/

NetApp security advisory NTAP-20260429-0012. CVEs: CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-34268. Multiple NetApp products incorporate Java SE. Java SE versions 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2 and 26 are susceptible to a vulnerability that could allow unauthenticated attacker with network access via HTTPS or multiple protocols or with logon to the infrastructure where Oracle Java SE executes to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker for CVE-2026-22013. Refer to “Oracle Critical Patch Update

Open source
Advisory

2026-09-01-ntap-20260429-0011

Source: https://security.netapp.com/advisory/NTAP-20260429-0011/

NetApp security advisory NTAP-20260429-0011. CVEs: CVE-2026-34282. Multiple NetApp products incorporate Oracle Java Platform, Standard Edition (Java SE). Java SE versions 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2 and 26 are susceptible to a vulnerability which when successfully exploited could allow unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Refer to “Oracle Critical Patch Update Advisory - April 2026” for additional details.

Open source
AI

2026-09-02-vast-data-1b-round-at-30b-nvidia-s-ai-storage-bet-2026-tech-insider-org

Source: https://news.google.com/rss/articles/CBMihwFBVV95cUxPQWRKRndZWUgzSW9MR2wzZ095Y25DLXRtcnVMMDBEdlpHdEpnMmU3dUExbkk0TC1lZm9fUEV4V212Q3MyUlgwdzdEQW5ENE5oeng4akJXMXF5a2ZENmQ2Z2cxV2Y2c0dDdUNIbjZzeHRSNUVWVXNqNTc0S1RHSW5aY2pILVg5OUk?oc=5

tech-insider.org article from the NetApp NVIDIA Google News RSS feed. Vast Data $1B Round at $30B: NVIDIA’s AI Storage Bet [2026] - tech-insider.org. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Docs

Configuring S3 Access Points for Amazon FSx for NetApp ONTAP with Active Directory (AWS Storage Blog)

Source: https://aws.amazon.com/blogs/storage/enabling-ai-powered-analytics-on-enterprise-file-data-configuring-s3-access-points-for-amazon-fsx-for-netapp-ontap-with-active-directory/

AWS Storage Blog walk-through of attaching S3 Access Points to FSx for ONTAP file shares joined to AWS Managed Microsoft AD so that AI/ML services (Athena, SageMaker, EMR) can consume SMB/NFS file data through an S3-compatible interface with per-application credentials and policies. S3 Access Points provide per-application scoped endpoints with their own IAM policies, which removes the need to share a single wide-open S3 alias between teams — a key governance pattern for regulated AI workloads. The architecture diagram shows the FSx for ONTAP file system mounted by EC2-based AI clients while S3 Access Points present the same data through the S3 API, all fronted by the Active Directory join for identity. Reference for anyone building hybrid analytics where file-system and object-store access must coexist without copying data.

Open source
Advisory

CVE-2026-5704 Tar Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0010/

NetApp published this interim advisory covering CVE-2026-5704; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Console Agent Container (cbs_catalog); NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-35388 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0006/

NetApp published this interim advisory covering CVE-2026-35388; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-35387 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0005/

NetApp published this interim advisory covering CVE-2026-35387; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400.

Open source
Advisory

CVE-2026-35386 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0004/

NetApp published this interim advisory covering CVE-2026-35386; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400.

Open source
Advisory

CVE-2026-32772 GNU Inetutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0009/

NetApp published this final advisory covering CVE-2026-32772; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-27699 Basic-ftp Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0008/

NetApp published this final advisory covering CVE-2026-27699; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-22998 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0019/

NetApp published this interim advisory covering CVE-2026-22998; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-68263 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0012/

NetApp published this interim advisory covering CVE-2025-68263; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-64756 Node-Glob Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0007/

NetApp published this final advisory covering CVE-2025-64756; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-37924 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0011/

NetApp published this interim advisory covering CVE-2025-37924; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

April 2026 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0001/

NetApp published this interim advisory covering CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32281, CVE-2026-32282, CVE-2026-32283, CVE-2026-32288, CVE-2026-32289; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; ONTAP tools for VMware vSphere 10; Trident; Trident Protect.

Open source
AI

2026-09-02-netapp-walks-the-ai-talk-with-google-enterprise-times

Source: https://news.google.com/rss/articles/CBMiigFBVV95cUxNeU9ZTmZ4RjNxelpsQWU4SW1CNFd2LXJfQVRQMVVHQnhhanFEWDhpWEI1VlVvX3EwUEtvUlFKdnlLWTlqd2JMbE0xcWxEQXRmc2tkTVh6YXRQeVFCTFREMG1RVXhLSXVnby1FMWpnSExsWWd6MWxQNVMyUG9oYndZdUtpeVN3QTdnbUE?oc=5

Enterprise Times article from the NetApp AI Google News RSS feed. NetApp Walks the AI Talk with Google - - Enterprise Times. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-enabling-ai-powered-analytics-on-enterprise-file-data-configuring-s3-access-poin

Source: https://news.google.com/rss/articles/CBMihAJBVV95cUxNQ1NQSXhIaWtKRUZITTBZdEdhdHhZcmZTTzZNQUhtV01mRzBmaXJCendSd2NaOFdjWWlYUGxmYlA0eElXNHFxVmZWRDVhRnIzWkw0RkJzUndwdmNCS09iT1ZIaUJ4SDRaallCOGJMS3NGZkpnVDFjWmVkaTZyMU5QaEVGTlFEZzZBY0hyTWJQQ0t0N1hLMzlCU1hfTDBLTkNVVGhrQmZCRl9ZTjBaVmM2NjBQVXRxSmV4Sld2bjVpNkNBZENfMXdFNi1ka0pNS2xfakxzSTFqRWtGdW1ybnJpSmZleDYyVGJLV3BFdGtWTWpuczBLS25nX3ZQYmVUOUNXNFJRUg?oc=5

aws.amazon.com article from the NetApp AI Google News RSS feed. Enabling AI-powered analytics on enterprise file data: Configuring S3 Access Points for Amazon FSx for NetApp ONTAP with Active Directory - aws.amazon.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

2026-09-01-ntap-20260424-0020

Source: https://security.netapp.com/advisory/NTAP-20260424-0020/

NetApp security advisory NTAP-20260424-0020. CVEs: CVE-2026-23095. Multiple NetApp products incorporate Linux Kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
AI

2026-09-02-netapp-expands-google-cloud-integration-to-streamline-enterprise-data-for-ai-sto

Source: https://news.google.com/rss/articles/CBMisAFBVV95cUxOM2dZUFlRN25BN1M5SGtmd2drZzE1cnRkVWxjblI4Z1NkM2RPZjYzWXFxeWl2a1Jtd0Z6S1gzaVVKWExWN1I4eTlGQW1pT282djVtcjBkV2VsaVUySXdkY05SM3B4SDdQQ1BvNFVOMVpNemNHd2tNSVZNMFFaVjhULUxFNmE4RG9CdGtCUkdUT1ozT0tkc3pzTEotLTY3ZkV4WG5RdFJwZXJ3dzlwVzBpRdIBtgFBVV95cUxQbWdzSXdxWTVKNXh4cXNOVERxZnZnWkNiRUlIazlYS0lTeWlQQmhITlE1dTBacWdHb0VucjZxbnprbk5XaDl1ZWI0ckJ6QnpRWjhQSGkxSk1aLWZGTm1vVXBmYW5UekhwREt2eXQxN09MUW1DWHROb1BMWkRHR3c1N1RGNmhxVzRtN0VCZV92OFFXSXVUUG1VbGxYaTZubE1EUXdOMDlmeUFTXzRncW1WbWEyc3Bxdw?oc=5

StorageReview.com article from the NetApp AI Google News RSS feed. NetApp Expands Google Cloud Integration to Streamline Enterprise Data for AI - StorageReview.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

CVE-2026-39865 Axios Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0002/

NetApp published this interim advisory covering CVE-2026-39865; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Shift Toolkit; Storage Manager for ProxMox.

Open source
Advisory

CVE-2026-3676 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0008/

NetApp published this final advisory covering CVE-2026-3676; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33186 gRPC-Go Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0005/

NetApp published this interim advisory covering CVE-2026-33186; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-33056 Tar-rs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0017/

NetApp published this interim advisory covering CVE-2026-33056; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Console Agent Container (cbs_catalog); NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-32746 GNU Inetutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0004/

NetApp published this final advisory covering CVE-2026-32746; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-27142 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0006/

NetApp published this interim advisory covering CVE-2026-27142; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-25679 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0007/

NetApp published this interim advisory covering CVE-2026-25679; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; NetApp Kubernetes Monitoring Operator; ONTAP tools for VMware vSphere 10; Trident; Trident Protect.

Open source
Advisory

CVE-2026-1577 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0009/

NetApp published this final advisory covering CVE-2026-1577; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1352 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0014/

NetApp published this final advisory covering CVE-2026-1352; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68161 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0013/

NetApp published this final advisory covering CVE-2025-68161; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-67735 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0011/

NetApp published this final advisory covering CVE-2025-67735; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-66168 Apache ActiveMQ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0001/

NetApp published this final advisory covering CVE-2025-66168; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-64118 Node-tar Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0019/

NetApp published this interim advisory covering CVE-2025-64118; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Console Agent Container (cbs_catalog); NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-55315 ASP.NET Core Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0020/

NetApp published this final advisory covering CVE-2025-55315; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36122 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0012/

NetApp published this final advisory covering CVE-2025-36122; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-14688 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0015/

NetApp published this final advisory covering CVE-2025-14688; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-12183 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0010/

NetApp published this final advisory covering CVE-2025-12183; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-58251 BusyBox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0016/

NetApp published this interim advisory covering CVE-2024-58251; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

2026-09-01-ntap-20260422-0018

Source: https://security.netapp.com/advisory/NTAP-20260422-0018/

NetApp security advisory NTAP-20260422-0018. CVEs: CVE-2026-24842. Multiple NetApp products incorporate node-tar. Node-tar versions prior to 7.5.7 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260422-0003

Source: https://security.netapp.com/advisory/NTAP-20260422-0003/

NetApp security advisory NTAP-20260422-0003. CVEs: CVE-2026-4046. Multiple NetApp products incorporate GNU C Library (glibc). Glibc versions through 2.43 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-4748 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0006/

NetApp published this final advisory covering CVE-2026-4748; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-4652 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0004/

NetApp published this final advisory covering CVE-2026-4652; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-4426 Libarchive Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0007/

NetApp published this interim advisory covering CVE-2026-4426; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp LOADER 8.x.

Open source
Advisory

CVE-2026-4247 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0005/

NetApp published this final advisory covering CVE-2026-4247; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-35414 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0019/

NetApp published this interim advisory covering CVE-2026-35414; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-35385 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0018/

NetApp published this interim advisory covering CVE-2026-35385; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-33227 Apache ActiveMQ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0002/

NetApp published this final advisory covering CVE-2026-33227; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-28386 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0016/

NetApp published this interim advisory covering CVE-2026-28386; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-65945 Auth0/node-jws Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0009/

NetApp published this interim advisory covering CVE-2025-65945; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2026 Axios Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0020/

NetApp published this interim advisory covering CVE-2025-62718, CVE-2026-40175; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Shift Toolkit; Storage Manager for ProxMox.

Open source
Advisory

2026-09-01-ntap-20260417-0017

Source: https://security.netapp.com/advisory/NTAP-20260417-0017/

NetApp security advisory NTAP-20260417-0017. CVEs: CVE-2026-31790. Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information.

Open source
Advisory

2026-09-01-ntap-20260417-0015

Source: https://security.netapp.com/advisory/NTAP-20260417-0015/

NetApp security advisory NTAP-20260417-0015. CVEs: CVE-2026-28387. Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260417-0014

Source: https://security.netapp.com/advisory/NTAP-20260417-0014/

NetApp security advisory NTAP-20260417-0014. CVEs: CVE-2026-28388. Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260417-0013

Source: https://security.netapp.com/advisory/NTAP-20260417-0013/

NetApp security advisory NTAP-20260417-0013. CVEs: CVE-2026-28389. Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260417-0012

Source: https://security.netapp.com/advisory/NTAP-20260417-0012/

NetApp security advisory NTAP-20260417-0012. CVEs: CVE-2026-28390. Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260417-0011

Source: https://security.netapp.com/advisory/NTAP-20260417-0011/

NetApp security advisory NTAP-20260417-0011. CVEs: CVE-2026-31789. Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260417-0010

Source: https://security.netapp.com/advisory/NTAP-20260417-0010/

NetApp security advisory NTAP-20260417-0010. CVEs: CVE-2026-32597. Multiple NetApp products incorporate PyJWT. PyJWT versions prior to 2.12.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260417-0008

Source: https://security.netapp.com/advisory/NTAP-20260417-0008/

NetApp security advisory NTAP-20260417-0008. CVEs: CVE-2026-31402. Multiple NetApp products incorporate Linux kernel. Certain Linux kernel versions are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260417-0003

Source: https://security.netapp.com/advisory/NTAP-20260417-0003/

NetApp security advisory NTAP-20260417-0003. CVEs: CVE-2026-23950. Multiple NetApp products incorporate Node-Tar. Node-Tar versions through 7.5.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260417-0001

Source: https://security.netapp.com/advisory/NTAP-20260417-0001/

NetApp security advisory NTAP-20260417-0001. CVEs: CVE-2026-34197. Multiple NetApp products incorporate Apache ActiveMQ. Apache ActiveMQ versions prior to 5.19.4 and 6.0.0 prior to 6.2.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
AI

2026-09-02-commvault-expands-commvault-flex-to-hitachi-vantara-and-netapp-for-scalable-resi

Source: https://news.google.com/rss/articles/CBMi7AFBVV95cUxNemd0Y3pWVFl6dFhoWlJGM09oU24tUDJRRXkxckxTNW5zTDRhZkRjSThyQmVFdHpCLWdqbUhlcF82R0o5MkxSbzZZdVlDdll6MG1RZjFLMWNJUkxPYnVkT0FMVUF0Nm5LUnM0YTFTTUwtbE5vaUR4cG5GTFBKdVA3SFYtbXRRU1ZXc2xDdGx2enBjZlZoQUwwUTh6eTNMVU5oeWt2cUNuV1ZDNFVZWGk5Tk85Uk54Z1dzYmRkeDhQZjl0US1vN1BoVjJLTVpXcUpQajF2MVdvekE4SU5DUmZsNUg3VTdJcUtTV3d2SQ?oc=5

PR Newswire article from the NetApp AI Google News RSS feed. Commvault Expands Commvault Flex to Hitachi Vantara and NetApp for Scalable Resilience in the AI Era - PR Newswire. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

March 2026 GNU C Library (glibc) Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0017/

NetApp published this interim advisory covering CVE-2026-4437, CVE-2026-4438; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-4747 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0014/

NetApp published this final advisory covering CVE-2026-4747; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33937 Handlebars.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0005/

NetApp published this interim advisory covering CVE-2026-33937; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-21717 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0011/

NetApp published this interim advisory covering CVE-2026-21717; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-21712 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0010/

NetApp published this interim advisory covering CVE-2026-21712; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-21226 Azure Core shared client library for Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0001/

NetApp published this interim advisory covering CVE-2026-21226; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1188 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0015/

NetApp published this final advisory covering CVE-2026-1188; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-14505 Elliptic Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0016/

NetApp published this interim advisory covering CVE-2025-14505; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-28842 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0002/

NetApp published this interim advisory covering CVE-2023-28842; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28841 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0003/

NetApp published this interim advisory covering CVE-2023-28841; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28840 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0004/

NetApp published this interim advisory covering CVE-2023-28840; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

2026-09-01-ntap-20260410-0020

Source: https://security.netapp.com/advisory/NTAP-20260410-0020/

NetApp security advisory NTAP-20260410-0020. CVEs: CVE-2026-3644. Multiple NetApp products incorporate Python. Certain versions of Python are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260410-0019

Source: https://security.netapp.com/advisory/NTAP-20260410-0019/

NetApp security advisory NTAP-20260410-0019. CVEs: CVE-2026-4519. Multiple NetApp products incorporate Python. Certain versions of Python are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260410-0013

Source: https://security.netapp.com/advisory/NTAP-20260410-0013/

NetApp security advisory NTAP-20260410-0013. CVEs: CVE-2026-21710. Multiple NetApp products incorporate Node.js. All Node.js HTTP servers on 20.x, 22.x, 24.x, and 25.x are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260410-0012

Source: https://security.netapp.com/advisory/NTAP-20260410-0012/

NetApp security advisory NTAP-20260410-0012. CVEs: CVE-2026-21714. Multiple NetApp products incorporate Node.js. Node.js versions 20.x, 22.x, 24.x, and 25.x are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260410-0009

Source: https://security.netapp.com/advisory/NTAP-20260410-0009/

NetApp security advisory NTAP-20260410-0009. CVEs: CVE-2026-33938. Multiple NetApp products incorporate Handlebars.js. Handlebars.js versions 4.0.0 through 4.7.8 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260410-0008

Source: https://security.netapp.com/advisory/NTAP-20260410-0008/

NetApp security advisory NTAP-20260410-0008. CVEs: CVE-2026-33939. Multiple NetApp products incorporate Handlebars.js. Handlebars.js versions 4.0.0 through 4.7.8 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260410-0007

Source: https://security.netapp.com/advisory/NTAP-20260410-0007/

NetApp security advisory NTAP-20260410-0007. CVEs: CVE-2026-33940. Multiple NetApp products incorporate Handlebars.js. Handlebars.js versions 4.0.0 through 4.7.8 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260410-0006

Source: https://security.netapp.com/advisory/NTAP-20260410-0006/

NetApp security advisory NTAP-20260410-0006. CVEs: CVE-2026-33941. Multiple NetApp products incorporate Handlebars.js. Handlebars.js versions 4.0.0 through 4.7.8 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
News

2026-09-02-nutanix-netapp-launch-virtualisation-migration-tie-up-it-brief-uk

Source: https://news.google.com/rss/articles/CBMiiAFBVV95cUxOM2w1cGh4UExnTnNRSFhUaWxwTGt6NGg1aFI1TVV3b2c1TVZodkltYVNabG9udDZ1OHowbi1VSU5UUmh1SE5DNjFyMFVuX09KbDNEaTRLZUVSQi01VGlleEJqb3RfdS14WkU0Qm5Hb0Jza1B1WkVtWG80UldWZUJCLTlLajVZTXVf?oc=5

IT Brief UK article from the NetApp ONTAP Google News RSS feed. Nutanix & NetApp launch virtualisation migration tie-up - IT Brief UK. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
News

2026-09-02-nutanix-and-netapp-form-strategic-alliance-with-new-integration-for-a-modern-clo

Source: https://news.google.com/rss/articles/CBMi0wFBVV95cUxOdUFENS1lMnJrbzNCUVV5QjNYQzB4Y1B1U2dwMWNQYzJGUU5UZ2tsZHJtb0l4WmVCdkl5TUpSV05mZFN4UXltTWYwc3FFcmlCOGFwemlSd0NwVktVZkg4Y3owa1pfcVFuWjRXM2RoWEoycThYYk5tdDRLcWM0MDZ6ZGNWeXBWNlhuTEVaWnZlMUhXTVJXT0FJNmV2ZDFKbjZpYTNCUTdCb1huR3Z6RjJrb2h0aTA2NENDcl9vR3hMNzRZUG9IWTZlQ1VHRVRUeEJrZnBB?oc=5

Intelligent CIO article from the NetApp ONTAP Google News RSS feed. Nutanix and NetApp form strategic alliance with new integration for a modern cloud platform - Intelligent CIO. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
AI

2026-09-02-netapp-launches-aide-to-unlock-enterprise-ai-potential-businesstoday-malaysia

Source: https://news.google.com/rss/articles/CBMioAFBVV95cUxNSk5EVThWQWF4cVRjUUswYUVvQWw5T25vUG1IaHVzTl9hVkJjYlRGLW5vRDJOb1ZwR2ZiazZUdE4tWW5wbDlLRXYxd0hBNU55dWpXMGpnb0NOZjFkbjFacEJ5Mnh2TXFtWGEwYzUzUElMbnBUOEFGUUdHdXJOcmNSUEdMLVJjZS1DdTRET3JfR3Z6STNLcGNRVTdQY1BzSndr?oc=5

BusinessToday Malaysia article from the NetApp NVIDIA Google News RSS feed. NetApp Launches AIDE To Unlock Enterprise AI Potential - BusinessToday Malaysia. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-ai-infrastructure-modernization-drives-storage-rethink-siliconangle

Source: https://news.google.com/rss/articles/CBMipgFBVV95cUxQOU90c2U4NjB6X2R6QmJpa1hNdTRXcWFkQlJmbjFmWDE1emk4ZDJrb0hNM25uR1M4UTVST2s2dEhrVG1rdzZwWVc4elJFMHowWEhHbDV4WXBKOFdGcGFvLXFVV0dhaW1iaFZqd3UwM3h0Sk1VcXZzbTBqTkJ5THpScm5VSzJCdElYdjd3YTNnaXBCUTE4aWI5UEJRYlZ3dE5HS3pucHlR?oc=5

SiliconANGLE article from the NetApp AI Google News RSS feed. AI infrastructure modernization drives storage rethink - SiliconANGLE. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-netapp-malaysia-enhances-ai-platform-with-new-data-engine-wider-nvidia-support-f

Source: https://news.google.com/rss/articles/CBMipwFBVV95cUxONnRnYzdhcmYxUkhwcWlmU3FjekJEUmxYOElmb25LMno3NWZNT25hVWF2d2hBUktzRVZIZVFWOTh6SzJRSWRLUlNFcFdTNDVSNHlSOVlVS2N6N0FEd2RQa2NlV3V1eno5Zk9PQ0RqYUQtU0pzblc1RkU0NDcya2Z0QjIzNWhWdUJZajdGd2czeUpqWGt0dDVzZVB6WXotOGNpVU1ROU5oQQ?oc=5

Focus Malaysia article from the NetApp NVIDIA Google News RSS feed. NetApp Malaysia enhances AI platform with new data engine, wider NVIDIA support - Focus Malaysia. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Product

Nutanix and NetApp Announce Integration to Align ONTAP with Nutanix Cloud Platform

Source: StorageReview.com

NetApp and Nutanix announced a strategic integration aligning ONTAP with the Nutanix Cloud Platform, enabling VM migration between platforms in minutes rather than days and letting Nutanix clusters consume ONTAP-backed storage. The alliance targets hybrid IT modernization and cyber-resilient infrastructure joint customers.

Archive digest
Advisory

Intel SA-01244 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0009/

NetApp published this interim advisory covering CVE-2025-20103, CVE-2025-20054; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3591 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0001/

NetApp published this interim advisory covering CVE-2026-3591; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3260 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0015/

NetApp published this final advisory covering CVE-2026-3260; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3119 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0002/

NetApp published this interim advisory covering CVE-2026-3119; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3104 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0004/

NetApp published this interim advisory covering CVE-2026-3104; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1519 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0003/

NetApp published this final advisory covering CVE-2026-1519; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8941 Linux-Pam Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0006/

NetApp published this interim advisory covering CVE-2025-8941; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-6020 Linux-Pam Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0005/

NetApp published this interim advisory covering CVE-2025-6020; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-20100 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0010/

NetApp published this interim advisory covering CVE-2025-20100; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20044 Intel TDX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0014/

NetApp published this interim advisory covering CVE-2025-20044; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20004 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0011/

NetApp published this interim advisory covering CVE-2025-20004; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-48869 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0012/

NetApp published this interim advisory covering CVE-2024-48869; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45332 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0008/

NetApp published this interim advisory covering CVE-2024-45332; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-33607 Intel TDX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0013/

NetApp published this interim advisory covering CVE-2024-33607; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22365 Linux-Pam Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0007/

NetApp published this interim advisory covering CVE-2024-22365; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
AI

Remote NetApp array over photonic link nears local access speed

Source: Blocks & Files — https://www.blocksandfiles.com/architecture/2026/04/02/remote-netapp-array-over-photonic-link-nears-local-access-speed/5213828/

A proof of concept with the IOWN Global Forum showed metro-distance access to a NetApp flash array is almost as fast as local access, with GPU training time increases under 1% over 3,000 km via photonic (optical) links. The scenario places GPU servers in rural locations with cheap power while data stays on NetApp flash arrays in metro datacenters — cutting energy costs up to 30%. Relevant to AI infrastructure economics: decoupling compute siting from storage latency for AI training workloads.

Open source
News

Remote NetApp array over photonic link nears local access speed

Source: https://www.blocksandfiles.com/architecture/2026/04/02/remote-netapp-array-over-photonic-link-nears-local-access-speed/5213828

Blocks & Files coverage of an IOWN proof of concept in which GPU training over a 3,000 km photonic link to NetApp storage increased training time by less than 1 percent.

Open source
AI

NetApp Embraces Lustre as AI Pushes Storage Limits

Source: HPCwire

HPCwire covers NetApp embracing the Lustre parallel file system as AI/HPC workloads push beyond traditional NAS limits, complementing its disaggregated ONTAP architecture and AI Data Engine. The move signals NetApp competing directly with parallel-FS specialists for large-scale model training storage.

Archive digest
AI

NetApp Embraces Lustre as AI Pushes Storage Limits

Source: HPCwire (via Google News)

HPCwire reports NetApp embracing the Lustre parallel filesystem as part of its AI/HPC storage strategy — acknowledging that massive training runs increasingly demand parallel-FS bandwidth alongside ONTAP's data management. Signals NetApp's willingness to meet HPC sites where they are rather than forcing a single filesystem.

Open source
Advisory

CVE-2026-3805 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0001/

NetApp published this interim advisory covering CVE-2026-3805; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-3784 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0003/

NetApp published this interim advisory covering CVE-2026-3784; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-3783 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0004/

NetApp published this interim advisory covering CVE-2026-3783; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP 9.

Open source
Advisory

CVE-2026-1965 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0002/

NetApp published this interim advisory covering CVE-2026-1965; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-58060 CUPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0009/

NetApp published this final advisory covering CVE-2025-58060; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-57347 Node.js dagre-d3-es Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0008/

NetApp published this final advisory covering CVE-2025-57347; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48795 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0014/

NetApp published this interim advisory covering CVE-2025-48795; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; SnapCenter.

Open source
Advisory

CVE-2025-46394 BusyBox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0010/

NetApp published this interim advisory covering CVE-2025-46394; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-15224 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0005/

NetApp published this interim advisory covering CVE-2025-15224; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-13034 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0006/

NetApp published this interim advisory covering CVE-2025-13034; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-11234 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0015/

NetApp published this final advisory covering CVE-2025-11234; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22898 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0007/

NetApp published this interim advisory covering CVE-2021-22898; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

2026-09-01-ntap-20260327-0011

Source: https://security.netapp.com/advisory/NTAP-20260327-0011/

NetApp security advisory NTAP-20260327-0011. CVEs: CVE-2026-23949. Multiple NetApp products incorporate Jaraco.Context. Jaraco.context versions 5.2.0 prior to 6.1.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information.

Open source
AI

2026-09-02-netapp-s-cecile-kellam-dani-conner-unified-data-fabric-could-help-agencies-harne

Source: https://news.google.com/rss/articles/CBMihgFBVV95cUxNQWYyOHYtX000bFdQLXl5VGpOZ1pLcEpoX2ljQ3FsTWp5cENydW1VVGFyTW5heTdJcGw5LThLR2JuYk5WRzBBTUpaWjQ3ME1taHN0dENya0VSY0d1cnh1SWFzMjNiUEZ4bGt2UHRUY05HY05GWFZmZFZiZmpsY1VnZFFYdzJSQQ?oc=5

govconwire.com article from the NetApp AI Google News RSS feed. NetApp’s Cecile Kellam, Dani Conner: Unified Data Fabric Could Help Agencies Harness AI’s Potential - govconwire.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

NetApp Goes All-In on AI Infrastructure, and the Numbers Back It Up

Source: iTWire via Google News — https://news.google.com/rss/articles/CBMivgFBVV95cUxNOFR3WlZXWlZPdU5vLS1ncjhzcDVqaHo0dHo1SVdTSVFVcFZoZmxueEFQNDB5ajQ1QWdGUmd3TDVaRXo0UkZHT19sTEwyWlNMaWtkMERVTmctQXZxdWNyR2pjNEptb2dXaFB6RWpqZkgxLU1FTW1hX0ZTWVpCQkpjbnlhWW93Vm5ZRXdfRGJyOGR5SGxuNXlYV1NSdF9qcUlYZ0U4aUxtcFVmMVZ5UUxNN1BMM1hRTkQ0eExWSHN3?oc=5

iTWire argues NetApp's all-in AI infrastructure strategy is showing up in the numbers — all-flash ARR growth and AI-adjacent deal flow supporting the pivot toward Intelligent Data Infrastructure and the NVIDIA-aligned stack.

Open source
AI

NetApp Goes All-In on AI Infrastructure, and the Numbers Back It Up

Source: iTWire (via Google News) — https://news.google.com/rss/articles/CBMivgFBVV95cUxNOFR3WlZXWlZPdU5vLS1ncjhzcDVqaHo0dHo1S?oc=5

iTWire analysis piece arguing NetApp has committed fully to AI infrastructure — AI Data Engine, AFX/AIPod portfolio, and NVIDIA partnerships — and that financial numbers (all-flash momentum, AI-deployment counts in earnings calls) support the strategy. Context piece on the AI-driven growth narrative ahead of recent record quarterly results.

Open source
Advisory

December 2025 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0007/

NetApp published this final advisory covering CVE-2025-55130, CVE-2025-55132, CVE-2025-59465; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-27446 Apache ActiveMQ Artemis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0011/

NetApp published this final advisory covering CVE-2026-27446; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-2673 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0015/

NetApp published this interim advisory covering CVE-2026-2673; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-25749 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0010/

NetApp published this interim advisory covering CVE-2026-25749; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1489 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0002/

NetApp published this interim advisory covering CVE-2026-1489; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-0988 GLib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0004/

NetApp published this interim advisory covering CVE-2026-0988; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-9714 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0006/

NetApp published this interim advisory covering CVE-2025-9714; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-55131 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0008/

NetApp published this final advisory covering CVE-2025-55131; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-43590 Visual Studio Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0009/

NetApp published this final advisory covering CVE-2024-43590; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-41409 PCRE2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0014/

NetApp published this interim advisory covering CVE-2022-41409; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
AI

2026-09-02-netapp-goes-all-in-on-ai-infrastructure-and-the-numbers-back-it-up-itwire

Source: https://news.google.com/rss/articles/CBMivgFBVV95cUxNOFR3WlZXWlZPdU5vLS1ncjhzcDVqaHo0dHo1SVdTSVFVcFZoZmxueEFQNDB5ajQ1QWdGUmd3TDVaRXo0UkZHT19sTEwyWlNMaWtkMERVTmctQXZxdWNyR2pjNEptb2dXaFB6RWpqZkgxLU1FTW1hX0ZTWVpCQkpjbnlhWW93Vm5ZRXdfRGJyOGR5SGxuNXlYV1NSdF9qcUlYZ0U4aUxtcFVmMVZ5UUxNN1BMM1hRTkQ0eExWSHN3?oc=5

iTWire article from the NetApp NVIDIA Google News RSS feed. NetApp Goes All-In on AI Infrastructure, and the Numbers Back It Up - iTWire. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

2026-09-01-ntap-20260320-0013

Source: https://security.netapp.com/advisory/NTAP-20260320-0013/

NetApp security advisory NTAP-20260320-0013. CVEs: CVE-2026-23231. Multiple NetApp products incorporate Linux kernel. Certain versions of linux kernel are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260320-0012

Source: https://security.netapp.com/advisory/NTAP-20260320-0012/

NetApp security advisory NTAP-20260320-0012. CVEs: CVE-2026-27141. Multiple NetApp products incorporate Golang. golang.org/x/net/http2 versions 0.50.0 prior to 0.51.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260320-0005

Source: https://security.netapp.com/advisory/NTAP-20260320-0005/

NetApp security advisory NTAP-20260320-0005. CVEs: CVE-2026-0861. Multiple NetApp products incorporate GNU C. GNU C Library (aka glibc) versions 2.30 through 2.42 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260320-0003

Source: https://security.netapp.com/advisory/NTAP-20260320-0003/

NetApp security advisory NTAP-20260320-0003. CVEs: CVE-2026-1484. Multiple NetApp products incorporate GLib. GLib versions 2.87.0 through 2.87.3 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260320-0001

Source: https://security.netapp.com/advisory/NTAP-20260320-0001/

NetApp security advisory NTAP-20260320-0001. CVEs: CVE-2026-1485. Multiple NetApp products incorporate GLib. GLib versions through 2.86.3 and 2.87.0 through 2.87.2 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
AI

2026-09-02-nvidia-gtc-2026-the-rise-of-ai-requires-a-rethink-of-enterprise-storage-technolo

Source: https://news.google.com/rss/articles/CBMitAFBVV95cUxOLVhZUkhzbWtLd2dwN0RpTmIxb3pOR0FFcFM3WHJNSGdQYkc5dmNkS09CaVFEY2JvTkkyaTBldFc4SFY5Sml5R3h4S3hMbEJlY0tFSnFxYnZUMkI5b05iYWt3ZmlhR2drN190MHd1SHdibGtfMDdjX2NMVEF1cFhabzlKc29WLUJfblgxOV9GZE5OV29QTVpVWEo1Y2VBeE11YVJRakNnOXJHUzQ1UXVzY2JyT3o?oc=5

BizTech Magazine article from the NetApp NVIDIA Google News RSS feed. NVIDIA GTC 2026: The Rise of AI Requires a Rethink of Enterprise Storage Technology - BizTech Magazine. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Product

NetApp unveils next-gen EF-Series arrays & AI data platform to solve enterprise bottlenecks

Source: SDxCentral via Google News — https://news.google.com/rss/articles/CBMivwFBVV95cUxPRkZNX0xkRHBjX3RLSFpmNnQxMm5TTEtxLWdfNGcyMGZwempHMkRHalNsWi1kd2gtQXQ2VVRRNUp6cWU5ZGMtcW51RjlydUlLMUp1MzNGcFc5UmFzUGk3V0NMbU56X0tfWHMwYmdhYTBuNkxXUF9mSDRCODFWWW1uVWZfeDNkMndMdVFHbmJuaE96b0V4aXBhZ0dTbm5sZGhxX0JVWkRRcGJTcXBvdlA1QVI2RU9wSW1MdlE5b2NRaw?oc=5

SDxCentral's coverage of NetApp's next-generation EF-Series flash arrays alongside the AI data platform push (AI Data Engine / AFX era) — positioning both HPC-oriented EF bandwidth and ONTAP-based data activation as answers to enterprise AI data bottlenecks.

Open source
Product

NetApp unveils next-gen EF-Series arrays & AI data platform to solve enterprise bottlenecks

Source: SDxCentral (via Google News) — https://news.google.com/rss/articles/CBMivwFBVV95cUxPRkZNX0xkRHBjX3RLSFpmNnQxMm5TTEtxLWdfN?oc=5

SDxCentral covered NetApp's launch of next-generation EF-Series all-flash arrays alongside its AI data platform push (AI Data Engine), positioning the pair as a fix for enterprise AI data bottlenecks — high-performance SAN storage for training/inference plus a data orchestration layer above it.

Open source
AI

2026-09-02-netapp-unveils-next-gen-ef-series-arrays-ai-data-platform-to-solve-enterprise-bo

Source: https://news.google.com/rss/articles/CBMivwFBVV95cUxPRkZNX0xkRHBjX3RLSFpmNnQxMm5TTEtxLWdfNGcyMGZwempHMkRHalNsWi1kd2gtQXQ2VVRRNUp6cWU5ZGMtcW51RjlydUlLMUp1MzNGcFc5UmFzUGk3V0NMbU56X0tfWHMwYmdhYTBuNkxXUF9mSDRCODFWWW1uVWZfeDNkMndMdVFHbmJuaE96b0V4aXBhZ0dTbm5sZGhxX0JVWkRRcGJTcXBvdlA1QVI2RU9wSW1MdlE5b2NRaw?oc=5

SDxCentral article from the NetApp AI Google News RSS feed. NetApp unveils next-gen EF-Series arrays & AI data platform to solve enterprise bottlenecks - SDxCentral. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-netapp-accelerates-momentum-in-ai-leadership-with-nvidia-cxo-digitalpulse

Source: https://news.google.com/rss/articles/CBMikwFBVV95cUxQMTM1aTE1bGY0VVNsNHdjNnpwclEzb2kycWRsdXlJS0xybVZqQkNjbEFkNzZtUjZsdUFrWDNyanI3ZGZ2eWZBOUJibFZ1VUhtY1dkdFNQZUJSQ29jM3EzOUJmeGV4RnN6b0NFZC12RmN1bGtwMEhGb0pJSi1BOHk1VS1ZZVZfTE9JTGo3OVVCd2NDY2s?oc=5

CXO Digitalpulse article from the NetApp NVIDIA Google News RSS feed. NetApp Accelerates Momentum in AI Leadership with NVIDIA - CXO Digitalpulse. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

Jensen Huang & George Kurian: Revolutionary AI products — NVIDIA GTC 2026 joint keynote

Source: https://www.nvidia.com/gtc/sessions/speaker-jensen-huang-george-kurian/

Jensen Huang (NVIDIA) and George Kurian (NetApp) take the GTC 2026 keynote stage together to announce expanded co-engineering for agentic AI factories: AIPod with NVIDIA reference designs, GPUDirect Storage on NetApp EF-Series, NVIDIA NIM microservices validated against ONTAP, and the joint Enterprise AI factory blueprint that ties HGX/HGX-B200 systems to ONTAP data pipelines. Pitches the NetApp platform as the data foundation for NVIDIA Blackwell infrastructure and a unified path for customers moving from proof-of-concept agent prototypes into production at scale.

Open source
AI

2026-09-02-nvidia-launches-bluefield-4-stx-storage-architecture-for-agentic-ai-at-gtc-2026-

Source: https://news.google.com/rss/articles/CBMirwFBVV95cUxPeGxrVTVZcERJUkNIQW5KREU3NG41V0dST0gzelZwNTB4R2FZVmNlTVQ1YkxqQ1U1NHdHSEtYTWwzS28zQzBKZEtDbzU0MzNMbmc4SHR5MlA2STg3MlRIUVhCZXgzVWp2aDJtVXdMTmRnejkxNXZnMlV2T2VJczFsaU9wcU5sdmpUcXhGMnFYc3RhdzJVWThTYkFycldUT2pxejFLUWo3YW4xVTRCcFBZ?oc=5

Tom's Hardware article from the NetApp NVIDIA Google News RSS feed. Nvidia launches BlueField-4 STX storage architecture for agentic AI at GTC 2026 - Tom's Hardware. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-vultr-adopts-nvidia-rubin-platform-nvidia-dynamo-and-nvidia-nemotron-to-reinvent

Source: https://news.google.com/rss/articles/CBMi8wFBVV95cUxNUDVEdDM0UjR0QjRQZ3hvX0MxZ3E5c1h1S2hYSHhJbzVpNVZTRE9wdUdLOFpKTDY0a1g1MVROaGlIWXhUcEZJZmhjakt0ZElXX0xRQVZWa3pFWG0yN3M1TldaX1dZdTlvMXJkaW9RM2FXWlotWFpCMEo0aGJiLXdRWDYtZERPdWhUQ0RydlRZMmhlaFlRMDVnTmdmSkptOWdlZW5ZSXZkY2JoN2g1R2dSbU9pcTJHTkstV2w3SEZaODV2eUtXall0VDRlUWpNSWRISDRzTmdvdTFOanBaSUhtbUt2a19QU1c0QTh2cmNoelBHSjg?oc=5

Business Wire article from the NetApp NVIDIA Google News RSS feed. Vultr Adopts NVIDIA Rubin Platform, NVIDIA Dynamo, and NVIDIA Nemotron to Reinvent Enterprise AI Inference - Business Wire. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-vultr-adopts-nvidia-rubin-platform-along-with-dynamo-nemotron-channel-insider

Source: https://news.google.com/rss/articles/CBMiggFBVV95cUxQVUIwaEhrOXd5OUQ0RlJOVWxxYkt5ZUhWOFR4TlBYM2RYNzF2UmdUYVd5NXBhVnFZNm1YbVdTUG55OTBDRG5sWWFkY19QYUx6UUtBQVRBTUpmWm1lajB0azRxUDU2WjBkUEQzbTBtb211Z0g2czdkZW12NEdKTFp4dHpB?oc=5

Channel Insider article from the NetApp NVIDIA Google News RSS feed. Vultr Adopts NVIDIA Rubin Platform Along with Dynamo & Nemotron - Channel Insider. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-nvidia-launches-bluefield-4-stx-storage-architecture-with-broad-industry-adoptio

Source: https://news.google.com/rss/articles/CBMitgFBVV95cUxPUG9yUG1DWW9LY0loM29UR3ZKLTNpaUFTTVVaRmR0eDJvSUZMMlp2bXpoU2wtZ1FwekNtWk15TlBBZ3Z0YjdDUFc3Y3FsQWlUYUtOMC1qUnNZcUpJb2ZVNmtucmVoOEowdTdPdUVxSG9UdHBuSjduSXJjSld1azJURnVaMWVWY0dLRTQxMHkzWndIM0VzRlN6UXBCVWl3Rkk4eXpNQmdFOVUyZmQzRVFPV1RNY2lodw?oc=5

nvidianews.nvidia.com article from the NetApp NVIDIA Google News RSS feed. NVIDIA Launches BlueField-4 STX Storage Architecture With Broad Industry Adoption - nvidianews.nvidia.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

Intel SA-01315 Intel AMT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0015/

NetApp published this interim advisory covering CVE-2025-32008, CVE-2025-20080; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1642 Nginx Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0008/

NetApp published this interim advisory covering CVE-2026-1642; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2026-0915 Glibc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0003/

NetApp published this interim advisory covering CVE-2026-0915; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-68372 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0007/

NetApp published this interim advisory covering CVE-2025-68372; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-5702 Glibc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0002/

NetApp published this interim advisory covering CVE-2025-5702; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-41117 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0006/

NetApp published this final advisory covering CVE-2025-41117; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27708 Intel CSME Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0013/

NetApp published this interim advisory covering CVE-2025-27708; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15281 Glibc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0001/

NetApp published this interim advisory covering CVE-2025-15281; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-14104 Util-linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0012/

NetApp published this interim advisory covering CVE-2025-14104; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-11413 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0011/

NetApp published this interim advisory covering CVE-2025-11413; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260313-0010

Source: https://security.netapp.com/advisory/NTAP-20260313-0010/

NetApp security advisory NTAP-20260313-0010. CVEs: CVE-2026-25639. Multiple NetApp products incorporate Axios. Axios versions prior to 0.30.3 prior and to 1.13.5 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260313-0009

Source: https://security.netapp.com/advisory/NTAP-20260313-0009/

NetApp security advisory NTAP-20260313-0009. CVEs: CVE-2026-21637. Multiple NetApp products incorporate Node.js. Certain versions of Node.js are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

Intel SA-01397 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0003/

NetApp published this interim advisory covering CVE-2025-30513, CVE-2025-31944, CVE-2025-32007, CVE-2025-32467, CVE-2025-27572, CVE-2025-27940; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-27171 Zlib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0015/

NetApp published this interim advisory covering CVE-2026-27171; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Management Services for Element Software and NetApp HCI; NetApp LOADER 8.x; Trident.

Open source
Advisory

CVE-2026-26278 Fast-xml-parser Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0007/

NetApp published this interim advisory covering CVE-2026-26278; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-25896 Fast-xml-parser Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0006/

NetApp published this interim advisory covering CVE-2026-25896; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-21636 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0014/

NetApp published this final advisory covering CVE-2026-21636; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61726 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0009/

NetApp published this interim advisory covering CVE-2025-61726; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent; ONTAP tools for VMware vSphere 10; Trident Protect.

Open source
Advisory

CVE-2025-59466 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0011/

NetApp published this final advisory covering CVE-2025-59466; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-59464 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0012/

NetApp published this final advisory covering CVE-2025-59464; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-58190 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0008/

NetApp published this interim advisory covering CVE-2025-58190; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Trident Protect.

Open source
Advisory

CVE-2025-31648 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0002/

NetApp published this interim advisory covering CVE-2025-31648; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-23166 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0013/

NetApp published this final advisory covering CVE-2025-23166; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22885 Intel TDX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0004/

NetApp published this interim advisory covering CVE-2025-22885; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260311-0010

Source: https://security.netapp.com/advisory/NTAP-20260311-0010/

NetApp security advisory NTAP-20260311-0010. CVEs: CVE-2026-26007. Multiple NetApp products incorporate pyca/cryptography. Cryptography versions prior to 46.0.5 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information.

Open source
Advisory

2026-09-01-ntap-20260311-0001

Source: https://security.netapp.com/advisory/NTAP-20260311-0001/

NetApp security advisory NTAP-20260311-0001. CVEs: CVE-2026-22610. Multiple NetApp products incorporate Angular. Angular versions prior to 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

February 2026 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0001/

NetApp published this final advisory covering CVE-2025-13473, CVE-2025-14550, CVE-2026-1207, CVE-2026-1285, CVE-2026-1287, CVE-2026-1312; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-26158 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0007/

NetApp published this interim advisory covering CVE-2026-26158; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-26157 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0006/

NetApp published this interim advisory covering CVE-2026-26157; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-23016 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0019/

NetApp published this interim advisory covering CVE-2026-23016; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1225 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0008/

NetApp published this interim advisory covering CVE-2026-1225; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; SnapCenter.

Open source
Advisory

CVE-2026-0865 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0014/

NetApp published this interim advisory covering CVE-2026-0865; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2025-9820 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0016/

NetApp published this interim advisory covering CVE-2025-9820; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-37731 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0005/

NetApp published this final advisory covering CVE-2025-37731; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36428 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0004/

NetApp published this final advisory covering CVE-2025-36428; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36353 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0003/

NetApp published this final advisory covering CVE-2025-36353; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-2534 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0002/

NetApp published this final advisory covering CVE-2025-2534; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15367 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0013/

NetApp published this interim advisory covering CVE-2025-15367; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15366 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0012/

NetApp published this interim advisory covering CVE-2025-15366; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15282 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0011/

NetApp published this interim advisory covering CVE-2025-15282; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-14831 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0015/

NetApp published this interim advisory covering CVE-2025-14831; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-12781 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0010/

NetApp published this interim advisory covering CVE-2025-12781; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-11468 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0009/

NetApp published this interim advisory covering CVE-2025-11468; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260305-0018

Source: https://security.netapp.com/advisory/NTAP-20260305-0018/

NetApp security advisory NTAP-20260305-0018. CVEs: CVE-2026-23001. Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260305-0017

Source: https://security.netapp.com/advisory/NTAP-20260305-0017/

NetApp security advisory NTAP-20260305-0017. CVEs: CVE-2026-22988. Multiple NetApp products incorporate Linux kernel. Certain versions of Linux Kernel are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Docs

2026-09-05-kb-ontap-volumes-aggregates-free-space-recommendation

Source: https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/What_is_the_recommended_free_space_to_maintain_in_ONTAP_volumes_and_aggregates_for_optimal_operation

Documents NetApp's published minimum-free-space thresholds for both volumes and aggregates (the so-called WAFL reserve) — historically 10% for aggregates (5% on modern AFF with WAFL reserve reduction) and 10% per volume — and explains what breaks when each threshold is crossed: aggregate full blocks new writes, overwrites and triggers `wafl_vol_blocked`, while volume-level fullness breaks Snapshot reserve calculations and dedupe metadata. The KB also covers the difference between `volume show -fields percent-used,available` thresholds versus the system-level `aggr show_space` WAFL reserve. Practical reading for capacity planners who are sizing new AFF/AFF-A800 / FAS deployments or troubleshooting why Snapshot copies are being auto-deleted at low overall utilization.

Open source
Advisory

CVE-2026-24734 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0003/

NetApp published this final advisory covering CVE-2026-24734; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-24733 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0002/

NetApp published this interim advisory covering CVE-2026-24733; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8191 Swagger UI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0011/

NetApp published this interim advisory covering CVE-2025-8191; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent).

Open source
Advisory

CVE-2025-66614 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0001/

NetApp published this interim advisory covering CVE-2025-66614; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-66516 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0004/

NetApp published this interim advisory covering CVE-2025-66516; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36425 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0015/

NetApp published this final advisory covering CVE-2025-36425; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36247 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0012/

NetApp published this final advisory covering CVE-2025-36247; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-14689 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0014/

NetApp published this final advisory covering CVE-2025-14689; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-13867 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0013/

NetApp published this final advisory covering CVE-2025-13867; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-49861 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0007/

NetApp published this interim advisory covering CVE-2024-49861; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2024-41996 Diffie-Hellman Key Exchange Protocol Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0009/

NetApp published this interim advisory covering CVE-2024-41996; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Manageability SDK; NetApp Shift Toolkit; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-26581 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0005/

NetApp published this final advisory covering CVE-2024-26581; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4623 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0006/

NetApp published this interim advisory covering CVE-2023-4623; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-40735 Diffie-Hellman Key Exchange Protocol Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0008/

NetApp published this interim advisory covering CVE-2022-40735; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Manageability SDK; NetApp Shift Toolkit; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2002-20001 Diffie-Hellman Key Exchange Protocol Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0010/

NetApp published this interim advisory covering CVE-2002-20001; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Manageability SDK; NetApp Shift Toolkit; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
AI

NetApp Embraces Lustre as AI Pushes Storage Limits (HPCwire)

Source: https://www.hpcwire.com/2026/02/25/netapp-lustre-ai-storage/

HPCwire coverage of NetApp integrating Lustre parallel file systems alongside ONTAP and EF-Series as AI training workloads push the limits of POSIX file semantics. The piece frames NetApp's positioning as a tiered AI data platform: Lustre for hot training data, ONTAP for governance/metadata/checkpoints, and EF-Series NVMe for the GPUDirect path. Useful signal of how NetApp plans to coexist with purpose-built parallel-FS vendors while still anchoring enterprise data on ONTAP.

Open source
Advisory

CVE-2026-1757 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0011/

NetApp published this interim advisory covering CVE-2026-1757; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Manageability SDK.

Open source
Advisory

CVE-2026-0992 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0012/

NetApp published this interim advisory covering CVE-2026-0992; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Manageability SDK.

Open source
Advisory

CVE-2025-66863 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0014/

NetApp published this interim advisory covering CVE-2025-66863; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36442 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0002/

NetApp published this final advisory covering CVE-2025-36442; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36387 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0008/

NetApp published this final advisory covering CVE-2025-36387; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36384 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0004/

NetApp published this final advisory covering CVE-2025-36384; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36366 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0007/

NetApp published this final advisory covering CVE-2025-36366; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36184 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0005/

NetApp published this final advisory covering CVE-2025-36184; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36123 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0010/

NetApp published this final advisory covering CVE-2025-36123; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36008 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0003/

NetApp published this final advisory covering CVE-2025-36008; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36001 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0009/

NetApp published this final advisory covering CVE-2025-36001; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-2668 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0001/

NetApp published this final advisory covering CVE-2025-2668; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-47118 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0006/

NetApp published this final advisory covering CVE-2024-47118; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260220-0013

Source: https://security.netapp.com/advisory/NTAP-20260220-0013/

NetApp security advisory NTAP-20260220-0013. CVEs: CVE-2026-0990. Multiple NetApp products incorporate libxml2. Libxml2 versions through 2.15.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
AI

Designing for agentic AI with open-source tools (NetApp engineering blog)

Source: https://www.netapp.com/blog/designing-for-agentic-ai/

NetApp engineering blog on designing agentic AI systems with open-source tool stacks (LangGraph, MCP servers, ONTAP as the agent's data plane). Walks through how an agent should call ONTAP primitives (snapshots, clones, SnapMirror, S3 access points), how RBAC maps to agent identities, and what governance surfaces an enterprise should require before letting an agent write to production storage. Companion to the AI Data Engine launch announcements.

Open source
AI

NetApp, SK Telecom test AI workloads on virtual machines (Tech in Asia)

Source: https://www.techinasia.com/netapp-sk-telecom-ai-vm-workloads/

Tech in Asia reports on a NetApp + SK Telecom joint trial that ran agentic AI workloads on VMs backed by ONTAP storage, evaluating throughput, multi-tenancy isolation, and how agent memory persists across sessions. The piece frames it as one of the first public APAC-carrier demonstrations of an AI-factory pattern outside the hyperscalers, with NetApp providing both the storage layer and the data-engineering tooling.

Open source
Advisory

CVE-2025-55193 Ruby Gem Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0002/

NetApp published this interim advisory covering CVE-2025-55193; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-39973 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0016/

NetApp published this interim advisory covering CVE-2025-39973; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-39971 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0017/

NetApp published this interim advisory covering CVE-2025-39971; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-38622 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0020/

NetApp published this interim advisory covering CVE-2025-38622; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400.

Open source
Advisory

CVE-2025-36427 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0005/

NetApp published this final advisory covering CVE-2025-36427; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36424 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0007/

NetApp published this final advisory covering CVE-2025-36424; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36423 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0008/

NetApp published this final advisory covering CVE-2025-36423; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36365 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0004/

NetApp published this final advisory covering CVE-2025-36365; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36098 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0006/

NetApp published this final advisory covering CVE-2025-36098; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36070 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0009/

NetApp published this final advisory covering CVE-2025-36070; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24293 Ruby Gem Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0001/

NetApp published this interim advisory covering CVE-2025-24293; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15079 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0013/

NetApp published this interim advisory covering CVE-2025-15079; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-14819 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0014/

NetApp published this interim advisory covering CVE-2025-14819; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-14524 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0015/

NetApp published this interim advisory covering CVE-2025-14524; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP 9.

Open source
Advisory

CVE-2025-11002 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0011/

NetApp published this final advisory covering CVE-2025-11002; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2025-11001 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0012/

NetApp published this final advisory covering CVE-2025-11001; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Trident Autosupport.

Open source
Advisory

CVE-2024-57699 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0003/

NetApp published this final advisory covering CVE-2024-57699; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26594 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0018/

NetApp published this final advisory covering CVE-2024-26594; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
AI

2026-09-02-ai-ad-of-the-week-netapp-invokes-lemmings-to-illustrate-risks-of-ai-hype-adage-c

Source: https://news.google.com/rss/articles/CBMiaEFVX3lxTFBPWmtEMGZlZ1hJNi1zRzFmTHNxVlFaUENnYTQ2cmRvdk5lQmFyalNET3BCUmczc054d25OZk9DNWRLcHNMY19KVVNYSmp0NHptSk5OX29uS0Q5SEU2ekloUVV3dHVEMkox?oc=5

adage.com article from the NetApp AI Google News RSS feed. AI ad of the week: NetApp invokes lemmings to illustrate risks of AI hype - adage.com. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

NetApp FlexPod AI expands enterprise AI reference architectures (Cisco + NVIDIA)

Source: https://www.netapp.com/blog/flexpod-ai-expands-enterprise-ai/

NetApp blog post on the expanded FlexPod AI reference architectures jointly delivered with Cisco and validated against NVIDIA HGX/HGX-B200 platforms. Documents the supported configurations (NVIDIA H100, H200, B200 GPUs; Cisco UCS X-Series; ONTAP AI / EF-Series storage tiers), the workloads they were validated for (training, fine-tuning, RAG inference), and the partner roles for delivery.

Open source
AI

2026-09-04-aipod-mini-rag-intel

Source: https://docs.netapp.com/us-en/netapp-solutions-ai/infra/ai-minipod.html

NVA-style reference design (dated 2026-02-12) for a small-footprint RAG inferencing stack: Intel Xeon 6 processors + NetApp AIPod Mini storage + a downstream ChatQnA-style application running a large language model. The validated design demonstrates multi-user concurrent queries that pull context from an organization's internal corpus through retrieval-augmented generation, with NetApp handling the data layer (ONTAP volumes for the embedding store + raw documents; SnapMirror to move snapshots of refreshed data into the inference cluster). Pairs with Intel Xeon 6 (Granite Rapids / Sierra Forest family) so the inference compute stays x86 — useful for shops with an Intel-only datacenter standard. Why it matters: this is the smaller sibling to AIPod with NVIDIA DGX (which targets foundation-model training/inference at scale) and AIPod with Lenovo for NVIDIA OVX. AIPod Mini is for the ~1–10 GPU RAG deployments that are increasingly common as enterprises move from POC to production GenAI without buying DGX-class hardware. The Intel pairing also positions NetApp against the all-NVIDIA narrative.

Open source
AI

NetApp and Cisco expand FlexPod for enterprise AI infrastructure (Splunk SOAR storage)

Source: https://www.channele2e.com/news/netapp-cisco-flexpod-ai-2026/

ChannelE2E coverage of Cisco + NetApp expanding FlexPod with validated AI architectures and adding Splunk SOAR storage references: converged-stack blueprints for NVIDIA H100/H200 deployments with ONTAP as the unified file-and-block layer, plus a Splunk SOAR security-analytics reference for SOC teams running on FlexPod. Positions FlexPod as a converged alternative to the DIY NVIDIA-MGX stacks for enterprises that want Cisco networking + NetApp storage validated end-to-end.

Open source
AI

How Can NetApp and NVIDIA Transform Enterprise Data Management (Analytics India)

Source: https://analyticsindiamag.com/cloud/netapp-nvidia-enterprise-data-management/

Analytics India Magazine long-form on the NetApp-NVIDIA partnership: the joint go-to-market, the AIPod reference architectures, NVIDIA NIM + NeMo integration with NetApp AI Data Engine, and where Indian enterprises (BFSI, telecom, healthcare) are deploying the stack. Pairs well with the global coverage by adding an APAC angle and giving concrete customer examples that the US-centric trade press usually leaves out.

Open source
Advisory

CVE-2026-24061 GNU Internet Utilities Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0001/

NetApp published this final advisory covering CVE-2026-24061; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8177 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0004/

NetApp published this interim advisory covering CVE-2025-8177; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8176 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0003/

NetApp published this interim advisory covering CVE-2025-8176; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5449 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0011/

NetApp published this interim advisory covering CVE-2025-5449; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15547 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0015/

NetApp published this final advisory covering CVE-2025-15547; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-0736 Infinispan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0014/

NetApp published this interim advisory covering CVE-2025-0736; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2024-8244 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0006/

NetApp published this interim advisory covering CVE-2024-8244; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent.

Open source
Advisory

CVE-2023-3603 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0012/

NetApp published this interim advisory covering CVE-2023-3603; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-32253 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0002/

NetApp published this interim advisory covering CVE-2023-32253; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-1667 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0013/

NetApp published this interim advisory covering CVE-2023-1667; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-5397 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0007/

NetApp published this interim advisory covering CVE-2020-5397; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-1257 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0008/

NetApp published this interim advisory covering CVE-2018-1257; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-11040 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0010/

NetApp published this interim advisory covering CVE-2018-11040; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-11039 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0009/

NetApp published this interim advisory covering CVE-2018-11039; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
AI

NetApp updates data platform to address AI data challenges (CRN Asia)

Source: https://www.crnasia.com/news/netapp-data-platform-ai-challenges/

CRN Asia coverage of NetApp's data-platform updates targeting AI pipelines: ingest acceleration, vector-store integration, AI Data Engine GA in APAC regions, and tighter Azure NetApp Files integration for Microsoft Fabric / Azure OpenAI customers. Useful for tracking regional availability and channel-readiness of the AI features that NetApp announced at its global Q3 FY26 update.

Open source
Advisory

CVE-2025-69421 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0007/

NetApp published this interim advisory covering CVE-2025-69421; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-69420 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0006/

NetApp published this interim advisory covering CVE-2025-69420; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-69419 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0008/

NetApp published this interim advisory covering CVE-2025-69419; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); NetApp LOADER 8.x; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-69418 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0009/

NetApp published this interim advisory covering CVE-2025-69418; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp LOADER 8.x.

Open source
Advisory

CVE-2025-68813 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0002/

NetApp published this interim advisory covering CVE-2025-68813; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68160 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0010/

NetApp published this interim advisory covering CVE-2025-68160; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp LOADER 8.x.

Open source
Advisory

CVE-2025-66199 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0015/

NetApp published this interim advisory covering CVE-2025-66199; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp LOADER 8.x; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-15469 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0014/

NetApp published this interim advisory covering CVE-2025-15469; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-15468 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0013/

NetApp published this interim advisory covering CVE-2025-15468; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp LOADER 8.x; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-15467 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0011/

NetApp published this interim advisory covering CVE-2025-15467; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); NetApp Console Agent Container (storage_services); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-11187 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0012/

NetApp published this interim advisory covering CVE-2025-11187; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp LOADER 8.x; ONTAP 9.

Open source
Advisory

CVE-2024-56779 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0001/

NetApp published this interim advisory covering CVE-2024-56779; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

2026-09-01-ntap-20260204-0005

Source: https://security.netapp.com/advisory/NTAP-20260204-0005/

NetApp security advisory NTAP-20260204-0005. CVEs: CVE-2026-22795. Multiple NetApp products incorporate OpenSSL. OpenSSL versions 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1. are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260204-0004

Source: https://security.netapp.com/advisory/NTAP-20260204-0004/

NetApp security advisory NTAP-20260204-0004. CVEs: CVE-2026-22796. Multiple NetApp products incorporate OpenSSL. OpenSSL versions 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

September 2025 Apache Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0016/

NetApp published this interim advisory covering CVE-2025-58056, CVE-2025-58057; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

CVE-2026-0672 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0007/

NetApp published this interim advisory covering CVE-2026-0672; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2025-68973 GnuPG Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0014/

NetApp published this interim advisory covering CVE-2025-68973; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68493 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0012/

NetApp published this final advisory covering CVE-2025-68493; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68390 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0018/

NetApp published this interim advisory covering CVE-2025-68390; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68384 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0019/

NetApp published this interim advisory covering CVE-2025-68384; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-67735 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0017/

NetApp published this final advisory covering CVE-2025-67735; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61729 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0002/

NetApp published this interim advisory covering CVE-2025-61729; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Data Infrastructure Insights Telegraf Agent; NetApp Console Agent; ONTAP tools for VMware vSphere 10; Trident.

Open source
Advisory

CVE-2025-61727 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0003/

NetApp published this interim advisory covering CVE-2025-61727; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent; NetApp Console Agent; ONTAP tools for VMware vSphere 10; Trident; Trident Protect.

Open source
Advisory

CVE-2025-5916 Libarchive Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0020/

NetApp published this interim advisory covering CVE-2025-5916; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24528 Kerberos Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0015/

NetApp published this final advisory covering CVE-2025-24528; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-14017 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0009/

NetApp published this interim advisory covering CVE-2025-14017; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-13878 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0001/

NetApp published this interim advisory covering CVE-2025-13878; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-12543 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0005/

NetApp published this interim advisory covering CVE-2025-12543; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-3884 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0004/

NetApp published this interim advisory covering CVE-2024-3884; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-23944 Apache ZooKeeper Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0008/

NetApp published this interim advisory covering CVE-2024-23944; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights and Data Secure Storage Workload Security Agent.

Open source
News

2026-09-02-review-netapp-ontap-manages-data-in-a-scalable-and-secure-platform-for-federal-a

Source: https://news.google.com/rss/articles/CBMivwFBVV95cUxONDNEdDVGMWpxU3Y5Njk4TTh0NDhxa0lNWHRydVN6UFdma1NvS2oxZWcySHZpQWxiUE1Ba08tMmhMRzVfbC15eV8zR21ITmFjRko4Qk1BTHNxOWlUdkppX1JkanN5c1VVeW5yaGVobzBCMkNCU2swaFQ4dHJGdXVIVTZYYWNxb1JMbHQ1c3NBSmh2S2lDR1NZMk9VR0I1TURQQ1QteVdMd1NLUVhFZDhVSnROZW5LcVJ6dHlWeU1Xaw?oc=5

FedTech Magazine article from the NetApp ONTAP Google News RSS feed. Review: NetApp ONTAP Manages Data in a Scalable and Secure Platform for Federal Agencies - FedTech Magazine. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
Advisory

2026-09-01-ntap-20260130-0011

Source: https://security.netapp.com/advisory/NTAP-20260130-0011/

NetApp security advisory NTAP-20260130-0011. CVEs: CVE-2026-22801. Multiple NetApp products incorporate libpng. Libpng versions 1.6.26 prior to 1.6.54 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260130-0010

Source: https://security.netapp.com/advisory/NTAP-20260130-0010/

NetApp security advisory NTAP-20260130-0010. CVEs: CVE-2026-21441. Multiple NetApp products incorporate Urllib3. Urllib3 versions 1.22 prior to 2.6.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

January 2026 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0009/

NetApp published this interim advisory covering CVE-2025-9230, CVE-2026-21964, CVE-2026-21968, CVE-2026-21948, CVE-2026-21936, CVE-2026-21941, CVE-2026-21937; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

January 2026 MySQL Server 9.0.0 through 9.5.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0010/

NetApp published this interim advisory covering CVE-2026-21950, CVE-2026-21965, CVE-2026-21952, CVE-2026-21949, CVE-2026-21929; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2026 Java Platform Standard Edition 8u471-b50 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0013/

NetApp published this interim advisory covering CVE-2025-47219, CVE-2026-21947, CVE-2025-6052, CVE-2025-7425, CVE-2025-43368, CVE-2025-6021; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6965 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0011/

NetApp published this interim advisory covering CVE-2025-6965; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-68161 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0014/

NetApp published this interim advisory covering CVE-2025-68161; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights and Data Secure Storage Workload Security Agent; NetApp Manageability SDK.

Open source
Advisory

CVE-2025-66568 Ruby-Saml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0002/

NetApp published this final advisory covering CVE-2025-66568; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2025-66567 Ruby-Saml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0003/

NetApp published this final advisory covering CVE-2025-66567; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2025-62507 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0015/

NetApp published this final advisory covering CVE-2025-62507; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-40027 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0005/

NetApp published this interim advisory covering CVE-2025-40027; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-38732 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0006/

NetApp published this interim advisory covering CVE-2025-38732; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-30065 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0008/

NetApp published this final advisory covering CVE-2025-30065; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-53899 Virtualenv Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0001/

NetApp published this interim advisory covering CVE-2024-53899; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2025 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0007/

NetApp published this final advisory covering CVE-2017-15422, CVE-2017-7868, CVE-2011-4599, CVE-2014-7923, CVE-2017-7867, CVE-2016-6293, CVE-2017-15396, CVE-2020-21913, CVE-2020-10531, CVE-2016-7415, CVE-2017-17484, CVE-2017-14952; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

2026-09-01-ntap-20260123-0012

Source: https://security.netapp.com/advisory/NTAP-20260123-0012/

NetApp security advisory NTAP-20260123-0012. CVEs: CVE-2026-21932, CVE-2026-21945, CVE-2026-21925, CVE-2026-21933. Multiple NetApp products incorporate the Oracle Java Platform, Standard Edition (Java SE). Java SE versions 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, and 25.0.1 are susceptible to vulnerabilities that could allow an unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Refer to “Oracle Critical Patch Update Advisory - January 2026” for additional details.

Open source
Advisory

Intel SA-01367 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0015/

NetApp published this interim advisory covering CVE-2025-26403, CVE-2025-32086; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-39946 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0010/

NetApp published this interim advisory covering CVE-2025-39946; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-39943 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0011/

NetApp published this final advisory covering CVE-2025-39943; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-38728 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0008/

NetApp published this final advisory covering CVE-2025-38728; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-38491 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0006/

NetApp published this interim advisory covering CVE-2025-38491; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-38465 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0005/

NetApp published this interim advisory covering CVE-2025-38465; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp HCI Baseboard Management Controller (BMC) - H610S; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2025-38430 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0004/

NetApp published this interim advisory covering CVE-2025-38430; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-38181 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0009/

NetApp published this interim advisory covering CVE-2025-38181; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22889 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0014/

NetApp published this interim advisory covering CVE-2025-22889; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22840 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0013/

NetApp published this interim advisory covering CVE-2025-22840; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22839 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0012/

NetApp published this interim advisory covering CVE-2025-22839; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-36927 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0001/

NetApp published this interim advisory covering CVE-2024-36927; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36903 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0002/

NetApp published this interim advisory covering CVE-2024-36903; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
AI

2026-09-02-stocks-making-the-biggest-moves-midday-netapp-nvidia-expand-energy-intel-and-mor

Source: https://news.google.com/rss/articles/CBMimgFBVV95cUxOd0VFeGR2MW9EY1dfbXBXLUFiclMxME9OUkxXSlh3bEJVYlZnTlhzM2Zkd1EtQUdpQll4NHVvOU5icm9VaFpwNkIwWVg1ckxDMjNXMG1SSlM5LWtNX3BkYzVubncyVkFhSDAtR21EUUE5Ql9oZTBEdUtjLVEtS3A1azhHY0NVeG1lN0NxUVBWRFVvc2dCMnRUcHdR?oc=5

CNBC article from the NetApp NVIDIA Google News RSS feed. Stocks making the biggest moves midday: NetApp, Nvidia, Expand Energy, Intel and more - CNBC. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
AI

2026-09-02-netapp-s-quote-to-cash-transformation-applying-ai-across-the-revenue-lifecycle-o

Source: https://news.google.com/rss/articles/CBMiqAFBVV95cUxQTDFoUXJQOWtURE9QY3o4RjBlbkhfdjlwZkRZTEZmcTVNR1NMd3lra3RZT3hFYnI0YXp5ZnJ0em0xQnM5eG52dldWLWhjemZjRXZrSGhZd1pNeUM1a3JxSTdtUEJNc0MzVnMtYjNIdC1xRjU3NnZXR3RYM3hRU0xwRVREOHF0ZzdDWEJfbGFQdTNUMVd0MllpX29fSWNzNXJzM1dkNlNWUlY?oc=5

Oracle Blogs article from the NetApp AI Google News RSS feed. NetApp’s Quote-to-Cash Transformation: Applying AI Across the Revenue Lifecycle - Oracle Blogs. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Docs

ONTAP Tools 10.4 full deployment walkthrough for VMware vSphere

Source: NetApp Docs / Virtualization community via Google News — https://news.google.com/rss/articles/CBMipwFBVV95cUxOa2NQU1BQdWZyM3BMcEgxaFRXbDlaY1VZMl9IeUNpY2k1aFh5ZUhFc0c0bzRMa25LbWliWjFrVDFFWUVEbzk1elVfcV9hb1QzQ0xibzhaZ29pTWM5LW56ejRxZXZQZjlPLTB2aEx0TVNzSWI0MHV5a2x2Y0prbWNWSkY5LUdsZDBXUW40eUMybXhBSl9oc2pQRnpzeDc5WGRTRzdoYW9Jcw?oc=5

Full deployment walkthrough for ONT Tools 10.4 on vSphere — VSC/SRA provisioning plug-in deployment covering OVA install, registration, and certificate handling. Reference for virtualization-focused admins.

Open source
AI

ONTAP Reaches 171GiB/s with GPUDirect Storage

Source: NetApp Blog via Google News — https://news.google.com/rss/articles/CBMickFVX3lxTFBEeDhpZmtDdW04WUhxclBaaVlKaV90VHRJdVFLemM1bXZtdEd0WkZ6V3RzLWl0TnI4UURndEJhbnROb3dBbE5DNVBNeFQtS0VTMGE0NkpyTGdfS1RsazJxaVFxbWRkc1cza1NBZF84ZkpNdw?oc=5

NetApp's GPUDirect Storage support lets NVIDIA GPUs pull data directly from ONTAP storage over NVMe-oF, bypassing CPU hops. The benchmark headline: 171 GiB/s throughput feeding GPU clusters — key for large-model training and checkpoint loads on AIPod/ONTAP AI designs.

Open source
AI

Unlock powerful AIOps with NetApp Active IQ and BlueXP (NetApp)

Source: https://www.netapp.com/blog/unlock-aiops-active-iq-bluexp/

NetApp blog walkthrough of the AIOps capabilities in Active IQ + BlueXP: anomaly detection on storage performance, predictive failure analytics for disks and controllers, capacity forecasting, and AI-driven remediation suggestions. Useful documentation for ONTAP admins who want to understand what telemetry is collected, how models are trained, and what actions can be triggered automatically.

Open source
AI

NetApp AIPod Mini with Intel: affordable, simple, secure AI infrastructure (NetApp)

Source: https://www.netapp.com/blog/netapp-aipod-mini-with-intel/

NetApp blog detailing the AIPod Mini with Intel reference architecture: smaller, cheaper turnkey AI appliance built on Intel Xeon 6 + Gaudi accelerators, validated ONTAP storage and BlueXP orchestration. Targets mid-market customers and edge inferencing deployments that want the AIPod experience without the cost of NVIDIA HGX pods. Discusses supported workload profiles (RAG, vector search, inferencing).

Open source
Docs

Introducing NetApp BlueXP in 60 seconds or less (NetApp)

Source: https://www.netapp.com/blog/intro-netapp-bluexp-60-seconds/

NetApp quick-reference page for BlueXP: the unified control plane that replaces Cloud Manager and consolidates management of ONTAP clusters (on-prem, AWS FSx, Azure NetApp Files, Google Cloud NetApp Volumes), Kubernetes (Trident), BlueXP backup/restore and tiering. Useful onboarding entry point for admins new to the NetApp cloud-portfolio vocabulary.

Open source
Advisory

CVE-2025-7425 Libxslt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0014/

NetApp published this interim advisory covering CVE-2025-7425; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-66293 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0006/

NetApp published this interim advisory covering CVE-2025-66293; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-65018 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0003/

NetApp published this interim advisory covering CVE-2025-65018; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-64720 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0004/

NetApp published this interim advisory covering CVE-2025-64720; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-64505 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0007/

NetApp published this interim advisory covering CVE-2025-64505; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61919 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0011/

NetApp published this final advisory covering CVE-2025-61919; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61780 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0009/

NetApp published this final advisory covering CVE-2025-61780; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61772 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0010/

NetApp published this final advisory covering CVE-2025-61772; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61771 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0012/

NetApp published this final advisory covering CVE-2025-61771; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61770 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0008/

NetApp published this final advisory covering CVE-2025-61770; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-58767 Ruby/Rexml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0020/

NetApp published this interim advisory covering CVE-2025-58767; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5222 ICU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0002/

NetApp published this interim advisory covering CVE-2025-5222; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2025-27558 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0017/

NetApp published this interim advisory covering CVE-2025-27558; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-36913 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0018/

NetApp published this interim advisory covering CVE-2024-36913; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2024-36357 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0016/

NetApp published this interim advisory covering CVE-2024-36357; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2024-36350 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0015/

NetApp published this interim advisory covering CVE-2024-36350; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2024-25062 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0019/

NetApp published this interim advisory covering CVE-2024-25062; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP 9.

Open source
Advisory

CVE-2023-40403 Libxslt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0013/

NetApp published this interim advisory covering CVE-2023-40403, CVE-2022-4909; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
AI

AI on the edge: how to leverage edge inferencing with AIPod Mini (NetApp)

Source: https://www.netapp.com/blog/ai-on-the-edge-aipod-mini/

NetApp engineering blog on edge inferencing with AIPod Mini: how to deploy a self-contained AI appliance at the edge that synchronizes training/inference corpora back to a central ONTAP cluster via SnapMirror. Covers network-bandwidth optimization, local vector store sizing, and the operational playbook for running models at retail/industrial sites with intermittent connectivity.

Open source
Advisory

2026-09-01-ntap-20260116-0005

Source: https://security.netapp.com/advisory/NTAP-20260116-0005/

NetApp security advisory NTAP-20260116-0005. CVEs: CVE-2025-64506. Multiple NetApp products incorporate libpng. Libpng versions 1.6.0 prior to 1.6.51 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS).

Open source
AI

NetApp launches AI Data Engine to manage enterprise data (Investing.com)

Source: https://www.investing.com/news/netapp-ai-data-engine-launch/

Investing.com coverage of the AI Data Engine launch: positioning, target customers, pricing model, and analyst commentary. Less technical than the engineering press but useful as a record of how the Street is framing the product versus DataPelago, NVIDIA NeMo, and Palantir AIP-style data-platform adjacencies. Includes a quick comparison of where AI Data Engine sits in the broader NetApp product line (ONTAP, AIPod, BlueXP).

Open source
AI

NVIDIA's New KV Cache Makes Waves in Enterprise Storage

Source: TechTarget (via Google News)

TechTarget covers how NVIDIA's approach to spilling LLM KV cache context out to enterprise storage is reshaping storage requirements: inference platforms need low-latency flash tiers for cached context, which plays directly to NetApp's strengths (AFF/ASA, AFX, and the NVIDIA AI Data Platform integration). A foundational read for understanding why inference is becoming a storage workload.

Open source
Advisory

CVE-2025-9900 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0012/

NetApp published this final advisory covering CVE-2025-9900; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-9566 Podman Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0007/

NetApp published this final advisory covering CVE-2025-9566; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8961 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0014/

NetApp published this interim advisory covering CVE-2025-8961; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8534 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0015/

NetApp published this interim advisory covering CVE-2025-8534; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8114 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0010/

NetApp published this interim advisory covering CVE-2025-8114; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68615 Net-SNMP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0002/

NetApp published this interim advisory covering CVE-2025-68615; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5987 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0009/

NetApp published this interim advisory covering CVE-2025-5987; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-59419 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0001/

NetApp published this interim advisory covering CVE-2025-59419; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

CVE-2025-54350 Iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0006/

NetApp published this final advisory covering CVE-2025-54350; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4878 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0008/

NetApp published this interim advisory covering CVE-2025-4878; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4877 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0011/

NetApp published this interim advisory covering CVE-2025-4877; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20109 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0003/

NetApp published this interim advisory covering CVE-2025-20109; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-52355 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0013/

NetApp published this final advisory covering CVE-2023-52355; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-41419 Gevent Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0005/

NetApp published this final advisory covering CVE-2023-41419; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
AI

Nvidia pushes AI inference context out to NVMe SSDs

Source: https://www.blocksandfiles.com/ai-ml/2026/01/06/nvidia-pushes-ai-inference-context-out-to-nvme-ssds/4090444

Blocks & Files reports NVIDIA's push to extend inference KV-cache and context memory to NVMe storage. NetApp is described as an expected partner, not as a validated EF-Series reference platform.

Open source
Advisory

CVE-2025-7424 Libxslt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0012/

NetApp published this interim advisory covering CVE-2025-7424; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6965 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0013/

NetApp published this interim advisory covering CVE-2025-6965; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-53816 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0015/

NetApp published this final advisory covering CVE-2025-53816; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2025-5318 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0001/

NetApp published this interim advisory covering CVE-2025-5318; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5278 GNU Coreutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0011/

NetApp published this interim advisory covering CVE-2025-5278; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-50182 Urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0004/

NetApp published this interim advisory covering CVE-2025-50182; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Data Classification.

Open source
Advisory

CVE-2025-50181 Urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0005/

NetApp published this interim advisory covering CVE-2025-50181; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp Data Classification.

Open source
Advisory

CVE-2025-38092 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0008/

NetApp published this final advisory covering CVE-2025-38092; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-38089 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0009/

NetApp published this interim advisory covering CVE-2025-38089; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27391 Apache ActiveMQ Artemis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0010/

NetApp published this interim advisory covering CVE-2025-27391; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-14847 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0016/

NetApp published this interim advisory covering CVE-2025-14847; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-1220 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0014/

NetApp published this final advisory covering CVE-2025-1220; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1125 Grub Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0002/

NetApp published this interim advisory covering CVE-2025-1125; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-0689 Grub Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0003/

NetApp published this interim advisory covering CVE-2025-0689; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-45217 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0007/

NetApp published this final advisory covering CVE-2024-45217; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-27281 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0006/

NetApp published this interim advisory covering CVE-2024-27281; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-66471 Urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0009/

NetApp published this interim advisory covering CVE-2025-66471; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Data Classification; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-66418 Urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0008/

NetApp published this interim advisory covering CVE-2025-66418; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Data Classification; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-66412 Angular Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0006/

NetApp published this interim advisory covering CVE-2025-66412; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-66035 Angular Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0007/

NetApp published this interim advisory covering CVE-2025-66035; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-62408 C-ares Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0014/

NetApp published this interim advisory covering CVE-2025-62408; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-40281 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0011/

NetApp published this interim advisory covering CVE-2025-40281; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-39828 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0013/

NetApp published this interim advisory covering CVE-2025-39828; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-39823 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0012/

NetApp published this interim advisory covering CVE-2025-39823; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-38734 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0010/

NetApp published this interim advisory covering CVE-2025-38734; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-23366 Wildfly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0004/

NetApp published this final advisory covering CVE-2025-23366; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-2251 Wildfly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0003/

NetApp published this interim advisory covering CVE-2025-2251; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2025-13601 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0001/

NetApp published this interim advisory covering CVE-2025-13601; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2025-10966 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0002/

NetApp published this interim advisory covering CVE-2025-10966; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-0620 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0005/

NetApp published this interim advisory covering CVE-2025-0620; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2023-2283 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0015/

NetApp published this interim advisory covering CVE-2023-2283; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-67779 React Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0014/

NetApp published this interim advisory covering CVE-2025-67779; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Data Classification; NetApp Shift Toolkit.

Open source
Advisory

CVE-2025-66675 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0013/

NetApp published this final advisory covering CVE-2025-66675; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-58181 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0003/

NetApp published this interim advisory covering CVE-2025-58181; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Data Infrastructure Insights Telegraf Agent.

Open source
Advisory

CVE-2025-55184 React Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0015/

NetApp published this interim advisory covering CVE-2025-55184; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Data Classification; NetApp Shift Toolkit.

Open source
Advisory

CVE-2025-47912 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0004/

NetApp published this interim advisory covering CVE-2025-47912; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Trident; Trident Autosupport.

Open source
Advisory

CVE-2025-22874 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0001/

NetApp published this interim advisory covering CVE-2025-22874; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent.

Open source
Advisory

CVE-2025-14769 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0006/

NetApp published this final advisory covering CVE-2025-14769; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-14558 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0005/

NetApp published this final advisory covering CVE-2025-14558; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-13837 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0008/

NetApp published this interim advisory covering CVE-2025-13837; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2025-13836 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0007/

NetApp published this interim advisory covering CVE-2025-13836; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2025-8851 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0007/

NetApp published this interim advisory covering CVE-2025-8851; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8225 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0011/

NetApp published this interim advisory covering CVE-2025-8225; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8224 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0010/

NetApp published this interim advisory covering CVE-2025-8224; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-66200 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0003/

NetApp published this interim advisory covering CVE-2025-66200; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-65082 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0001/

NetApp published this final advisory covering CVE-2025-65082; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-59775 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0005/

NetApp published this final advisory covering CVE-2025-59775; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-58098 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0004/

NetApp published this final advisory covering CVE-2025-58098; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-55753 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0002/

NetApp published this final advisory covering CVE-2025-55753; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-11839 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0015/

NetApp published this interim advisory covering CVE-2025-11839; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-11083 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0012/

NetApp published this interim advisory covering CVE-2025-11083; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-11082 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0014/

NetApp published this interim advisory covering CVE-2025-11082; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-11081 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0013/

NetApp published this interim advisory covering CVE-2025-11081; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-13978 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0008/

NetApp published this interim advisory covering CVE-2024-13978; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6228 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0009/

NetApp published this interim advisory covering CVE-2023-6228; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-50164 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0006/

NetApp published this interim advisory covering CVE-2025-64775; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-9390 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0008/

NetApp published this interim advisory covering CVE-2025-9390; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-55182 React Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0001/

NetApp published this interim advisory covering CVE-2025-55182; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Data Classification; NetApp Shift Toolkit.

Open source
Advisory

CVE-2025-53906 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0006/

NetApp published this interim advisory covering CVE-2025-53906; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-53905 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0007/

NetApp published this interim advisory covering CVE-2025-53905; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48041 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0014/

NetApp published this final advisory covering CVE-2025-48041; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48040 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0013/

NetApp published this interim advisory covering CVE-2025-48040; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48038 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0012/

NetApp published this interim advisory covering CVE-2025-48038; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-47279 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0010/

NetApp published this final advisory covering CVE-2025-47279; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-46712 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0011/

NetApp published this interim advisory covering CVE-2025-46712; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-39839 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0015/

NetApp published this interim advisory covering CVE-2025-39839; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1390 Libcap Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0002/

NetApp published this interim advisory covering CVE-2025-1390; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-10911 Libxslt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0003/

NetApp published this interim advisory covering CVE-2025-10911; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46809 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0009/

NetApp published this final advisory covering CVE-2023-46809; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
News

2026-09-02-netapp-collaborates-with-aws-to-bring-enterprise-data-to-aws-ai-services-01net

Source: https://news.google.com/rss/articles/CBMimgFBVV95cUxQZFQzNjVGaF91SHAxV1NEUnktMnBRWWpVSkRxdmV5alJfS056S0xvWnIyVGtaUWgwdC1UdC1HNHlaOEhXVEZ3dzh5dkJMaDYwT2RMYl9RSDVjRzRsbkxYa2lZUENVR0ZYSG1aTlEzZ2R0WEVOZlpsRnlYYlhnZkRoZXRHU0I1d1Y0NTh6bUpJbGp6TURFOUlRa21R?oc=5

01net article from the NetApp ONTAP Google News RSS feed. NetApp Collaborates with AWS to bring Enterprise Data to AWS AI Services - 01net. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
Advisory

CVE-2025-60753 Libarchive Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0013/

NetApp published this final advisory covering CVE-2025-60753; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6075 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0014/

NetApp published this interim advisory covering CVE-2025-6075; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5372 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0005/

NetApp published this final advisory covering CVE-2025-5372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-41115 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0004/

NetApp published this final advisory covering CVE-2025-41115; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-37997 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0011/

NetApp published this interim advisory covering CVE-2025-37997; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-37973 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0010/

NetApp published this interim advisory covering CVE-2025-37973; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-37894 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0009/

NetApp published this interim advisory covering CVE-2025-37894; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-37820 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0008/

NetApp published this interim advisory covering CVE-2025-37820; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-23367 Wildfly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0012/

NetApp published this final advisory covering CVE-2025-23367; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-2336 AngularJS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0015/

NetApp published this interim advisory covering CVE-2025-2336; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-12818 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0007/

NetApp published this interim advisory covering CVE-2025-12818; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-12817 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0006/

NetApp published this interim advisory covering CVE-2025-12817; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-52881 Runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0003/

NetApp published this interim advisory covering CVE-2025-52881; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-36186 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0010/

NetApp published this final advisory covering CVE-2025-36186; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36185 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0006/

NetApp published this final advisory covering CVE-2025-36185; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36131 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0008/

NetApp published this final advisory covering CVE-2025-36131; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36006 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0011/

NetApp published this final advisory covering CVE-2025-36006; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-33012 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0009/

NetApp published this final advisory covering CVE-2025-33012; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-31133 Runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0001/

NetApp published this interim advisory covering CVE-2025-31133; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-27209 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0013/

NetApp published this final advisory covering CVE-2025-27209; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-23165 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0012/

NetApp published this final advisory covering CVE-2025-23165; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-4068 Micromatch Braces Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0014/

NetApp published this final advisory covering CVE-2024-4068; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-3566 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0015/

NetApp published this final advisory covering CVE-2024-3566; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5981 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0004/

NetApp published this interim advisory covering CVE-2023-5981; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

2026-09-01-ntap-20251121-0002

Source: https://security.netapp.com/advisory/NTAP-20251121-0002/

NetApp security advisory NTAP-20251121-0002. CVEs: CVE-2025-52565. Multiple NetApp products incorporate runc. Runc versions prior to 1.2.8, prior to 1.3.3, and prior to 1.4.0-rc.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2025-37944 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0010/

NetApp published this final advisory covering CVE-2025-37944; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-31498 C-ares Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0006/

NetApp published this final advisory covering CVE-2025-31498; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-27152 Axios Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0004/

NetApp published this final advisory covering CVE-2025-27152; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Shift Toolkit.

Open source
Advisory

CVE-2025-26646 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0001/

NetApp published this final advisory covering CVE-2025-26646; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-26597 X.Org Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0002/

NetApp published this final advisory covering CVE-2025-26597; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45782 Grub Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0008/

NetApp published this final advisory covering CVE-2024-45782; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-52522 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0011/

NetApp published this interim advisory covering CVE-2023-52522; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A320; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-34241 CUPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0007/

NetApp published this final advisory covering CVE-2023-34241; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-25434 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0009/

NetApp published this final advisory covering CVE-2023-25434; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61795 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0014/

NetApp published this interim advisory covering CVE-2025-61795; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-55752 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0013/

NetApp published this final advisory covering CVE-2025-55752; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-54410 Docker Moby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0009/

NetApp published this interim advisory covering CVE-2025-54410; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-52099 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0015/

NetApp published this final advisory covering CVE-2025-52099; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48976 Apache Commons FileUpload Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0004/

NetApp published this final advisory covering CVE-2025-48976; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Snap Creator Framework.

Open source
Advisory

CVE-2025-41254 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0010/

NetApp published this interim advisory covering CVE-2025-41254; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Snap Creator Framework.

Open source
Advisory

CVE-2025-26596 Xorg-server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0007/

NetApp published this final advisory covering CVE-2025-26596; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-26595 Xorg-server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0006/

NetApp published this final advisory covering CVE-2025-26595; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24934 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0012/

NetApp published this final advisory covering CVE-2025-24934; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-23167 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0005/

NetApp published this final advisory covering CVE-2025-23167; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-11731 Libxslt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0011/

NetApp published this interim advisory covering CVE-2025-11731; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-21490 AngularJS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0001/

NetApp published this interim advisory covering CVE-2024-21490; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

October 2025 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0013/

NetApp published this interim advisory covering CVE-2025-53042, CVE-2025-53062, CVE-2025-53053, CVE-2025-53040, CVE-2025-53054, CVE-2025-53045, CVE-2025-53044, CVE-2025-53069; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

October 2025 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0006/

NetApp published this interim advisory covering CVE-2025-53057, CVE-2025-53066; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); E-Series SANtricity Unified Manager and Web Services Proxy; OnCommand Insight; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2025-9086 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0007/

NetApp published this interim advisory covering CVE-2025-9086; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-8677 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0003/

NetApp published this interim advisory covering CVE-2025-8677; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-8277 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0010/

NetApp published this interim advisory covering CVE-2025-8277; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-7545 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0005/

NetApp published this interim advisory covering CVE-2025-7545; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-55754 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0011/

NetApp published this interim advisory covering CVE-2025-55754; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-40780 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0002/

NetApp published this interim advisory covering CVE-2025-40780; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-40778 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0001/

NetApp published this interim advisory covering CVE-2025-40778; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-1182 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0004/

NetApp published this interim advisory covering CVE-2025-1182; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-10148 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0008/

NetApp published this interim advisory covering CVE-2025-10148; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2023-5156 Glibc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0009/

NetApp published this interim advisory covering CVE-2023-5156; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2025-9640 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0002/

NetApp published this final advisory covering CVE-2025-9640; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-47906 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0005/

NetApp published this interim advisory covering CVE-2025-47906; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; NetApp Console Agent; NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2025-31257 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0009/

NetApp published this interim advisory covering CVE-2025-31257; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27819 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0008/

NetApp published this final advisory covering CVE-2025-27819; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27818 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0007/

NetApp published this final advisory covering CVE-2025-27818; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27817 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0006/

NetApp published this final advisory covering CVE-2025-27817; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-10230 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0001/

NetApp published this final advisory covering CVE-2025-10230; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-51744 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0003/

NetApp published this interim advisory covering CVE-2024-51744; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2025 OpenSSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0010/

NetApp published this interim advisory covering CVE-2025-61984, CVE-2025-61985; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400.

Open source
Advisory

July 2025 LuaJIT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0013/

NetApp published this interim advisory covering CVE-2024-25176, CVE-2024-25177, CVE-2024-25178; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6170 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0002/

NetApp published this interim advisory covering CVE-2025-6170; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Manageability SDK; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-49795 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0001/

NetApp published this interim advisory covering CVE-2025-49795; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-47273 Pypi/Setuptools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0007/

NetApp published this interim advisory covering CVE-2025-47273; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-6345 Pypi/Setuptools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0006/

NetApp published this interim advisory covering CVE-2024-6345; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-29217 PyJWT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0005/

NetApp published this interim advisory covering CVE-2022-29217; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-24801 Twisted Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0009/

NetApp published this final advisory covering CVE-2022-24801; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-21716 Twisted Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0008/

NetApp published this final advisory covering CVE-2022-21716; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-42771 Babel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0003/

NetApp published this final advisory covering CVE-2021-42771; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-24372 LuaJIT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0012/

NetApp published this interim advisory covering CVE-2020-24372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-15890 LuaJIT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0011/

NetApp published this interim advisory covering CVE-2020-15890; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-19391 LuaJIT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0014/

NetApp published this interim advisory covering CVE-2019-19391; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
News

2026-09-02-recap-of-netapp-insight-2025-storagenewsletter

Source: https://news.google.com/rss/articles/CBMif0FVX3lxTE1DYkJkX0QyTEI1UjlYUEVFZzNjMGYwbWlSSks2Q1U1Y0w3YzVHaFg4dWpkSTBURGpQczk0cHY3NmIzbmF5a054UHIzcjNhN0puY3NvVmdRWldIRGlEMnE2b05UWENKVEozX011Zi1RTmRNUGwzbW1mbkgtQ1gxN1E?oc=5

StorageNewsletter article from the NetApp ONTAP Google News RSS feed. Recap of NetApp Insight 2025 - StorageNewsletter. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
News

2026-09-02-informatica-netapp-the-un-structured-partnership-informatica

Source: https://news.google.com/rss/articles/CBMilAFBVV95cUxNdFkwSEdwdW9yMjZRVHhaM3hiQnZtMFhmckRvQ2Y0VENUSWVnN0NrOTlweW9Yd1lJQ0VVZlh1eE1JRHE3QzNEQU9LU2NlbDJfcmRVM2hUeVpZRkVjSVZqdXFvWVhBNk9aTGRFSjJYT1Q4SnpBV1B1RjRQRkdoV0JTd204SFhhclF5RnZSYjRIMHJ1eWtu?oc=5

Informatica article from the NetApp ONTAP Google News RSS feed. Informatica & NetApp: The (un)structured partnership - Informatica. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `news` for the NetApp Black Box library.

Open source
Advisory

CVE-2025-7709 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0011/

NetApp published this interim advisory covering CVE-2025-7709; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-7039 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0009/

NetApp published this interim advisory covering CVE-2025-7039; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2025-6197 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0003/

NetApp published this final advisory covering CVE-2025-6197; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6023 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0002/

NetApp published this final advisory covering CVE-2025-6023; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-49844 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0012/

NetApp published this interim advisory covering CVE-2025-49844; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4056 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0010/

NetApp published this final advisory covering CVE-2025-4056; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-3580 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0006/

NetApp published this final advisory covering CVE-2025-3580; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-3454 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0005/

NetApp published this final advisory covering CVE-2025-3454; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6322 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0004/

NetApp published this final advisory covering CVE-2024-6322; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-35200 Nginx Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0008/

NetApp published this interim advisory covering CVE-2024-35200; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-34161 Nginx Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0007/

NetApp published this interim advisory covering CVE-2024-34161; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-11612 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0001/

NetApp published this interim advisory covering CVE-2024-11612; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-9784 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0007/

NetApp published this interim advisory covering CVE-2025-9784; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; OnCommand Insight.

Open source
Advisory

CVE-2025-9232 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0013/

NetApp published this interim advisory covering CVE-2025-9232; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-9231 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0012/

NetApp published this interim advisory covering CVE-2025-9231; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-9230 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0011/

NetApp published this interim advisory covering CVE-2025-9230; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Antivirus Connector; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-8671 HTTP/2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0004/

NetApp published this final advisory covering CVE-2025-8671; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Snap Creator Framework.

Open source
Advisory

CVE-2025-55668 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0003/

NetApp published this final advisory covering CVE-2025-55668; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-55163 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0005/

NetApp published this final advisory covering CVE-2025-55163; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5115 Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0006/

NetApp published this interim advisory covering CVE-2025-5115; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Snap Creator Framework.

Open source
Advisory

CVE-2025-32462 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0001/

NetApp published this interim advisory covering CVE-2025-32462; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27427 Apache ActiveMQ Artemis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0009/

NetApp published this interim advisory covering CVE-2025-27427; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-6931 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0002/

NetApp published this interim advisory covering CVE-2023-6931; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820.

Open source
Advisory

CVE-2023-50780 Apache ActiveMQ Artemis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0010/

NetApp published this interim advisory covering CVE-2023-50780; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-39810 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0008/

NetApp published this interim advisory covering CVE-2023-39810; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-01139 UEFI Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0004/

NetApp published this interim advisory covering CVE-2024-39279, CVE-2024-31157; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - 2820; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2025-22853 Intel TDX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0006/

NetApp published this interim advisory covering CVE-2025-22853; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-21096 Intel TDX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0005/

NetApp published this interim advisory covering CVE-2025-21096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20613 Intel TDX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0007/

NetApp published this interim advisory covering CVE-2025-20613; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-57360 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0001/

NetApp published this interim advisory covering CVE-2024-57360; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-31155 Intel UEFI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0003/

NetApp published this interim advisory covering CVE-2024-31155; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22185 Intel ACTM Module Software Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0010/

NetApp published this interim advisory covering CVE-2024-22185; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4373 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0009/

NetApp published this interim advisory covering CVE-2025-4373; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820.

Open source
Advisory

CVE-2025-36071 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0007/

NetApp published this final advisory covering CVE-2025-36071; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36010 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0004/

NetApp published this final advisory covering CVE-2025-36010; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-3360 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0010/

NetApp published this interim advisory covering CVE-2025-3360; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2025-33143 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0008/

NetApp published this final advisory covering CVE-2025-33143; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-33114 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0006/

NetApp published this final advisory covering CVE-2025-33114; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-33092 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0005/

NetApp published this final advisory covering CVE-2025-33092; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-36293 Intel SGX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0012/

NetApp published this interim advisory covering CVE-2024-36293; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-31068 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0015/

NetApp published this interim advisory covering CVE-2024-31068; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-28047 Intel UEFI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0011/

NetApp published this interim advisory covering CVE-2024-28047; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24985 Intel ACTM Module Software Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0013/

NetApp published this interim advisory covering CVE-2024-24985; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21859 Intel UEFI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0014/

NetApp published this interim advisory covering CVE-2024-21859; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6481 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0001/

NetApp published this interim advisory covering CVE-2023-6481; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-45322 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0003/

NetApp published this interim advisory covering CVE-2023-45322; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP 9.

Open source
Advisory

CVE-2021-36368 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0002/

NetApp published this interim advisory covering CVE-2021-36368; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
AI

2026-09-04-vector-database-solution-netapp

Source: https://docs.netapp.com/us-en/netapp-solutions-ai/vector-db/ai-vdb-solution-with-netapp.html

Authors Karthikeyan Nagalingam and Rodrigo Nascimento (NetApp), dated 2025-09-15. Validated design for deploying vector databases on NetApp storage, covering two open-source engines: Milvus (the leading standalone vector DB) and pgvector (the PostgreSQL extension for vector search). The doc covers infrastructure guidelines for ONTAP and StorageGRID as the backing object/file store and benchmarks Milvus running on AWS FSx for NetApp ONTAP, demonstrating NetApp's "file-object duality" — same data visible as NFS/SMB files AND as S3 objects via ONTAP S3. Why it matters: vector DBs are the data layer of every modern RAG/recommendation/semotion system; the doc positions FSx ONTAP as the enterprise answer to "where do my embeddings live" for AWS shops and ONTAP/StorageGRID for on-prem. It also serves as a reference for sizing Milvus index files (typically large, append-heavy, seek-light — exactly the workload ONTAP is tuned for).

Open source
AI

2026-09-04-aipod-nvidia-dgx-intro

Source: https://docs.netapp.com/us-en/netapp-solutions-ai/infra/ai-aipod-nv-intro.html

Reference architecture NVA-1173 (dated 2025-09-15) for NetApp AIPod with NVIDIA DGX systems. Built on the NVIDIA DGX BasePOD design, AIPod layers NetApp AFF storage systems on top so customers can "start small and grow non-disruptively" while managing data from edge → core → cloud. Covers: key components of the AIPod reference architecture, system connectivity and configuration, validation testing results, and solution sizing guidance. The doc frames AIPod as part of NetApp's larger AI portfolio — alongside NVIDIA DGX SuperPOD with EF-Series, AIPod with Lenovo for NVIDIA OVX, BeeGFS/Lustre parallel file systems on E-Series, AIPod Mini for RAG, and vector database solutions. Why it matters: AIPod is the flagship NetApp+NVIDIA validated AI stack; the introduction doc is the entry point for solution engineers and customer architects planning ML/DL/analytics workloads on DGX compute. The "start small, grow non-disruptively" pitch differentiates NetApp from bolt-on DGX storage.

Open source
AI

NetApp's Enterprise AI Bet: Can DataPelago Buyout Accelerate Growth? (TradingView)

Source: https://www.tradingview.com/symbols/NTAP/community/netapp-datapelago-ai-bet/

TradingView community write-up on NetApp's DataPelago acquisition as part of its broader Enterprise AI bet. Walks through the financial logic, the competitive set (Pure Storage, VAST, Dell PowerScale), and what an investor should expect on the next two earnings calls. Less technical than the engineering press but a useful record of how the Street is reading the AI strategy.

Open source
Advisory

CVE-2025-8916 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0011/

NetApp published this interim advisory covering CVE-2025-8916; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2025-54351 Iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0004/

NetApp published this final advisory covering CVE-2025-54351; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-54349 Iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0003/

NetApp published this final advisory covering CVE-2025-54349; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48913 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0001/

NetApp published this interim advisory covering CVE-2025-48913; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Snap Creator Framework.

Open source
Advisory

CVE-2025-41242 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0002/

NetApp published this interim advisory covering CVE-2025-41242; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Snap Creator Framework.

Open source
Advisory

CVE-2025-24305 Intel Xeon Processors Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0010/

NetApp published this interim advisory covering CVE-2025-24305; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22392 Intel AMT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0005/

NetApp published this interim advisory covering CVE-2025-22392; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-21090 Intel Xeon Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0009/

NetApp published this interim advisory covering CVE-2025-21090; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20067 Intel CSME Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0007/

NetApp published this interim advisory covering CVE-2025-20067; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20053 Intel Xeon Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0008/

NetApp published this interim advisory covering CVE-2025-20053; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20037 Intel CSME Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0006/

NetApp published this interim advisory covering CVE-2025-20037; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20250912-0012

Source: https://security.netapp.com/advisory/NTAP-20250912-0012/

NetApp security advisory NTAP-20250912-0012. CVEs: CVE-2025-8885. Multiple NetApp products incorporate Bouncy Castle. Certain versions of Bouncy Castle are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
AI

NetApp Acquires DataPelago, Making Data AI-Ready at the Infrastructure Layer (Yahoo Finance)

Source: https://finance.yahoo.com/news/netapp-acquires-datapelago-ai-infrastructure-layer/

Yahoo Finance coverage of NetApp's acquisition of DataPelago, framed as a move to make data AI-ready at the storage/infrastructure layer rather than at the application layer. Outlines the DataPelago technology (accelerated unstructured-data processing, GPUDirect-class pipelines) and how it slots into the AI Data Engine roadmap. Useful background for any future 'what is AI Data Engine' explainer page.

Open source
Advisory

CVE-2025-5244 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0005/

NetApp published this interim advisory covering CVE-2025-5244; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4674 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0010/

NetApp published this final advisory covering CVE-2025-4674; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2025-3198 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0004/

NetApp published this interim advisory covering CVE-2025-3198; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-30258 GnuPG Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0002/

NetApp published this interim advisory covering CVE-2025-30258; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-23419 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0007/

NetApp published this interim advisory covering CVE-2025-23419; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-52979 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0003/

NetApp published this interim advisory covering CVE-2024-52979; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2240 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20250904-0001/

NetApp published this final advisory covering CVE-2024-2240; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2024-12718 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0008/

NetApp published this interim advisory covering CVE-2024-12718; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-54090 Apache Http Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0014/

NetApp published this interim advisory covering CVE-2025-54090; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-53817 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0002/

NetApp published this final advisory covering CVE-2025-53817; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2025-47907 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0001/

NetApp published this interim advisory covering CVE-2025-47907; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent.

Open source
Advisory

CVE-2025-2533 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0010/

NetApp published this final advisory covering CVE-2025-2533; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-52894 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0011/

NetApp published this final advisory covering CVE-2024-52894; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-51473 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0012/

NetApp published this final advisory covering CVE-2024-51473; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-49828 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0013/

NetApp published this final advisory covering CVE-2024-49828; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3749 Axios Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0009/

NetApp published this interim advisory covering CVE-2021-3749; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Shift Toolkit.

Open source
Advisory

CVE-2025-4673 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0009/

NetApp published this interim advisory covering CVE-2025-4673; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent; Trident; Trident Autosupport; Trident Protect.

Open source
Advisory

CVE-2025-32442 Fastify Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0001/

NetApp published this final advisory covering CVE-2025-32442; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-2703 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0004/

NetApp published this final advisory covering CVE-2025-2703; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22868 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0008/

NetApp published this interim advisory covering CVE-2025-22868; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; NetApp Console Agent; NetApp Kubernetes Monitoring Operator; Trident.

Open source
Advisory

CVE-2023-42365 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0006/

NetApp published this interim advisory covering CVE-2023-42365; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2023-42364 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0005/

NetApp published this interim advisory covering CVE-2023-42364; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-8194 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0001/

NetApp published this interim advisory covering CVE-2025-8194; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-1735 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0009/

NetApp published this final advisory covering CVE-2025-1735; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1180 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0008/

NetApp published this interim advisory covering CVE-2025-1180; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-7347 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0003/

NetApp published this interim advisory covering CVE-2024-7347; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-47220 Webrick Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0010/

NetApp published this final advisory covering CVE-2024-47220; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-32760 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0004/

NetApp published this interim advisory covering CVE-2024-32760; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-2496 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0005/

NetApp published this interim advisory covering CVE-2024-2496; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6597 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0002/

NetApp published this final advisory covering CVE-2023-6597; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-52356 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0006/

NetApp published this final advisory covering CVE-2023-52356; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2025 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0007/

NetApp published this interim advisory covering CVE-2025-1151, CVE-2025-1149, CVE-2025-1150, CVE-2025-1152; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-8058 Glibc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0002/

NetApp published this interim advisory covering CVE-2025-8058; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-6297 Dpkg Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0008/

NetApp published this interim advisory covering CVE-2025-6297; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-50200 Rabbitmq-Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0001/

NetApp published this interim advisory covering CVE-2025-50200; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-50063 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0006/

NetApp published this interim advisory covering CVE-2025-50063; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4748 Erlang-OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0005/

NetApp published this interim advisory covering CVE-2025-4748; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-46701 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0004/

NetApp published this interim advisory covering CVE-2025-46701; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27144 Go-Jose Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0009/

NetApp published this final advisory covering CVE-2025-27144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-8118 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0011/

NetApp published this final advisory covering CVE-2024-8118; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-28180 Go-Jose Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0010/

NetApp published this interim advisory covering CVE-2024-28180; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-47108 OpenTelemetry-Go Contrib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0003/

NetApp published this final advisory covering CVE-2023-47108; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3978 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0012/

NetApp published this interim advisory covering CVE-2023-3978; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center.

Open source
Advisory

CVE-2025-7783 Form-Data Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0002/

NetApp published this interim advisory covering CVE-2025-7783; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Astra Control Center; NetApp Shift Toolkit.

Open source
Advisory

CVE-2025-6491 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0008/

NetApp published this final advisory covering CVE-2025-6491; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5372 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0005/

NetApp published this interim advisory covering CVE-2025-5372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5351 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0006/

NetApp published this interim advisory covering CVE-2025-5351; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27210 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0001/

NetApp published this final advisory covering CVE-2025-27210; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-35962 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0007/

NetApp published this final advisory covering CVE-2024-35962; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-12905 tar-fs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0003/

NetApp published this final advisory covering CVE-2024-12905; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Shift Toolkit.

Open source
Advisory

CVE-2023-39615 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0009/

NetApp published this interim advisory covering CVE-2023-39615; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-38655 Intel AMT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0004/

NetApp published this interim advisory covering CVE-2023-38655; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6395 GNUTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0007/

NetApp published this interim advisory covering CVE-2025-6395; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-53506 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0003/

NetApp published this interim advisory covering CVE-2025-53506; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48734 Apache Commons Beanutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0004/

NetApp published this interim advisory covering CVE-2025-48734; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-40777 ISC Bind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0002/

NetApp published this interim advisory covering CVE-2025-40777; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-40776 ISC Bind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0001/

NetApp published this final advisory covering CVE-2025-40776; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-32990 GNUTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0006/

NetApp published this interim advisory covering CVE-2025-32990; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-32989 GNUTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0008/

NetApp published this interim advisory covering CVE-2025-32989; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-32988 GNUTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0009/

NetApp published this interim advisory covering CVE-2025-32988; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-25809 Runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0010/

NetApp published this interim advisory covering CVE-2023-25809; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center.

Open source
Advisory

CVE-2019-10086 Apache Commons Beanutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0005/

NetApp published this interim advisory covering CVE-2019-10086; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; OnCommand Insight; SnapCenter; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

July 2025 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250724-0008/

NetApp published this interim advisory covering CVE-2025-50102, CVE-2025-50093, CVE-2025-50085, CVE-2025-50083, CVE-2025-50084, CVE-2025-50096, CVE-2025-50080, CVE-2025-50097, CVE-2025-50101, CVE-2025-50099, CVE-2025-50082, CVE-2025-50077, CVE-2025-50092, CVE-2025-5399, CVE-2025-50100, CVE-2025-50078, CVE-2025-50104, CVE-2025-50091, CVE-2025-50098, CVE-2025-50087, CVE-2025-50079, CVE-2025-50086; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

CVE-2025-53023 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250724-0001/

NetApp published this interim advisory covering CVE-2025-53023; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

CVE-2025-50088 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250724-0003/

NetApp published this interim advisory covering CVE-2025-50088; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

CVE-2025-50081 MySQL Client Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250724-0005/

NetApp published this interim advisory covering CVE-2025-50081; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

CVE-2025-30752 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250724-0011/

NetApp published this interim advisory covering CVE-2025-30752; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2025 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0013/

NetApp published this final advisory covering CVE-2025-53020, CVE-2025-49812, CVE-2025-49630, CVE-2025-23048, CVE-2024-47252, CVE-2024-43394, CVE-2024-43204, CVE-2024-42516; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9.

Open source
Advisory

Intel SA-00756 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0012/

NetApp published this interim advisory covering CVE-2021-33141, CVE-2021-33162, CVE-2021-33157, CVE-2021-33161, CVE-2022-37341, CVE-2021-33145, CVE-2021-33158, CVE-2021-33142, CVE-2021-33146; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6069 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0005/

NetApp published this interim advisory covering CVE-2025-6069; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-52520 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0015/

NetApp published this interim advisory covering CVE-2025-52520; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5245 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0010/

NetApp published this interim advisory covering CVE-2025-5245; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-52434 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0014/

NetApp published this final advisory covering CVE-2025-52434; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-49796 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0004/

NetApp published this interim advisory covering CVE-2025-49796; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-49794 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0003/

NetApp published this interim advisory covering CVE-2025-49794; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-4598 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0001/

NetApp published this interim advisory covering CVE-2025-4598; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4517 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0009/

NetApp published this interim advisory covering CVE-2025-4517; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-4435 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0008/

NetApp published this interim advisory covering CVE-2025-4435; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-4330 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0007/

NetApp published this interim advisory covering CVE-2025-4330; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-4138 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0006/

NetApp published this interim advisory covering CVE-2025-4138; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-40909 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0002/

NetApp published this interim advisory covering CVE-2025-40909; the API labels exploitation information as **Public**. The API currently lists affected products as: Snap Creator Framework.

Open source
Advisory

CVE-2025-6021 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0009/

NetApp published this interim advisory covering CVE-2025-6021; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-5399 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0010/

NetApp published this final advisory covering CVE-2025-5399; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4516 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0004/

NetApp published this final advisory covering CVE-2025-4516; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2025-30065 Apache Parquet Avro Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0001/

NetApp published this final advisory covering CVE-2025-30065; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-56128 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0005/

NetApp published this final advisory covering CVE-2024-56128; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3750 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0006/

NetApp published this interim advisory covering CVE-2023-3750; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22799 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0007/

NetApp published this final advisory covering CVE-2023-22799; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-46392 Apache Commons Configuration Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0009/

NetApp published this interim advisory covering CVE-2025-46392; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-32463 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0010/

NetApp published this final advisory covering CVE-2025-32463; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-29087 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0003/

NetApp published this interim advisory covering CVE-2025-29087; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-22233 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0008/

NetApp published this interim advisory covering CVE-2025-22233; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-1179 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0006/

NetApp published this interim advisory covering CVE-2025-1179; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-0840 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0005/

NetApp published this interim advisory covering CVE-2025-0840; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-9622 Resteasy Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0004/

NetApp published this final advisory covering CVE-2024-9622; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-12801 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0001/

NetApp published this interim advisory covering CVE-2024-12801; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; E-Series SANtricity Unified Manager and Web Services Proxy; Management Services for Element Software and NetApp HCI; ONTAP tools for VMware vSphere 10; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2024-12798 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0002/

NetApp published this interim advisory covering CVE-2024-12798; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; E-Series SANtricity Unified Manager and Web Services Proxy; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2025-4802 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0010/

NetApp published this interim advisory covering CVE-2025-4802; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-26618 Erlang OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0009/

NetApp published this final advisory covering CVE-2025-26618; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-50076 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0003/

NetApp published this interim advisory covering CVE-2024-50076; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2024-49997 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0005/

NetApp published this interim advisory covering CVE-2024-49997; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-47693 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0002/

NetApp published this interim advisory covering CVE-2024-47693; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-47689 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0001/

NetApp published this interim advisory covering CVE-2024-47689; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-45778 Grub Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0007/

NetApp published this interim advisory covering CVE-2024-45778; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-42256 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0004/

NetApp published this interim advisory covering CVE-2024-42256; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-5025 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0008/

NetApp published this interim advisory covering CVE-2025-5025; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-4947 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0009/

NetApp published this interim advisory covering CVE-2025-4947; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-49125 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0006/

NetApp published this interim advisory covering CVE-2025-49125; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-49124 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0005/

NetApp published this interim advisory covering CVE-2025-49124; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4123 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0001/

NetApp published this final advisory covering CVE-2025-4123; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-3050 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0002/

NetApp published this final advisory covering CVE-2025-3050; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-2518 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0003/

NetApp published this final advisory covering CVE-2025-2518; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-53846 Erlang OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0010/

NetApp published this interim advisory covering CVE-2024-53846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-49350 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0004/

NetApp published this final advisory covering CVE-2024-49350; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4575 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0009/

NetApp published this interim advisory covering CVE-2025-4575; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-27610 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0003/

NetApp published this final advisory covering CVE-2025-27610; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27363 Freetype Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0008/

NetApp published this interim advisory covering CVE-2025-27363; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-27111 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0002/

NetApp published this final advisory covering CVE-2025-27111; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-25184 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0001/

NetApp published this final advisory covering CVE-2025-25184; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24855 Libxslt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0006/

NetApp published this final advisory covering CVE-2025-24855; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-23061 Mongoose Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0004/

NetApp published this final advisory covering CVE-2025-23061; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-56406 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0010/

NetApp published this final advisory covering CVE-2024-56406; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-53900 Mongoose Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0005/

NetApp published this final advisory covering CVE-2024-53900; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-47685 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0011/

NetApp published this interim advisory covering CVE-2024-47685; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; SnapCenter Plug-in for VMware vSphere; StorageGRID (formerly StorageGRID Webscale); StorageGRID Baseboard Management Controller (BMC) - SG6060/SGF6024/SG100/SG1000; StorageGRID Baseboard Management Controller (BMC) - SG6160/SGF6112/SG110/SG1100.

Open source
Advisory

CVE-2023-1192 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0012/

NetApp published this interim advisory covering CVE-2023-1192; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-32415 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0003/

NetApp published this interim advisory covering CVE-2025-32415; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; ONTAP 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-32414 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0004/

NetApp published this interim advisory covering CVE-2025-32414; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-29088 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0010/

NetApp published this interim advisory covering CVE-2025-29088; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-52981 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0009/

NetApp published this interim advisory covering CVE-2024-52981; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-47611 XZ Utils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0006/

NetApp published this interim advisory covering CVE-2024-47611; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21664 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0005/

NetApp published this final advisory covering CVE-2024-21664; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2022-37026 Erlang-otp Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0008/

NetApp published this final advisory covering CVE-2022-37026; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32224 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0007/

NetApp published this final advisory covering CVE-2022-32224; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-3576 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0008/

NetApp published this final advisory covering CVE-2025-3576; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

CVE-2025-3277 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0005/

NetApp published this interim advisory covering CVE-2025-3277; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-31115 XZ Utils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0001/

NetApp published this interim advisory covering CVE-2025-31115; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-30211 Erlang/OTP Vulnerability NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0006/

NetApp published this interim advisory covering CVE-2025-30211; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-22871 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0004/

NetApp published this final advisory covering CVE-2025-22871; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; Astra Control Provisioner; Data Infrastructure Insights Telegraf Agent; NetApp Console Agent; NetApp Kubernetes Monitoring Operator; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-29937 FREEBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0007/

NetApp published this final advisory covering CVE-2024-29937; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5379 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0003/

NetApp published this interim advisory covering CVE-2023-5379; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-40775 ISC Bind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0001/

NetApp published this final advisory covering CVE-2025-40775; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-31672 Apache POI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0004/

NetApp published this interim advisory covering CVE-2025-31672; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-1861 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0005/

NetApp published this final advisory covering CVE-2025-1861; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1734 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0009/

NetApp published this final advisory covering CVE-2025-1734; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1217 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0008/

NetApp published this final advisory covering CVE-2025-1217; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-50083 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0010/

NetApp published this interim advisory covering CVE-2024-50083; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2024-12243 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0002/

NetApp published this interim advisory covering CVE-2024-12243; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

May 2025 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250516-0002/

NetApp published this final advisory covering CVE-2025-0915, CVE-2025-1000, CVE-2025-1992; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1493 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250516-0001/

NetApp published this final advisory covering CVE-2025-1493; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-0624 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250516-0006/

NetApp published this interim advisory covering CVE-2025-0624; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-22870 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0007/

NetApp published this final advisory covering CVE-2025-22870; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Trident; Trident Autosupport; Trident Protect.

Open source
Advisory

CVE-2024-38828 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0009/

NetApp published this interim advisory covering CVE-2024-38828; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-35890 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0008/

NetApp published this final advisory covering CVE-2024-35890; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-11741 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0006/

NetApp published this final advisory covering CVE-2024-11741; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24626 GNU Screen Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0003/

NetApp published this final advisory covering CVE-2023-24626; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-28831 BusyBox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0005/

NetApp published this final advisory covering CVE-2021-28831; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-26937 GNU Screen Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0004/

NetApp published this final advisory covering CVE-2021-26937; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-8165 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0002/

NetApp published this final advisory covering CVE-2020-8165; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2015-0240 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0001/

NetApp published this final advisory covering CVE-2015-0240; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-29768 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0001/

NetApp published this final advisory covering CVE-2025-29768; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-27423 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0002/

NetApp published this final advisory covering CVE-2025-27423; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-7409 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0008/

NetApp published this final advisory covering CVE-2024-7409; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-37372 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0010/

NetApp published this final advisory covering CVE-2024-37372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-3446 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0007/

NetApp published this final advisory covering CVE-2024-3446; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-3219 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0004/

NetApp published this interim advisory covering CVE-2024-3219; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-27280 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0003/

NetApp published this final advisory covering CVE-2024-27280; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-28362 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0009/

NetApp published this final advisory covering CVE-2023-28362; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2025 MySQL 8.0.41, 8.4.4 and 9.2.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0006/

NetApp published this interim advisory covering CVE-2025-21577, CVE-2025-30682, CVE-2025-30687, CVE-2025-30688, CVE-2025-21574, CVE-2025-21575, CVE-2025-30693, CVE-2025-30695, CVE-2025-30689, CVE-2025-30696, CVE-2025-30715, CVE-2025-21584, CVE-2025-21580, CVE-2025-21581, CVE-2025-21585, CVE-2025-21579, CVE-2025-30705, CVE-2025-30683, CVE-2025-30684, CVE-2025-30685, CVE-2025-30699, CVE-2025-30704, CVE-2024-13176, CVE-2025-30721, CVE-2025-30703, CVE-2025-30681; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

April 2025 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0005/

NetApp published this interim advisory covering CVE-2025-30698, CVE-2025-21587; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp Console; NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight.

Open source
Advisory

CVE-2025-32728 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0002/

NetApp published this interim advisory covering CVE-2025-32728; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-32433 Erlang OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0001/

NetApp published this final advisory covering CVE-2025-32433; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22228 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0009/

NetApp published this interim advisory covering CVE-2025-22228; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-9287 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0006/

NetApp published this final advisory covering CVE-2024-9287; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2024-6096 Progress Telerik Reporting Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0003/

NetApp published this final advisory covering CVE-2024-6096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-3447 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0005/

NetApp published this final advisory covering CVE-2024-3447; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-10846 compose-go Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0008/

NetApp published this final advisory covering CVE-2024-10846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-5733 ISC DHCP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0010/

NetApp published this final advisory covering CVE-2018-5733; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
AI

2026-09-02-nvidia-nemo-microservices-for-ai-agents-hits-the-market-the-next-platform

Source: https://news.google.com/rss/articles/CBMirAFBVV95cUxQMXBUVDhVTFJnSF9manFlcmRGNE5CaEVtd2R5ZU9YT3Bwa3AwR2lEZmdnXzdZWmVpalF0QXpyVjUzcGk2RGNxN01Xb2xva2pQOUo0Rk5uRVJpcnFhYXNGOXZJQS1EUm5QU0tramJPRzc1WVA0a0RHblhZSmV2TlFNckpfLXFuVDBUZWVDSnZUZTI5a2NJNndZWXFMVlI3WkV3M2lzc3BoZzZOZGMx?oc=5

The Next Platform article from the NetApp NVIDIA Google News RSS feed. Nvidia NeMo Microservices For AI Agents Hits The Market - The Next Platform. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

CVE-2025-30722 MySQL Client Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250418-0005/

NetApp published this final advisory covering CVE-2025-30722; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

CVE-2025-30706 MySQL Connector/J Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250418-0007/

NetApp published this final advisory covering CVE-2025-30706; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-7254 MySQL Connector/J Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250418-0006/

NetApp published this final advisory covering CVE-2024-7254; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-27982 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250418-0001/

NetApp published this final advisory covering CVE-2024-27982; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-13176 MySQL Connector/ODBC Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250418-0010/

NetApp published this final advisory covering CVE-2024-13176; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1178 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0008/

NetApp published this interim advisory covering CVE-2025-1178; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-1176 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0007/

NetApp published this interim advisory covering CVE-2025-1176; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-47814 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0009/

NetApp published this final advisory covering CVE-2024-47814; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-4418 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0002/

NetApp published this interim advisory covering CVE-2024-4418; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1441 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0003/

NetApp published this interim advisory covering CVE-2024-1441; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-11168 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0004/

NetApp published this interim advisory covering CVE-2024-11168; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Mediator; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-0450 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0005/

NetApp published this interim advisory covering CVE-2024-0450; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2024-0397 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0006/

NetApp published this interim advisory covering CVE-2024-0397; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Mediator; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2021-47001 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0001/

NetApp published this interim advisory covering CVE-2021-47001; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-1153 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0005/

NetApp published this interim advisory covering CVE-2025-1153; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-1148 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0004/

NetApp published this interim advisory covering CVE-2025-1148; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-1147 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0003/

NetApp published this interim advisory covering CVE-2025-1147; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-53580 Iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0009/

NetApp published this final advisory covering CVE-2024-53580; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2024-50602 Libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0008/

NetApp published this interim advisory covering CVE-2024-50602; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SAN Host Utilities for Windows.

Open source
Advisory

CVE-2024-36958 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0007/

NetApp published this interim advisory covering CVE-2024-36958; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-36945 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0006/

NetApp published this interim advisory covering CVE-2024-36945; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2024-23444 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0001/

NetApp published this interim advisory covering CVE-2024-23444; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-12254 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0010/

NetApp published this final advisory covering CVE-2024-12254; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

March 2025 Ingress NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0008/

NetApp published this final advisory covering CVE-2025-24513, CVE-2025-24514, CVE-2025-1097, CVE-2025-1098, CVE-2025-1974; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-29927 Next.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0002/

NetApp published this final advisory covering CVE-2025-29927; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-8176 Libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0009/

NetApp published this interim advisory covering CVE-2024-8176; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2024-56171 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0010/

NetApp published this interim advisory covering CVE-2024-56171; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9.

Open source
Advisory

CVE-2024-54085 AMI MegaRAC Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0003/

NetApp published this final advisory covering CVE-2024-54085; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; StorageGRID Baseboard Management Controller (BMC) - SG6160/SGF6112/SG110/SG1100.

Open source
Advisory

CVE-2024-43484 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0007/

NetApp published this final advisory covering CVE-2024-43484; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-20672 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0006/

NetApp published this final advisory covering CVE-2024-20672; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24531 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0005/

NetApp published this final advisory covering CVE-2023-24531; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Trident; Trident Autosupport.

Open source
Advisory

CVE-2021-3773 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0004/

NetApp published this final advisory covering CVE-2021-3773; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

January 2025 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0003/

NetApp published this final advisory covering CVE-2025-23084, CVE-2025-23085; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24928 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0006/

NetApp published this interim advisory covering CVE-2025-24928; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; ONTAP 9.

Open source
Advisory

CVE-2025-1215 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0005/

NetApp published this final advisory covering CVE-2025-1215; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-35896 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0004/

NetApp published this interim advisory covering CVE-2024-35896; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-35894 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0002/

NetApp published this final advisory covering CVE-2024-35894; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-2408 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0008/

NetApp published this final advisory covering CVE-2024-2408; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-10524 Wget Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0007/

NetApp published this interim advisory covering CVE-2024-10524; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2021-4207 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0009/

NetApp published this final advisory covering CVE-2021-4207; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2021-4206 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0010/

NetApp published this final advisory covering CVE-2021-4206; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-25293 Ruby SAML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0008/

NetApp published this final advisory covering CVE-2025-25293; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-25292 Ruby SAML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0009/

NetApp published this final advisory covering CVE-2025-25292; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2025-25291 Ruby SAML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0010/

NetApp published this final advisory covering CVE-2025-25291; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2025-24014 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0005/

NetApp published this final advisory covering CVE-2025-24014; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-22134 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0004/

NetApp published this final advisory covering CVE-2025-22134; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-0938 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0002/

NetApp published this interim advisory covering CVE-2025-0938; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Mediator.

Open source
Advisory

CVE-2024-9264 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0007/

NetApp published this final advisory covering CVE-2024-9264; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-3220 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0001/

NetApp published this interim advisory covering CVE-2024-3220; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-27113 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0004/

NetApp published this interim advisory covering CVE-2025-27113; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9.

Open source
Advisory

CVE-2025-26603 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0003/

NetApp published this final advisory covering CVE-2025-26603; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-0725 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0009/

NetApp published this interim advisory covering CVE-2025-0725; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-0665 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0007/

NetApp published this final advisory covering CVE-2025-0665; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-0167 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0008/

NetApp published this interim advisory covering CVE-2025-0167; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-9823 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0006/

NetApp published this interim advisory covering CVE-2024-9823; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-6763 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0005/

NetApp published this interim advisory covering CVE-2024-6763; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-54133 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0010/

NetApp published this final advisory covering CVE-2024-54133; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-35176 Ruby REXML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0001/

NetApp published this interim advisory covering CVE-2024-35176; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1298 Tianocore EDK Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0002/

NetApp published this final advisory covering CVE-2024-1298; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-26466 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0002/

NetApp published this interim advisory covering CVE-2025-26466; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2025-26465 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0003/

NetApp published this interim advisory covering CVE-2025-26465; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2025-23083 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0008/

NetApp published this final advisory covering CVE-2025-23083; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-0395 glibc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0006/

NetApp published this interim advisory covering CVE-2025-0395; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-40896 libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0004/

NetApp published this interim advisory covering CVE-2024-40896; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-26306 iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0007/

NetApp published this final advisory covering CVE-2024-26306; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-34188 Mongoose Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0001/

NetApp published this final advisory covering CVE-2023-34188; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3929 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0010/

NetApp published this final advisory covering CVE-2021-3929; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2021-3735 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0009/

NetApp published this final advisory covering CVE-2021-3735; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2021-3549 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0005/

NetApp published this interim advisory covering CVE-2021-3549; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-25193 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0006/

NetApp published this interim advisory covering CVE-2025-25193; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2025-24970 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0005/

NetApp published this interim advisory covering CVE-2025-24970; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2025-22866 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0002/

NetApp published this final advisory covering CVE-2025-22866; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1094 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0010/

NetApp published this final advisory covering CVE-2025-1094; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-0306 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0009/

NetApp published this final advisory covering CVE-2025-0306; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-45341 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0004/

NetApp published this final advisory covering CVE-2024-45341; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2024-45338 golang.org/x/net Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0001/

NetApp published this interim advisory covering CVE-2024-45338; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45336 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0003/

NetApp published this final advisory covering CVE-2024-45336; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator; Trident.

Open source
Advisory

CVE-2024-45310 runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0008/

NetApp published this interim advisory covering CVE-2024-45310; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-43709 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0007/

NetApp published this final advisory covering CVE-2024-43709; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24860 Apache Cassandra Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0005/

NetApp published this final advisory covering CVE-2025-24860; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24814 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0002/

NetApp published this final advisory covering CVE-2025-24814; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-23184 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0003/

NetApp published this interim advisory covering CVE-2025-23184; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2025-23015 Apache Cassandra Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0006/

NetApp published this final advisory covering CVE-2025-23015; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-27137 Apache Cassandra Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0004/

NetApp published this final advisory covering CVE-2024-27137; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-12797 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0001/

NetApp published this interim advisory covering CVE-2024-12797; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-11477 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0007/

NetApp published this final advisory covering CVE-2024-11477; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Trident Autosupport.

Open source
Advisory

CVE-2023-6918 libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0009/

NetApp published this interim advisory covering CVE-2023-6918; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6152 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0008/

NetApp published this final advisory covering CVE-2023-6152; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38037 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0010/

NetApp published this final advisory covering CVE-2023-38037; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2024 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0008/

NetApp published this final advisory covering CVE-2024-51562, CVE-2024-51563, CVE-2024-51564, CVE-2024-51565, CVE-2024-51566; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2021 SELinux Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0004/

NetApp published this interim advisory covering CVE-2021-36084, CVE-2021-36085, CVE-2021-36086, CVE-2021-36087; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-0662 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0006/

NetApp published this final advisory covering CVE-2025-0662; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-0411 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0005/

NetApp published this final advisory covering CVE-2025-0411; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2025-0374 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0007/

NetApp published this final advisory covering CVE-2025-0374; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-0373 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0009/

NetApp published this final advisory covering CVE-2025-0373; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-12705 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0003/

NetApp published this final advisory covering CVE-2024-12705; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-11187 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0002/

NetApp published this interim advisory covering CVE-2024-11187; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-6780 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0010/

NetApp published this interim advisory covering CVE-2023-6780; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4639 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0001/

NetApp published this interim advisory covering CVE-2023-4639; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

January 2025 rsync Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0002/

NetApp published this interim advisory covering CVE-2024-12084, CVE-2024-12085, CVE-2024-12086, CVE-2024-12087, CVE-2024-12088, CVE-2024-12747; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

January 2025 MySQL 8.0.40, 8.4.3, and 9.1.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0004/

NetApp published this interim advisory covering CVE-2024-11053, CVE-2025-21500, CVE-2025-21501, CVE-2025-21518, CVE-2025-21522, CVE-2025-21497, CVE-2025-21555, CVE-2025-21559, CVE-2025-21540, CVE-2025-21490, CVE-2025-21491, CVE-2025-21503, CVE-2025-21523, CVE-2025-21531, CVE-2025-21505, CVE-2025-21529, CVE-2025-21543, CVE-2025-21519, CVE-2025-21546, CVE-2025-21520; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2024-52318 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0009/

NetApp published this final advisory covering CVE-2024-52318; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-49766 Werkzeug Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0005/

NetApp published this final advisory covering CVE-2024-49766; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-47554 Apache Commons IO Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0010/

NetApp published this interim advisory covering CVE-2024-47554; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp BlueXP; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9; SANtricity Storage Plugin for vCenter; SnapCenter.

Open source
Advisory

CVE-2024-45337 golang.org/x/crypto Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0007/

NetApp published this interim advisory covering CVE-2024-45337; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Data Infrastructure Insights Telegraf Agent; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-31141 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0001/

NetApp published this final advisory covering CVE-2024-31141; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24789 Golang Go Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0008/

NetApp published this final advisory covering CVE-2024-24789; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-11053 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0003/

NetApp published this interim advisory covering CVE-2024-11053; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

January 2025 MySQL 9.1.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0014/

NetApp published this interim advisory covering CVE-2025-21566, CVE-2025-21567; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

January 2025 MySQL 8.4.3 and 9.1.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0013/

NetApp published this interim advisory covering CVE-2025-21499, CVE-2025-21493; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

January 2025 MySQL 8.0.39, 8.4.2, and 9.0.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0010/

NetApp published this interim advisory covering CVE-2024-37371, CVE-2025-21521, CVE-2025-21525, CVE-2025-21504, CVE-2025-21536, CVE-2025-21534, CVE-2025-21494; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2025-21502 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0009/

NetApp published this interim advisory covering CVE-2025-21502; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2025-21492 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0011/

NetApp published this interim advisory covering CVE-2025-21492; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-52798 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0002/

NetApp published this final advisory covering CVE-2024-52798; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-52317 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0004/

NetApp published this final advisory covering CVE-2024-52317; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-52316 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0003/

NetApp published this final advisory covering CVE-2024-52316; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45296 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0001/

NetApp published this final advisory covering CVE-2024-45296; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-38827 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0007/

NetApp published this interim advisory covering CVE-2024-38827; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-38821 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0006/

NetApp published this final advisory covering CVE-2024-38821; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-13176 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0005/

NetApp published this interim advisory covering CVE-2024-13176; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 9; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-11053 MySQL Enterprise Backup Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0012/

NetApp published this final advisory covering CVE-2024-11053; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-41946 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0007/

NetApp published this final advisory covering CVE-2024-41946; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-39908 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0008/

NetApp published this interim advisory covering CVE-2024-39908; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-38807 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0006/

NetApp published this interim advisory covering CVE-2024-38807; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-29415 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0010/

NetApp published this final advisory covering CVE-2024-29415; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21409 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0002/

NetApp published this final advisory covering CVE-2024-21409; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-0690 Ansible Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0001/

NetApp published this interim advisory covering CVE-2024-0690; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-52434 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0009/

NetApp published this final advisory covering CVE-2023-52434; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-41913 strongSwan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0003/

NetApp published this final advisory covering CVE-2023-41913; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0049 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0005/

NetApp published this final advisory covering CVE-2023-0049; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2021-3918 Json-schema Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0004/

NetApp published this final advisory covering CVE-2021-3918; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Astra Control Center.

Open source
Advisory

CVE-2024-8929 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250110-0008/

NetApp published this final advisory covering CVE-2024-8929; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45289 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250110-0001/

NetApp published this final advisory covering CVE-2024-45289; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-39281 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250110-0002/

NetApp published this final advisory covering CVE-2024-39281; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-10979 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250110-0003/

NetApp published this final advisory covering CVE-2024-10979; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); ONTAP tools for VMware vSphere 10.

Open source
Docs

ONTAP hardware and software compatibility matrix

Source: https://docs.netapp.com/us-en/ontap-systems/supported-platforms.html

NetApp's supported-platform matrix provides the minimum ONTAP train for newer controllers: the A20/A30/A50 and C30/C60/C80 generation begins at 9.16.1, A1K/A70/A90 at 9.15.1, AFX 1K at 9.17.1, and AFX 2K at 9.19.1. It also maps ASA r2 and recent FAS generations to their starting releases.

Open source
Advisory

CVE-2024-53677 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250103-0005/

NetApp published this final advisory covering CVE-2024-53677; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-49767 Werkzeug Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250103-0007/

NetApp published this final advisory covering CVE-2024-49767; the API labels exploitation information as **Public**. The API currently lists affected products as: BlueXP Classification; Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2024-43398 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250103-0006/

NetApp published this interim advisory covering CVE-2024-43398; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-38429 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250103-0009/

NetApp published this final advisory covering CVE-2023-38429; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2017-18017 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250103-0010/

NetApp published this interim advisory covering CVE-2017-18017; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A320; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2016-10229 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250103-0008/

NetApp published this final advisory covering CVE-2016-10229; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Docs

2026-09-03-kb-ontap-upgrade-resolution-guide

Source: https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/ONTAP_Upgrade_Resolution_Guide

NetApp's official pre-upgrade resolution tree for ONTAP 9 — the canonical starting point whenever an ONTAP 9.x upgrade misbehaves. Indexes every documented upgrade blocker by failure stage (pre-upgrade validation, NDU takeover/giveback, post-upgrade verification) and links to the matching symptoms, EMS messages, and remediation KBs. Public index confirms 19,221+ views and pairs directly with the ONTAP Upgrade Post Upgrade Resolution Guide. For ONTAP 9 admins this is the "before you open a TAC case" checklist that maps symptoms to root-cause articles. (Full content is gated behind NetApp Support login; this entry captures the public index and related-article links visible to all readers.)

Open source
Docs

2026-09-03-kb-ontap-switch-unreachable-management-ip

Source: https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/SwitchUnreachable_Alert_Due_to_Cluster_Switch_wrong_management_IP_configured

ONTAP 9.x cluster-switch troubleshooting for Broadcom BES-53248 switches (the most common cluster-network switch in modern AFF deployments). Diagnoses the `SwitchUnreachable_Alert on CLUSTER_NAME (SWITCH_1 | SWITCH_2)` EMS event when `system switch ethernet show` returns `IsMonitored: false / Reason: IP address not reachable` and `network device-discovery show` shows the switch is still being CDP-discovered on the data port but the management IP no longer matches. The trigger: management-IP change (firmware upgrade, IP-reclaim, or operator error) without re-running ONTAP's switch-health monitor configuration. Shows expected output for both healthy and unhealthy states. Resolution: reconfigure the switch-health monitor (`system switch ethernet modify -switch-ip`) to the new IP and confirm reachability. Useful for any site that just did a switch firmware update.

Open source
Docs

2026-09-03-kb-ontap-reclaim-aggregate-space

Source: https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/How_to_reclaim_space_in_an_aggregate_that_is_full

Classic ONTAP operational KB — when an aggregate reports full, your first move is to figure out whether the space is actually consumed by user data, snapshot reserve, WAFL metadata overhead, or space-optimized metadata. The guide walks through the diagnostic commands (`aggr show_space`, `volume show-space`, `df -h` against the aggregate, examining `percent-used` vs `physical-used`), the difference between space reservation modes (volume guarantee none/file/full) and snapshot policies that hold old copies you can prune. Then the reclaim playbook: deleting snapshots, resizing volumes down, turning on volume-level autogrow with a higher maximum, moving a volume to a less-full aggregate, deleting unused FlexClone parents/LUNs, and finally raising the aggregate size if there is spare spare disk or free LUNs in the disk pool. Important caveat: increasing the aggregate's snap reserve or volume guarantee is rarely the right answer; usually you need to free data.

Open source
Docs

2026-09-03-kb-ontap-pci-nmi-umce-panics

Source: https://kb.netapp.com/on-prem/ontap/OHW/OHW-KBs/How_to_troubleshoot_PCI_NMI_UMCE_and_nested_machine_check_exception_panics

Hardware-level panic troubleshooting for ONTAP nodes that hit a PCI Express NMI, an Uncorrectable Machine Check Exception (UMCE), or nested machine-check panics — the kind of crash that takes a controller down and triggers HA takeover. The KB explains how to read the panic string (`PCI: NMI...`, `MCE: ...`, bank/socket/MCA registers), how to collect the SP-core/buddy dump and pair it with the matching AutoSupport, and the difference between a CPU-side MCE (often firmware/microcode) and a PCIe device-side error (link degradation, bad slot, IO card firmware). Then the resolution flow: identify which PCI device logged the error (NIC, FC HBA, NVMe shelf), reseat or move the card to a different slot, update the card/CPLD firmware via the service image, and confirm no upstream switch or shelf port issues. A solid field reference for TAC cases on FAS/AFF takeovers where the panic root-cause isn't immediately obvious.

Open source
Docs

2026-09-03-kb-ontap-nse-sed-fips-unlock

Source: https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/How_to_unlock_SED_and_FIPS_disks_using_NSE

NetApp Knowledge Base how-to for unlocking Self-Encrypting Drives (SED) and FIPS-validated disks using NetApp Storage Encryption (NSE) before disabling the Onboard Key Manager (OKM). Stepwise procedure: requires authenticating to OKM, exporting the authentication keys for the disk shelves, and re-issuing unlock commands at the SP/BMC level so each disk's KAS (Key Authentication Server) accepts the cluster's KMIP-style key. Article is part of the OKM↔NSE migration playbook — must be performed BEFORE OKM is turned off or all encrypted data on the disks becomes permanently inaccessible. Tag list includes SED, FIPS, OKM, NSE, and storage encryption; specialty is core ONTAP 9. Public index visible; detailed procedure gated behind NetApp Support login.

Open source
Docs

2026-09-03-kb-ontap-metrocluster-svm-kek-mismatch

Source: https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/SVM-KEK_key_mismatch_warning_in_ONTAP_MetroCluster_with_Onboard_Key_Manager

Diagnostic walk-through for the `km.okm.key.missing` EMS event and the `Internal Error. The local and partner clusters do not have the same list of SVM-KEKs` warning returned by `metrocluster check cluster show -check onboard-key-management -instance`. In a MetroCluster IP/FC setup with Onboard Key Manager (OKM) enabled, SVM-KEKs (the per-SVM key-encryption keys) must exist on both clusters or encrypted volumes at the surviving site cannot be unlocked after a site failover. Public-visible content shows the EMS message, the metrocluster check output columns (Result of the Check, Additional Information/Recovery Steps), and the actual event timestamp from August 2026 (8/18/2026). Article references the underlying MCC + OKM + SVM-KEK recovery workflow which TAC runs to re-mirror the SVM key set to the surviving cluster — critical content for anyone running MetroCluster with NVE/NAE at both sites.

Open source
Docs

2026-09-03-kb-ontap-ktls-handshake-limit-913

Source: https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/Repeating_ktls.cnxnHandshakeLimit_message_after_ONTAP_Upgrade_to_9.13

Specific ONTAP 9.13+ post-upgrade failure mode: EMS log fills with `[nodename: kernel: ktls.cnxnHandshakeLimit:notice]: ONTAP reached the maximum limit of N concurrent TLS connection handshakes. If this limit is reached, subsequent TLS connections will fail.` Often paired with `ems.engine.suppressed:debug: Event 'ktls.cnxnHandshakeLimit' suppressed N times in last NNN seconds`. Root cause is the kernel TLS (kTLS) handshake concurrency cap (170 by default) — typically hit when many NFS-over-TLS, SMB-over-TLS, or LDAP-over-TLS clients reconnect simultaneously after the upgrade. Public EMS excerpt and article framing are visible; the actual tunables and remediation steps are behind NetApp Support login. Tag the KB when triaging post-9.13-upgrade incidents where TLS connections intermittently fail.

Open source
Docs

2026-09-03-kb-ontap-flexvol-inode-max

Source: https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/How_to_increase_the_maximum_inode_count_or_files_for_a_flexible_volume

Canonical 167,502-view ONTAP KB for the dreaded `wafl.vol.outOfInodes` / `file system is out of inodes` error. Walks through inspecting current settings with `set advanced` then `volume show -vserver svm1 -volume vol1 -fields size,files,files-used,files-maximum-possible` and shows the relationship between FlexVol size and `files-maximum-possible` (typically 1 inode per 32KB of volume size by default). The procedure to increase the inode ceiling is `volume modify -vserver svm1 -volume vol1 -files <new-count>` — and the KB warns that the max possible is bounded by current volume size unless you grow the volume at the same time. Critical context: shrinking a FlexVol below its current `files-used` is blocked; you can only grow inodes, never reduce. (Public preview shows the diagnostic commands; full step list behind NetApp Support login.)

Open source
Docs

2026-09-03-kb-ontap-failover-io-interruption-vmware

Source: https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/What_is_the_expected_I_O_interruption_time_during_storage_failover

NetApp's official sizing guidance for the I/O gap during ONTAP storage failover (SFO) when running VMware ESXi on NFS or block datastores. Confirms the I/O interruption is "typically limited to a few seconds up to approximately 15 seconds" — well under VMware's default NFS datastore timeout of 60s and the typical FC HBA timeout of 30s. Practical consequence: datastores stay mounted, VMs do not power off, in-flight I/O is briefly queued and resumes once the partner node is serving LIFs. Admins should expect short latency spikes inside guest OSes and brief application slowness but no fault tolerance events. Sets expectations correctly so the failover doesn't get escalated as a fault — useful for VMware/NetApp converged stack SREs.

Open source
Docs

2026-09-03-kb-ontap-cluster-recovery-failure-cases

Source: https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/What_are_the_main_failure_cases_that_require_cluster-level_recovery_in_an_ONTAP_environment

Definitive NetApp answer on when ONTAP needs cluster-level recovery (RDB + root aggregate restoration), as opposed to node-level or aggregate-level recovery. Two representative cases: (1) multiple simultaneous disk failures in aggr0 exceeding RAID-DP/RAID-TEC tolerance — typically more than three disks failing at once or a shelf-level power loss that takes root disks down. aggr0 holds the ONTAP OS image and the replicated database (RDB), so RDB quorum can't be re-established. (2) simultaneous power outage in both HA pair nodes causing a dirty shutdown that leaves RDB inconsistent. Cluster recovery is rare but disruptive — knowing the exact triggers helps admins plan dual-PSU, dual-feed, and battery-backed cache strategies for their root shelves.

Open source
Docs

2026-09-03-kb-ontap-autosupport-smtp-delivery-failure

Source: https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/ONTAP_AutoSupport_Transport_SMTP_Delivery_Failure_Resolution_Guide

NetApp's official resolution path for "AutoSupport emails aren't reaching NetApp" — the SMTP transport branch of the ASUP troubleshooting tree. Starts with `autosupport show -node <node> -instance` to verify mailhost/from/to, then `system node autosupport check show` to validate the four ASUP delivery channels (HTTPS, HTTP, SMTP, OnDemand). If SMTP fails, walks through checking SMTP reachability to the mailhost, reviewing `notifyd.log` for SMTP errors, and inspecting `autosupport history` for delivery timestamps. A 13,169-view / 2-vote KB rated as core-specialty ONTAP 9 material — used by every TAC case where the customer can't tell whether AutoSupport was even attempted.

Open source
Docs

2026-09-03-kb-ontap-9-performance-resolution-guide

Source: https://kb.netapp.com/on-prem/ontap/Perf/Perf-KBs/ONTAP_9_Performance_Resolution_Guide

NetApp's official performance troubleshooting tree for ONTAP 9 — the canonical starting point whenever a customer reports slow I/O, latency spikes, or throughput regressions. The guide organizes the investigation into the standard ONTAP 9 perf flow: confirm whether the bottleneck is on the client/network path, the protocol layer (NFS, SMB, iSCSI, FC), the storage virtual machine, the volume/FlexVol, the aggregate/WAFL, or the disk/RAID layer. Each branch points to the specific KB article, EMS message, and PerfStat/Statistics counter families to look at next (e.g. `statistics show`, `qos statistics`, ` wafl_hya_perf`, `nfs3_histogram`, WAFL read/write latency histograms, object-store offload latency if FabricPool is involved). Tells you which ONTAP 9 commands to run before you open a support case so your ASUP bundle has the data TAC actually needs.

Open source
AI

2026-09-03-kb-does-ontap-include-ai-engine-for-arp-ai

Source: https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/Does_ONTAP_include_an_AI_engine_for_ARP_AI

NetApp's authoritative answer to a frequently-asked AI question: ARP/AI (Autonomous Ransomware Protection with AI) does not mean ONTAP itself ships a general-purpose AI engine. ARP/AI is a pre-trained model file shipped with ONTAP and used at inference time to score file entropy / data-pattern anomalies; ONTAP has no built-in ML training engine or LLM. This matters when sizing conversations: customers who want to run their own models on ONTAP-stored data need NetApp AIPod (NVIDIA DGX BasePOD with NetApp storage) or FlexPod AI for the compute, while ARP/AI on the storage side is a one-way inference workload. Useful for clarifying the AI boundary between "what runs on NetApp" vs "what runs beside NetApp storage."

Open source
Advisory

CVE-2024-49761 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241227-0004/

NetApp published this final advisory covering CVE-2024-49761; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-48949 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241227-0003/

NetApp published this final advisory covering CVE-2024-48949; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-41123 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241227-0005/

NetApp published this final advisory covering CVE-2024-41123; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-3056 Podman Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241227-0002/

NetApp published this final advisory covering CVE-2024-3056; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-52439 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241227-0006/

NetApp published this final advisory covering CVE-2023-52439; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2018-20060 urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241227-0010/

NetApp published this interim advisory covering CVE-2018-20060; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-12121 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241227-0008/

NetApp published this final advisory covering CVE-2018-12121; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-12588 Rsyslog Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241227-0009/

NetApp published this final advisory covering CVE-2017-12588; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

November 2024 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0008/

NetApp published this final advisory covering CVE-2024-11233, CVE-2024-11234, CVE-2024-11236; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9.

Open source
Advisory

CVE-2024-9407 Podman Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0010/

NetApp published this final advisory covering CVE-2024-9407; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-48948 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0004/

NetApp published this final advisory covering CVE-2024-48948; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45663 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0003/

NetApp published this final advisory covering CVE-2024-45663; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26882 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0002/

NetApp published this interim advisory covering CVE-2024-26882; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A1K/A70/A90; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF/ASA Baseboard Management Controller (BMC) - A20/A30/A50/C30/C60/50; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-26633 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0001/

NetApp published this final advisory covering CVE-2024-26633; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-0985 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0005/

NetApp published this final advisory covering CVE-2024-0985; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-29403 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0009/

NetApp published this final advisory covering CVE-2023-29403; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-21583 Util-linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0006/

NetApp published this interim advisory covering CVE-2020-21583; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-17546 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0007/

NetApp published this final advisory covering CVE-2019-17546; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-9681 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0006/

NetApp published this interim advisory covering CVE-2024-9681; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-7254 Protobuf-java Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0010/

NetApp published this interim advisory covering CVE-2024-7254; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Console; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-43804 urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0007/

NetApp published this interim advisory covering CVE-2023-43804; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Mediator.

Open source
Advisory

CVE-2023-29402 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0004/

NetApp published this final advisory covering CVE-2023-29402; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29400 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0005/

NetApp published this final advisory covering CVE-2023-29400; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-12123 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0008/

NetApp published this final advisory covering CVE-2018-12123; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-12122 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0009/

NetApp published this final advisory covering CVE-2018-12122; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-9217 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0003/

NetApp published this final advisory covering CVE-2017-9217; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-52533 Gnome Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0009/

NetApp published this interim advisory covering CVE-2024-52533; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-39689 Certifi Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0001/

NetApp published this interim advisory covering CVE-2024-39689; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp XCP NFS; NetApp XCP SMB; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-38796 Tianocore EDK2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0006/

NetApp published this interim advisory covering CVE-2024-38796; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF BIOS - A700s; FAS/AFF BIOS - 2820; FAS/AFF BIOS - 8300/8700/A400/C400; FAS/AFF BIOS - A250/500f/C250; FAS/AFF BIOS - A300/8200/C190/A220/2720/2750/A150; FAS/AFF BIOS - A320; FAS/AFF BIOS - A700/9000; FAS/AFF BIOS - A800/C800; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2024-29857 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0008/

NetApp published this interim advisory covering CVE-2024-29857; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Console; ONTAP tools for VMware vSphere 9; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-28103 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0002/

NetApp published this final advisory covering CVE-2024-28103; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-42366 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0007/

NetApp published this interim advisory covering CVE-2023-42366; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-29405 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0003/

NetApp published this final advisory covering CVE-2023-29405; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28642 runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0005/

NetApp published this final advisory covering CVE-2023-28642; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-27561 runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0004/

NetApp published this interim advisory covering CVE-2023-27561; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2019-12749 D-Bus Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0010/

NetApp published this interim advisory covering CVE-2019-12749; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Docs

Elevating data privacy in Generative AI with NetApp (NetApp)

Source: https://www.netapp.com/blog/elevating-data-privacy-generative-ai/

NetApp technical blog on data-privacy architecture for generative AI workloads: ONTAP features (encryption, WORM/SnapLock, role-based access control, audit logging) that customers need to enforce when grounding LLMs in enterprise data. Includes sample policy mappings for GDPR/HIPAA and a reference architecture for SnapMirror-based RAG index replication between regions.

Open source
Advisory

CVE-2024-6197 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0008/

NetApp published this final advisory covering CVE-2024-6197; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-6162 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0009/

NetApp published this interim advisory covering CVE-2024-6162; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-41957 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0007/

NetApp published this interim advisory covering CVE-2024-41957; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-38820 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0003/

NetApp published this interim advisory covering CVE-2024-38820; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9; SnapCenter.

Open source
Advisory

CVE-2023-6378 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0012/

NetApp published this final advisory covering CVE-2023-6378; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

CVE-2023-34042 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0010/

NetApp published this interim advisory covering CVE-2023-34042; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2023-31486 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0011/

NetApp published this interim advisory covering CVE-2023-31486; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-2610 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0006/

NetApp published this final advisory covering CVE-2023-2610; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-24539 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0005/

NetApp published this final advisory covering CVE-2023-24539; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24537 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0004/

NetApp published this final advisory covering CVE-2023-24537; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-48174 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0001/

NetApp published this interim advisory covering CVE-2022-48174; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-2795 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0002/

NetApp published this interim advisory covering CVE-2022-2795; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

July 2024 7-Zip Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0011/

NetApp published this final advisory covering CVE-2023-52168, CVE-2023-52169; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-8373 AngularJS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0003/

NetApp published this interim advisory covering CVE-2024-8373; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-8372 AngularJS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0002/

NetApp published this interim advisory covering CVE-2024-8372; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36137 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0005/

NetApp published this final advisory covering CVE-2024-36137; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-30045 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0001/

NetApp published this final advisory covering CVE-2024-30045; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-28835 GNU TLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0009/

NetApp published this interim advisory covering CVE-2024-28835; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-22020 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0006/

NetApp published this final advisory covering CVE-2024-22020; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1459 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0008/

NetApp published this interim advisory covering CVE-2024-1459; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-1442 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0007/

NetApp published this final advisory covering CVE-2024-1442; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-7008 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0004/

NetApp published this interim advisory covering CVE-2023-7008; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2022-1304 E2fsprogs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0010/

NetApp published this interim advisory covering CVE-2022-1304; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-6384 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0001/

NetApp published this interim advisory covering CVE-2024-6384; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-41965 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0002/

NetApp published this interim advisory covering CVE-2024-41965; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-38428 GNU Wget Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0005/

NetApp published this interim advisory covering CVE-2024-38428; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-29736 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0003/

NetApp published this interim advisory covering CVE-2024-29736; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-25744 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0006/

NetApp published this final advisory covering CVE-2024-25744; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-29404 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0009/

NetApp published this final advisory covering CVE-2023-29404; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24540 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0008/

NetApp published this final advisory covering CVE-2023-24540; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24538 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0007/

NetApp published this final advisory covering CVE-2023-24538; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3520 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0010/

NetApp published this interim advisory covering CVE-2022-3520; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2022-0318 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0004/

NetApp published this interim advisory covering CVE-2022-0318; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

June 2024 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0002/

NetApp published this final advisory covering CVE-2022-24785, CVE-2022-31129, CVE-2010-4756, CVE-2024-21634, CVE-2024-25053, CVE-2024-25041, CVE-2024-20952, CVE-2024-20918, CVE-2024-20921, CVE-2024-20919, CVE-2024-20926, CVE-2024-20945, CVE-2023-33850, CVE-2017-20162, CVE-2023-46749, CVE-2023-5363, CVE-2017-20189, CVE-2023-44483, CVE-2018-9466, CVE-2021-36770, CVE-2023-2976, CVE-2023-22081, CVE-2023-22067, CVE-2023-5676, CVE-2021-23358, CVE-2023-24998, CVE-2021-3377, CVE-2023-26159, CVE-2022-3715, CVE-2023-37466, CVE-2023-51775, CVE-2023-37903, CVE-2023-46750, CVE-2021-20086, CVE-2023-39332, CVE-2023-38552, CVE-2023-39333, CVE-2023-39331; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

Intel SA-00999 CSME Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0003/

NetApp published this interim advisory covering CVE-2023-40067, CVE-2023-48361, CVE-2024-21844, CVE-2023-34424; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2024-8612 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0006/

NetApp published this final advisory covering CVE-2024-8612; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-37371 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0009/

NetApp published this interim advisory covering CVE-2024-37371; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-37370 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0007/

NetApp published this interim advisory covering CVE-2024-37370; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-36138 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0010/

NetApp published this final advisory covering CVE-2024-36138; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26641 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0008/

NetApp published this final advisory covering CVE-2024-26641; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-30587 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0004/

NetApp published this final advisory covering CVE-2023-30587; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-30584 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0005/

NetApp published this final advisory covering CVE-2023-30584; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2024 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0003/

NetApp published this final advisory covering CVE-2024-8927, CVE-2024-8925, CVE-2024-8926, CVE-2024-9026; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9.

Open source
Advisory

October 2024 MySQL Server 8.4.2 and 9.0.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0008/

NetApp published this interim advisory covering CVE-2024-21232, CVE-2024-21243, CVE-2024-21244; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

June 2023 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0011/

NetApp published this final advisory covering CVE-2023-30581, CVE-2023-30585, CVE-2023-30588, CVE-2023-30590; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-9143 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0001/

NetApp published this interim advisory covering CVE-2024-9143; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-26735 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0012/

NetApp published this interim advisory covering CVE-2024-26735; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-26733 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0013/

NetApp published this interim advisory covering CVE-2024-26733; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-23454 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0002/

NetApp published this final advisory covering CVE-2024-23454; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21247 MySQL Client Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0006/

NetApp published this interim advisory covering CVE-2024-21247; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-21209 MySQL Client Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0005/

NetApp published this final advisory covering CVE-2024-21209; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-21204 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0009/

NetApp published this interim advisory covering CVE-2024-21204; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-21200 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0007/

NetApp published this interim advisory covering CVE-2024-21200; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

October 2024 MySQL Server 8.0.39, 8.4.2, 9.0.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0006/

NetApp published this interim advisory covering CVE-2024-21193, CVE-2024-21194, CVE-2024-21196, CVE-2024-21197, CVE-2024-21198, CVE-2024-21199, CVE-2024-21201, CVE-2024-21203, CVE-2024-21213, CVE-2024-21218, CVE-2024-21219, CVE-2024-21230, CVE-2024-21231, CVE-2024-21236, CVE-2024-21237, CVE-2024-21239, CVE-2024-21241, CVE-2024-5535, CVE-2024-7264; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2024 MySQL Enterprise Backup Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0010/

NetApp published this final advisory covering CVE-2024-5535, CVE-2024-7264; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21238 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0009/

NetApp published this interim advisory covering CVE-2024-21238; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2024-21212 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0008/

NetApp published this interim advisory covering CVE-2024-21212; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2024-21207 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0007/

NetApp published this interim advisory covering CVE-2024-21207; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2023-5764 Ansible Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0001/

NetApp published this final advisory covering CVE-2023-5764; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-4237 Ansible Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0002/

NetApp published this final advisory covering CVE-2023-4237; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-32558 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0003/

NetApp published this final advisory covering CVE-2023-32558; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-25883 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0004/

NetApp published this final advisory covering CVE-2022-25883; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2024 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0010/

NetApp published this interim advisory covering CVE-2024-21208, CVE-2024-21210, CVE-2024-21217, CVE-2024-21235; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-7592 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0006/

NetApp published this interim advisory covering CVE-2024-7592; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-6232 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0007/

NetApp published this interim advisory covering CVE-2024-6232; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-45492 Libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0005/

NetApp published this interim advisory covering CVE-2024-45492; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); SAN Host Utilities for Windows.

Open source
Advisory

CVE-2024-45491 Libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0003/

NetApp published this interim advisory covering CVE-2024-45491; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); SAN Host Utilities for Windows.

Open source
Advisory

CVE-2024-45490 Libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0004/

NetApp published this interim advisory covering CVE-2024-45490; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2024-36886 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0002/

NetApp published this final advisory covering CVE-2024-36886; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-36883 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0001/

NetApp published this interim advisory covering CVE-2024-36883; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

September 2024 CUPS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0001/

NetApp published this interim advisory covering CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, CVE-2024-47177; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

Intel SA-01071 UEFI Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0009/

NetApp published this interim advisory covering CVE-2024-23599, CVE-2024-21871, CVE-2023-43626, CVE-2023-42772, CVE-2024-21829, CVE-2024-21781, CVE-2023-41833, CVE-2023-23904, CVE-2023-22351, CVE-2023-43753, CVE-2023-25546; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2024-8354 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0008/

NetApp published this final advisory covering CVE-2024-8354; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-8096 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0005/

NetApp published this interim advisory covering CVE-2024-8096; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-8088 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0010/

NetApp published this interim advisory covering CVE-2024-8088; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-7885 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0004/

NetApp published this interim advisory covering CVE-2024-7885; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-47850 CUPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0002/

NetApp published this final advisory covering CVE-2024-47850; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-47561 Apache Avro Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0003/

NetApp published this final advisory covering CVE-2024-47561; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2024-41909 Apache MINA SSHD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0006/

NetApp published this interim advisory covering CVE-2024-41909; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-27282 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0007/

NetApp published this final advisory covering CVE-2024-27282; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-6383 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0001/

NetApp published this interim advisory covering CVE-2024-6383; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45306 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0007/

NetApp published this interim advisory covering CVE-2024-45306; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-43802 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0008/

NetApp published this interim advisory covering CVE-2024-43802; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36946 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0002/

NetApp published this final advisory covering CVE-2024-36946; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-34158 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0003/

NetApp published this interim advisory covering CVE-2024-34158; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24791 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0004/

NetApp published this interim advisory covering CVE-2024-24791; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Provisioner; Trident; Trident Autosupport.

Open source
Advisory

CVE-2023-39333 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0006/

NetApp published this final advisory covering CVE-2023-39333; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2024 Node.js Elliptic Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0005/

NetApp published this final advisory covering CVE-2024-42459, CVE-2024-42460, CVE-2024-42461; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6923 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0003/

NetApp published this interim advisory covering CVE-2024-6923; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2024-45409 Ruby SAML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0008/

NetApp published this final advisory covering CVE-2024-45409; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2024-41721 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0009/

NetApp published this final advisory covering CVE-2024-41721; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-36902 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0002/

NetApp published this interim advisory covering CVE-2024-36902; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-34156 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0004/

NetApp published this final advisory covering CVE-2024-34156; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2024-34155 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0005/

NetApp published this interim advisory covering CVE-2024-34155; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2024-27399 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0001/

NetApp published this interim advisory covering CVE-2024-27399; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-30583 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0006/

NetApp published this final advisory covering CVE-2023-30583; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-30582 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0007/

NetApp published this final advisory covering CVE-2023-30582; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2024 FreeBSD ctl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0010/

NetApp published this final advisory covering CVE-2024-45063, CVE-2024-8178, CVE-2024-42416, CVE-2024-43110; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-8235 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0006/

NetApp published this interim advisory covering CVE-2024-8235; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-7006 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0001/

NetApp published this final advisory covering CVE-2024-7006; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-43790 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0005/

NetApp published this interim advisory covering CVE-2024-43790; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-43374 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0004/

NetApp published this interim advisory covering CVE-2024-43374; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-41928 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0009/

NetApp published this final advisory covering CVE-2024-41928; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-38809 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0003/

NetApp published this interim advisory covering CVE-2024-38809; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-38808 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0002/

NetApp published this interim advisory covering CVE-2024-38808; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-32668 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0007/

NetApp published this final advisory covering CVE-2024-32668; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-43102 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240916-0001/

NetApp published this final advisory covering CVE-2024-43102; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2024 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0005/

NetApp published this final advisory covering CVE-2024-28762, CVE-2024-31880, CVE-2024-31881; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00923 CSME Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0004/

NetApp published this interim advisory covering CVE-2023-28389, CVE-2023-32633; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2024-6119 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0001/

NetApp published this interim advisory covering CVE-2024-6119; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-36934 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0007/

NetApp published this interim advisory covering CVE-2024-36934; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36933 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0006/

NetApp published this interim advisory covering CVE-2024-36933; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9; SnapCenter Plug-in for VMware vSphere/BlueXP Backup and Recovery for Virtual Machine.

Open source
Advisory

CVE-2024-27398 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0012/

NetApp published this final advisory covering CVE-2024-27398; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-26900 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0011/

NetApp published this interim advisory covering CVE-2024-26900; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-52882 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0010/

NetApp published this interim advisory covering CVE-2023-52882; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-52585 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0009/

NetApp published this interim advisory covering CVE-2023-52585; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-37920 Certifi Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0002/

NetApp published this interim advisory covering CVE-2023-37920; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Mediator; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-48655 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0008/

NetApp published this final advisory covering CVE-2022-48655; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2024 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0003/

NetApp published this final advisory covering CVE-2024-37529, CVE-2024-35136, CVE-2024-35152, CVE-2024-31882; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-39684 RapidJSON Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0003/

NetApp published this final advisory covering CVE-2024-39684; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-38517 RapidJSON Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0001/

NetApp published this final advisory covering CVE-2024-38517; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2024-36929 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0010/

NetApp published this interim advisory covering CVE-2024-36929; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; SnapCenter Plug-in for VMware vSphere/BlueXP Backup and Recovery for Virtual Machine.

Open source
Advisory

CVE-2024-36919 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0009/

NetApp published this interim advisory covering CVE-2024-36919; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36916 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0006/

NetApp published this interim advisory covering CVE-2024-36916; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36905 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0005/

NetApp published this interim advisory covering CVE-2024-36905; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; SnapCenter Plug-in for VMware vSphere/BlueXP Backup and Recovery for Virtual Machine.

Open source
Advisory

CVE-2024-36904 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0004/

NetApp published this interim advisory covering CVE-2024-36904; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2024 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0007/

NetApp published this final advisory covering CVE-2024-41989, CVE-2024-41990, CVE-2024-41991, CVE-2024-42005; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2024 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0008/

NetApp published this final advisory covering CVE-2024-30260, CVE-2024-30261; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
AI

2026-09-02-we-are-going-to-deliver-strong-results-for-our-shareholders-netapp-ceo-george-ku

Source: https://news.google.com/rss/articles/CBMiW0FVX3lxTFBzd0drVlBSSVpqUWhvWERXWkJtSE8ydUxDeW50RzJmbVlRR09kQnRYNEIxNGd5S0JUQjlGRmFHZkVycU9TY24yaWVzVlE5U1I3Y1owS05VbE5fVWs?oc=5

Fox Business article from the NetApp NVIDIA Google News RSS feed. We are going to deliver strong results for our shareholders: NetApp CEO George Kurian - Fox Business. Auto-aggregated from public news sources. Refer to publisher for full text. Categorized as `ai` for the NetApp Black Box library.

Open source
Advisory

CVE-2024-7264 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0008/

NetApp published this interim advisory covering CVE-2024-7264; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-5971 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0001/

NetApp published this final advisory covering CVE-2024-5971; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-4693 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0007/

NetApp published this final advisory covering CVE-2024-4693; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-42154 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0010/

NetApp published this interim advisory covering CVE-2024-42154; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-38372 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0009/

NetApp published this final advisory covering CVE-2024-38372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-3653 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0002/

NetApp published this final advisory covering CVE-2024-3653; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-52433 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0003/

NetApp published this final advisory covering CVE-2023-52433; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-45744 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0006/

NetApp published this final advisory covering CVE-2023-45744; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-43491 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0005/

NetApp published this final advisory covering CVE-2023-43491; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29267 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0004/

NetApp published this final advisory covering CVE-2023-29267; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-7348 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0002/

NetApp published this final advisory covering CVE-2024-7348; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6874 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0004/

NetApp published this final advisory covering CVE-2024-6874; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-4467 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0005/

NetApp published this final advisory covering CVE-2024-4467; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-37891 urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0003/

NetApp published this interim advisory covering CVE-2024-37891; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-3596 RADIUS Protocol Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0001/

NetApp published this final advisory covering CVE-2024-3596; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2024-3567 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0007/

NetApp published this final advisory covering CVE-2024-3567; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-31870 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0006/

NetApp published this final advisory covering CVE-2024-31870; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-40146 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0008/

NetApp published this final advisory covering CVE-2023-40146; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-7589 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0002/

NetApp published this final advisory covering CVE-2024-7589; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6760 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0010/

NetApp published this final advisory covering CVE-2024-6760; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6759 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0009/

NetApp published this final advisory covering CVE-2024-6759; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6640 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0008/

NetApp published this final advisory covering CVE-2024-6640; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6505 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0006/

NetApp published this final advisory covering CVE-2024-6505; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-37280 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0003/

NetApp published this interim advisory covering CVE-2024-37280; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-34750 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0004/

NetApp published this interim advisory covering CVE-2024-34750; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-22018 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0007/

NetApp published this final advisory covering CVE-2024-22018; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-52340 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0005/

NetApp published this interim advisory covering CVE-2023-52340; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2018-19788 PolicyKit Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0001/

NetApp published this final advisory covering CVE-2018-19788; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2020-15999 Freetype Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240812-0001/

NetApp published this final advisory covering CVE-2020-15999; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

July 2024 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0005/

NetApp published this final advisory covering CVE-2024-38875, CVE-2024-39329, CVE-2024-39330, CVE-2024-39614; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6716 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0010/

NetApp published this final advisory covering CVE-2024-6716; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-40898 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0006/

NetApp published this interim advisory covering CVE-2024-40898; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-32007 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0009/

NetApp published this interim advisory covering CVE-2024-32007; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 10; OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

CVE-2024-0684 GNU Coreutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0001/

NetApp published this interim advisory covering CVE-2024-0684; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-39333 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0004/

NetApp published this final advisory covering CVE-2023-39333; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23358 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0003/

NetApp published this final advisory covering CVE-2021-23358; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-41110 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240802-0001/

NetApp published this final advisory covering CVE-2024-41110; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2024 MySQL Server 8.0.37 and 8.4.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240801-0001/

NetApp published this interim advisory covering CVE-2024-20996, CVE-2024-21125, CVE-2024-21127, CVE-2024-21129, CVE-2024-21130, CVE-2024-21134, CVE-2024-21142, CVE-2024-21162, CVE-2024-21163, CVE-2024-21171, CVE-2024-21173, CVE-2024-21177, CVE-2024-21179; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2024 MySQL Server 8.0.36 and 8.3.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240801-0002/

NetApp published this interim advisory covering CVE-2024-21135, CVE-2024-21159, CVE-2024-21160, CVE-2024-21166; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-4076 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0001/

NetApp published this interim advisory covering CVE-2024-4076; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-21176 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0006/

NetApp published this interim advisory covering CVE-2024-21176; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-21165 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0007/

NetApp published this interim advisory covering CVE-2024-21165; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2024-21157 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0008/

NetApp published this interim advisory covering CVE-2024-21157; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-21137 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0009/

NetApp published this interim advisory covering CVE-2024-21137; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-1975 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0002/

NetApp published this interim advisory covering CVE-2024-1975; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-1737 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0003/

NetApp published this interim advisory covering CVE-2024-1737; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-0760 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0004/

NetApp published this final advisory covering CVE-2024-0760; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-5642 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240726-0005/

NetApp published this interim advisory covering CVE-2024-5642; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-5585 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240726-0002/

NetApp published this final advisory covering CVE-2024-5585; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-4032 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240726-0004/

NetApp published this interim advisory covering CVE-2024-4032; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

July 2024 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0008/

NetApp published this interim advisory covering CVE-2024-21131, CVE-2024-21138, CVE-2024-21140, CVE-2024-21145, CVE-2024-21147; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-37894 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0001/

NetApp published this final advisory covering CVE-2024-37894; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21144 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0007/

NetApp published this interim advisory covering CVE-2024-21144; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); OnCommand Workflow Automation.

Open source
Advisory

CVE-2019-17626 ReportLab Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0006/

NetApp published this final advisory covering CVE-2019-17626; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2016-3751 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0004/

NetApp published this final advisory covering CVE-2016-3751; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2015-0973 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0005/

NetApp published this final advisory covering CVE-2015-0973; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2014-9515 Dozer Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0002/

NetApp published this final advisory covering CVE-2014-9515; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2024 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240712-0001/

NetApp published this final advisory covering CVE-2024-36387, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9.

Open source
Advisory

CVE-2024-6409 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240712-0003/

NetApp published this interim advisory covering CVE-2024-6409; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-5535 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240712-0005/

NetApp published this interim advisory covering CVE-2024-5535; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-39894 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240712-0004/

NetApp published this interim advisory covering CVE-2024-39894; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-4030 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240705-0005/

NetApp published this final advisory covering CVE-2024-4030; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-37051 JetBrains IDE Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20240705-0004/

NetApp published this final advisory covering CVE-2024-37051; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-32962 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240705-0003/

NetApp published this final advisory covering CVE-2024-32962; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-27309 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240705-0002/

NetApp published this final advisory covering CVE-2024-27309; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1931 Unbound Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240705-0006/

NetApp published this final advisory covering CVE-2024-1931; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6387 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240701-0001/

NetApp published this interim advisory covering CVE-2024-6387; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-6240 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240628-0002/

NetApp published this interim advisory covering CVE-2023-6240; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-36665 Protobuf.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240628-0006/

NetApp published this final advisory covering CVE-2023-36665; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1227 Podman Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240628-0001/

NetApp published this final advisory covering CVE-2022-1227; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2024 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0007/

NetApp published this final advisory covering CVE-2023-44981, CVE-2023-44487, CVE-2023-5072, CVE-2023-34462, CVE-2024-25047, CVE-2022-23540, CVE-2022-23541, CVE-2022-23539, CVE-2023-31484, CVE-2020-15366, CVE-2021-28363; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

February 2024 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0006/

NetApp published this final advisory covering CVE-2021-31684, CVE-2023-1370, CVE-2023-0464, CVE-2021-35550, CVE-2021-35560, CVE-2021-35586, CVE-2021-35578, CVE-2021-35564, CVE-2021-35559, CVE-2021-35556, CVE-2021-35565, CVE-2021-35588, CVE-2021-41035, CVE-2021-44906, CVE-2021-28167, CVE-2023-38359, CVE-2023-32344, CVE-2022-21299, CVE-2023-30996, CVE-2022-21496, CVE-2022-21434, CVE-2022-21443, CVE-2023-3817, CVE-2023-39410, CVE-2020-28458, CVE-2021-23445, CVE-2023-26136, CVE-2021-3572, CVE-2023-21930, CVE-2023-21967, CVE-2023-21954, CVE-2023-21939, CVE-2023-21968, CVE-2023-21937, CVE-2023-21938, CVE-2023-2597, CVE-2018-8032, CVE-2019-0227, CVE-2022-34357, CVE-2023-30588, CVE-2023-30589, CVE-2019-1547, CVE-2020-1971, CVE-2021-23839, CVE-2021-23840, CVE-2021-23841, CVE-2021-3449, CVE-2021-3711, CVE-2021-3712, CVE-2021-4160, CVE-2022-0778, CVE-2022-2097, CVE-2021-35603, CVE-2023-26115, CVE-2021-43138, CVE-2022-1471, CVE-2023-36478, CVE-2023-44487, CVE-2022-40897, CVE-2022-34169, CVE-2022-41854, CVE-2023-0215, CVE-2023-43051, CVE-2023-22049, CVE-2023-45857; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2024-4741 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0004/

NetApp published this interim advisory covering CVE-2024-4741; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-4603 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0001/

NetApp published this interim advisory covering CVE-2024-4603; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-4577 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0008/

NetApp published this final advisory covering CVE-2024-4577; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3080 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0002/

NetApp published this interim advisory covering CVE-2022-3080; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

May 2024 Bouncy Castle Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0007/

NetApp published this interim advisory covering CVE-2024-34447, CVE-2024-30172; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Console; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2024-34069 Werkzeug Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0004/

NetApp published this final advisory covering CVE-2024-34069; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-30171 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0008/

NetApp published this interim advisory covering CVE-2024-30171; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Console; ONTAP tools for VMware vSphere 9; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-2877 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0002/

NetApp published this interim advisory covering CVE-2024-2877; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22233 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0005/

NetApp published this final advisory covering CVE-2024-22233; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1086 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0009/

NetApp published this final advisory covering CVE-2024-1086; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-52425 libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0003/

NetApp published this interim advisory covering CVE-2023-52425; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; OnCommand Workflow Automation; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2022-4967 strongSwan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0006/

NetApp published this final advisory covering CVE-2022-4967; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-33883 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0003/

NetApp published this final advisory covering CVE-2024-33883; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-32487 less Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0009/

NetApp published this interim advisory covering CVE-2024-32487; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-24806 libuv Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0008/

NetApp published this final advisory covering CVE-2024-24806; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-24788 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0002/

NetApp published this final advisory covering CVE-2024-24788; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Astra Control Provisioner; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator; Trident; Trident Autosupport.

Open source
Advisory

CVE-2023-32067 c-ares Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0004/

NetApp published this interim advisory covering CVE-2023-32067; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-31130 c-ares Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0005/

NetApp published this interim advisory covering CVE-2023-31130; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-23913 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0007/

NetApp published this final advisory covering CVE-2023-23913; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-20569 Debian Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0006/

NetApp published this interim advisory covering CVE-2023-20569; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-48624 less Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0010/

NetApp published this final advisory covering CVE-2022-48624; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-34397 Gnome Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0008/

NetApp published this final advisory covering CVE-2024-34397; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2961 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0002/

NetApp published this interim advisory covering CVE-2024-2961; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-28085 Util-linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0003/

NetApp published this interim advisory covering CVE-2024-28085; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24787 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0006/

NetApp published this final advisory covering CVE-2024-24787; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2379 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0001/

NetApp published this interim advisory covering CVE-2024-2379; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-6237 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0007/

NetApp published this interim advisory covering CVE-2023-6237; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-20593 Debian Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0004/

NetApp published this final advisory covering CVE-2023-20593; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-20588 Debian Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0005/

NetApp published this final advisory covering CVE-2023-20588; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-33602 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0012/

NetApp published this interim advisory covering CVE-2024-33602; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-33601 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0014/

NetApp published this interim advisory covering CVE-2024-33601; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-33600 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0013/

NetApp published this interim advisory covering CVE-2024-33600; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-33599 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0011/

NetApp published this interim advisory covering CVE-2024-33599; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-28863 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0005/

NetApp published this final advisory covering CVE-2024-28863; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-28834 GNU TLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0004/

NetApp published this interim advisory covering CVE-2024-28834; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Converged Systems Advisor Agent; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-2660 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0007/

NetApp published this interim advisory covering CVE-2024-2660; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22262 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0003/

NetApp published this final advisory covering CVE-2024-22262; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-22259 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0002/

NetApp published this final advisory covering CVE-2024-22259; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-22243 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0001/

NetApp published this final advisory covering CVE-2024-22243; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-2048 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0009/

NetApp published this final advisory covering CVE-2024-2048; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2004 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0006/

NetApp published this interim advisory covering CVE-2024-2004; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-1313 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0008/

NetApp published this final advisory covering CVE-2024-1313; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-20863 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0015/

NetApp published this final advisory covering CVE-2023-20863; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2024-28752 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0001/

NetApp published this final advisory covering CVE-2024-28752; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-25046 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0005/

NetApp published this final advisory covering CVE-2024-25046; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-25030 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0006/

NetApp published this final advisory covering CVE-2024-25030; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2494 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0009/

NetApp published this interim advisory covering CVE-2024-2494; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-23450 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0010/

NetApp published this interim advisory covering CVE-2024-23450; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22025 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0008/

NetApp published this final advisory covering CVE-2024-22025; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22017 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0007/

NetApp published this final advisory covering CVE-2024-22017; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2024 IBM DB2 11.5 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0003/

NetApp published this final advisory covering CVE-2024-22360, CVE-2023-52296; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2024 IBM DB2 10.5, 11.1, and 11.5 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0004/

NetApp published this final advisory covering CVE-2023-38729, CVE-2024-27254; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-3096 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0010/

NetApp published this final advisory covering CVE-2024-3096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2757 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0011/

NetApp published this final advisory covering CVE-2024-2757; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26146 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0006/

NetApp published this final advisory covering CVE-2024-26146; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26144 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0013/

NetApp published this final advisory covering CVE-2024-26144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26143 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0004/

NetApp published this final advisory covering CVE-2024-26143; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26141 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0007/

NetApp published this final advisory covering CVE-2024-26141; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-25941 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0003/

NetApp published this final advisory covering CVE-2024-25941; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-25126 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0005/

NetApp published this final advisory covering CVE-2024-25126; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24474 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0012/

NetApp published this final advisory covering CVE-2024-24474; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1874 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0009/

NetApp published this final advisory covering CVE-2024-1874; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29483 Dnspython Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0001/

NetApp published this interim advisory covering CVE-2023-29483; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-26142 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0003/

NetApp published this final advisory covering CVE-2024-26142; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2511 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0013/

NetApp published this interim advisory covering CVE-2024-2511; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-2466 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0010/

NetApp published this final advisory covering CVE-2024-2466; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-2398 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0009/

NetApp published this interim advisory covering CVE-2024-2398; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-21885 X.Org X Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0004/

NetApp published this final advisory covering CVE-2024-21885; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-0853 MySQL Enterprise Backup Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0012/

NetApp published this final advisory covering CVE-2024-0853; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6516 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0008/

NetApp published this final advisory covering CVE-2023-6516; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-6129 MySQL Enterprise Backup Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0011/

NetApp published this final advisory covering CVE-2023-6129; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5680 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0005/

NetApp published this interim advisory covering CVE-2023-5680; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-5517 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0006/

NetApp published this final advisory covering CVE-2023-5517; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-5123 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0007/

NetApp published this final advisory covering CVE-2023-5123; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5122 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0002/

NetApp published this final advisory covering CVE-2023-5122; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3010 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0001/

NetApp published this final advisory covering CVE-2023-3010; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2312 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0003/

NetApp published this final advisory covering CVE-2024-2312; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-21015 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0010/

NetApp published this interim advisory covering CVE-2024-21015; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-0853 MySQL Cluster Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0009/

NetApp published this final advisory covering CVE-2024-0853; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5679 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0002/

NetApp published this interim advisory covering CVE-2023-5679; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-44487 MySQL Cluster Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0007/

NetApp published this final advisory covering CVE-2023-44487; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-4408 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0001/

NetApp published this final advisory covering CVE-2023-4408; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2023-32665 Gnome Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0006/

NetApp published this interim advisory covering CVE-2023-32665; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2023-32643 Gnome Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0005/

NetApp published this final advisory covering CVE-2023-32643; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

April 2024 MySQL Server 8.0.36 and 8.3.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0013/

NetApp published this interim advisory covering CVE-2023-6129, CVE-2024-20994, CVE-2024-20998, CVE-2024-21000, CVE-2024-21008, CVE-2024-21009, CVE-2024-21013, CVE-2024-21047, CVE-2024-21054, CVE-2024-21060, CVE-2024-21062, CVE-2024-21069, CVE-2024-21087, CVE-2024-21096, CVE-2024-21102; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2024 MySQL Server 8.0.35 and 8.2.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0014/

NetApp published this interim advisory covering CVE-2024-20993, CVE-2024-21061; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2024 MySQL Server 8.0.35 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0011/

NetApp published this interim advisory covering CVE-2024-21055, CVE-2024-21057; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2024 MySQL Server 8.0.34 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0012/

NetApp published this interim advisory covering CVE-2024-21049, CVE-2024-21050, CVE-2024-21051, CVE-2024-21052, CVE-2024-21053, CVE-2024-21056; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

April 2024 MySQL Cluster Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0015/

NetApp published this final advisory covering CVE-2024-21101, CVE-2024-21102; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2024 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0004/

NetApp published this interim advisory covering CVE-2023-41993, CVE-2024-21002, CVE-2024-21003, CVE-2024-21004, CVE-2024-21005, CVE-2024-21011, CVE-2024-21012, CVE-2024-21068, CVE-2024-21085, CVE-2024-21094; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

February 2024 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0010/

NetApp published this final advisory covering CVE-2024-26327, CVE-2024-26328; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-25940 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0004/

NetApp published this final advisory covering CVE-2024-25940; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24758 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0007/

NetApp published this interim advisory covering CVE-2024-24758; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24750 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0006/

NetApp published this interim advisory covering CVE-2024-24750; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22257 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0005/

NetApp published this final advisory covering CVE-2024-22257; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-1597 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0008/

NetApp published this final advisory covering CVE-2024-1597; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-51780 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0001/

NetApp published this final advisory covering CVE-2023-51780; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-45288 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0009/

NetApp published this final advisory covering CVE-2023-45288; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Provisioner; Trident; Trident Autosupport.

Open source
Advisory

CVE-2022-23086 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0002/

NetApp published this final advisory covering CVE-2022-23086; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23084 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0003/

NetApp published this final advisory covering CVE-2022-23084; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26462 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0012/

NetApp published this interim advisory covering CVE-2024-26462; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-26461 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0011/

NetApp published this interim advisory covering CVE-2024-26461; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-26458 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0010/

NetApp published this interim advisory covering CVE-2024-26458; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-6536 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0001/

NetApp published this final advisory covering CVE-2023-6536; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-6535 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0003/

NetApp published this interim advisory covering CVE-2023-6535; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-6356 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0002/

NetApp published this final advisory covering CVE-2023-6356; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2022-4289 GitLab Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0004/

NetApp published this interim advisory covering CVE-2022-4289; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23092 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0009/

NetApp published this final advisory covering CVE-2022-23092; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23091 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0008/

NetApp published this final advisory covering CVE-2022-23091; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23090 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0007/

NetApp published this final advisory covering CVE-2022-23090; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23089 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0006/

NetApp published this final advisory covering CVE-2022-23089; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23087 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0005/

NetApp published this final advisory covering CVE-2022-23087; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2024 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0013/

NetApp published this final advisory covering CVE-2024-27316, CVE-2024-24795, CVE-2023-38709; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-35191 Intel SPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240405-0005/

NetApp published this interim advisory covering CVE-2023-35191; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Advisory

March 2024 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240402-0002/

NetApp published this final advisory covering CVE-2024-23672, CVE-2024-24549; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-3094 XZ Utils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240402-0001/

NetApp published this final advisory covering CVE-2024-3094; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24785 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0008/

NetApp published this final advisory covering CVE-2024-24785; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24784 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0007/

NetApp published this final advisory covering CVE-2024-24784; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24783 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0005/

NetApp published this final advisory covering CVE-2024-24783; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2024-22201 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0001/

NetApp published this interim advisory covering CVE-2024-22201; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-21896 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0002/

NetApp published this final advisory covering CVE-2024-21896; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-45290 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0004/

NetApp published this final advisory covering CVE-2023-45290; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-41946 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0003/

NetApp published this final advisory covering CVE-2022-41946; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-28757 libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0001/

NetApp published this interim advisory covering CVE-2024-28757; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; OnCommand Workflow Automation; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2024-21892 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0003/

NetApp published this final advisory covering CVE-2024-21892; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1635 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0007/

NetApp published this interim advisory covering CVE-2024-1635; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-6660 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0002/

NetApp published this final advisory covering CVE-2023-6660; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29153 Intel SPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0005/

NetApp published this interim advisory covering CVE-2023-29153; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2022-23085 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0004/

NetApp published this final advisory covering CVE-2022-23085; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

SnakeYAML 1.32 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0009/

NetApp published this interim advisory covering CVE-2022-38752, CVE-2022-41854; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

SnakeYAML 1.31 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0010/

NetApp published this interim advisory covering CVE-2022-38749, CVE-2022-38751, CVE-2022-38750, CVE-2022-25857; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-22234 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0003/

NetApp published this interim advisory covering CVE-2024-22234; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21891 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0005/

NetApp published this final advisory covering CVE-2024-21891; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21890 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0002/

NetApp published this interim advisory covering CVE-2024-21890; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-0232 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0007/

NetApp published this interim advisory covering CVE-2024-0232; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-42282 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0008/

NetApp published this final advisory covering CVE-2023-42282; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-25147 Apache Portable Runtime (APR) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0001/

NetApp published this final advisory covering CVE-2022-25147; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

October 2023 Ingress nginx Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0012/

NetApp published this final advisory covering CVE-2023-5043, CVE-2023-5044; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 X.Org X Server 21.1.11 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0006/

NetApp published this final advisory covering CVE-2024-0408, CVE-2024-0409, CVE-2023-6816; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 Tianocore EDK2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0011/

NetApp published this final advisory covering CVE-2023-45229, CVE-2023-45230, CVE-2023-45231, CVE-2023-45232, CVE-2023-45233, CVE-2023-45234, CVE-2023-45235, CVE-2023-45236, CVE-2023-45237; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 IBM DB2 11.5 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0001/

NetApp published this final advisory covering CVE-2023-47141, CVE-2023-47152, CVE-2023-45193, CVE-2023-50308; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 IBM DB2 10.5, 11.1, 11.5 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0003/

NetApp published this final advisory covering CVE-2023-47145, CVE-2023-47746; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 IBM DB2 10.1, 10.5, 11.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0002/

NetApp published this final advisory covering CVE-2023-27859, CVE-2023-47158, CVE-2023-47747; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26308 Apache Commons Compress Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0009/

NetApp published this interim advisory covering CVE-2024-26308; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); NetApp Console.

Open source
Advisory

CVE-2024-25710 Apache Commons Compress Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0010/

NetApp published this interim advisory covering CVE-2024-25710; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); NetApp Console.

Open source
Advisory

CVE-2024-0853 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0004/

NetApp published this interim advisory covering CVE-2024-0853; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; ONTAP 9.

Open source
Advisory

CVE-2023-52426 libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0005/

NetApp published this interim advisory covering CVE-2023-52426; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); OnCommand Workflow Automation; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2023-50868 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0008/

NetApp published this interim advisory covering CVE-2023-50868; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-50387 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0007/

NetApp published this interim advisory covering CVE-2023-50387; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-4886 Ingress nginx Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0013/

NetApp published this final advisory covering CVE-2022-4886; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46672 Logstash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240229-0001/

NetApp published this final advisory covering CVE-2023-46672; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2861 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240229-0002/

NetApp published this final advisory covering CVE-2023-2861; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22667 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0008/

NetApp published this final advisory covering CVE-2024-22667; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-1048 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0007/

NetApp published this final advisory covering CVE-2024-1048; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-0831 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0005/

NetApp published this interim advisory covering CVE-2024-0831; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-0565 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0002/

NetApp published this interim advisory covering CVE-2024-0565; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-6779 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0006/

NetApp published this interim advisory covering CVE-2023-6779; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-6683 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0001/

NetApp published this final advisory covering CVE-2023-6683; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6004 libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0004/

NetApp published this interim advisory covering CVE-2023-6004; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-41056 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0003/

NetApp published this final advisory covering CVE-2023-41056; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2024-22207 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0002/

NetApp published this interim advisory covering CVE-2024-22207; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21733 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0005/

NetApp published this interim advisory covering CVE-2024-21733; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6246 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0007/

NetApp published this interim advisory covering CVE-2023-6246; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-6129 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0009/

NetApp published this interim advisory covering CVE-2023-6129; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-49238 Gradle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0003/

NetApp published this final advisory covering CVE-2023-49238; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4001 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0006/

NetApp published this final advisory covering CVE-2023-4001; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-45047 Apache MINA SSHD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0008/

NetApp published this final advisory covering CVE-2022-45047; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-41678 Apache ActiveMQ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0004/

NetApp published this interim advisory covering CVE-2022-41678; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; E-Series SANtricity Unified Manager and Web Services Proxy; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2020-1745 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0011/

NetApp published this final advisory covering CVE-2020-1745; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Service Level Manager; OnCommand Workflow Automation.

Open source
Advisory

CVE-2015-7501 Redhat JBoss Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0010/

NetApp published this interim advisory covering CVE-2015-7501; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-23638 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0010/

NetApp published this final advisory covering CVE-2024-23638; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21312 .NET Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0008/

NetApp published this final advisory covering CVE-2024-21312; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-0727 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0006/

NetApp published this interim advisory covering CVE-2024-0727; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; ONTAP 9; ONTAP Select Deploy administration utility; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-0057 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0007/

NetApp published this final advisory covering CVE-2024-0057; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-7090 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0001/

NetApp published this final advisory covering CVE-2023-7090; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-6693 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0004/

NetApp published this final advisory covering CVE-2023-6693; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-47039 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0005/

NetApp published this final advisory covering CVE-2023-47039; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); SRA Plugin for Linux.

Open source
Advisory

CVE-2023-42465 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0002/

NetApp published this final advisory covering CVE-2023-42465; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2021-44528 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0003/

NetApp published this final advisory covering CVE-2021-44528; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 GnuTLS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0011/

NetApp published this interim advisory covering CVE-2024-0567, CVE-2024-0553; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-3863 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0002/

NetApp published this interim advisory covering CVE-2023-3863; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3776 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0003/

NetApp published this final advisory covering CVE-2023-3776; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-34319 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0001/

NetApp published this final advisory covering CVE-2023-34319; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-28120 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0006/

NetApp published this final advisory covering CVE-2023-28120; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22796 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0009/

NetApp published this final advisory covering CVE-2023-22796; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22795 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0010/

NetApp published this final advisory covering CVE-2023-22795; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22794 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0008/

NetApp published this final advisory covering CVE-2023-22794; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22792 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0007/

NetApp published this final advisory covering CVE-2023-22792; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2002 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0004/

NetApp published this interim advisory covering CVE-2023-2002; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-22942 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0005/

NetApp published this final advisory covering CVE-2021-22942; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 MySQL Server 8.0.35 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0003/

NetApp published this final advisory covering CVE-2023-5363, CVE-2024-20960, CVE-2024-20961, CVE-2024-20962, CVE-2024-20963, CVE-2024-20964, CVE-2024-20965, CVE-2024-20966, CVE-2024-20967, CVE-2024-20969, CVE-2024-20970, CVE-2024-20971, CVE-2024-20972, CVE-2024-20973, CVE-2024-20974, CVE-2024-20976, CVE-2024-20977, CVE-2024-20978, CVE-2024-20981, CVE-2024-20982, CVE-2024-20984, CVE-2024-20985; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2024 MySQL Server 8.0.34 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0008/

NetApp published this final advisory covering CVE-2023-39975, CVE-2024-20968; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2024 MySQL Cluster Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0005/

NetApp published this final advisory covering CVE-2023-2283, CVE-2023-28484, CVE-2023-38545, CVE-2023-39975; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0002/

NetApp published this interim advisory covering CVE-2024-20918, CVE-2024-20919, CVE-2024-20921, CVE-2024-20922, CVE-2024-20923, CVE-2024-20925, CVE-2024-20926, CVE-2024-20932, CVE-2024-20945, CVE-2024-20952; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2024-20983 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0009/

NetApp published this interim advisory covering CVE-2024-20983; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2024-20975 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0007/

NetApp published this interim advisory covering CVE-2024-20975; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-20965 MySQL Cluster Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0006/

NetApp published this final advisory covering CVE-2024-20965; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-31248 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0001/

NetApp published this final advisory covering CVE-2023-31248; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

December 2023 X.Org X Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0003/

NetApp published this final advisory covering CVE-2023-6377, CVE-2023-6478; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2023 Infinispan Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0004/

NetApp published this interim advisory covering CVE-2023-5236, CVE-2023-3629, CVE-2023-5384, CVE-2023-3628; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-51767 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0006/

NetApp published this final advisory covering CVE-2023-51767; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4806 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0008/

NetApp published this interim advisory covering CVE-2023-4806; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-46672 Logstash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0002/

NetApp published this final advisory covering CVE-2023-46672; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46218 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0007/

NetApp published this interim advisory covering CVE-2023-46218; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-33202 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0001/

NetApp published this interim advisory covering CVE-2023-33202; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp Console; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2023-2861 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0005/

NetApp published this interim advisory covering CVE-2023-2861; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2023 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0004/

NetApp published this final advisory covering CVE-2023-49285, CVE-2023-49286; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp BlueXP.

Open source
Advisory

December 2023 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0003/

NetApp published this final advisory covering CVE-2023-5868, CVE-2023-5869, CVE-2023-5870; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

December 2023 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0001/

NetApp published this final advisory covering CVE-2023-38003, CVE-2023-38727, CVE-2023-40687, CVE-2023-40692, CVE-2023-47701; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6277 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0002/

NetApp published this interim advisory covering CVE-2023-6277; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5528 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0009/

NetApp published this final advisory covering CVE-2023-5528; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-50495 GNU Ncurses Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0008/

NetApp published this interim advisory covering CVE-2023-50495; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-50269 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0005/

NetApp published this final advisory covering CVE-2023-50269; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-49288 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0006/

NetApp published this final advisory covering CVE-2023-49288; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46219 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0007/

NetApp published this interim advisory covering CVE-2023-46219; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-21400 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0012/

NetApp published this interim advisory covering CVE-2023-21400; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-21255 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0010/

NetApp published this final advisory covering CVE-2023-21255; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-2007 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0011/

NetApp published this final advisory covering CVE-2023-2007; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-23633 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0013/

NetApp published this final advisory covering CVE-2022-23633; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-7104 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0008/

NetApp published this interim advisory covering CVE-2023-7104; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-6534 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0007/

NetApp published this final advisory covering CVE-2023-6534; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6337 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0006/

NetApp published this final advisory covering CVE-2023-6337; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46167 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0003/

NetApp published this final advisory covering CVE-2023-46167; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-45287 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0005/

NetApp published this final advisory covering CVE-2023-45287; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident Autosupport; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-45178 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0004/

NetApp published this final advisory covering CVE-2023-45178; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29258 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0002/

NetApp published this final advisory covering CVE-2023-29258; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-26031 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0001/

NetApp published this final advisory covering CVE-2023-26031; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 OpenSSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240105-0005/

NetApp published this interim advisory covering CVE-2023-51384, CVE-2023-51385; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-48795 SSH Protocol Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240105-0004/

NetApp published this interim advisory covering CVE-2023-48795; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; Element Plug-in for vCenter Server; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; StorageGRID (formerly StorageGRID Webscale); Terraform Provider for ONTAP.

Open source
Advisory

CVE-2023-48706 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240105-0001/

NetApp published this interim advisory covering CVE-2023-48706; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-40238 InsydeH2O Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240105-0002/

NetApp published this final advisory covering CVE-2023-40238; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

AMI AptioV SA-2023009 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240105-0003/

NetApp published this final advisory covering CVE-2023-39538, CVE-2023-39539; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5954 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0001/

NetApp published this final advisory covering CVE-2023-5954; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-48237 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0005/

NetApp published this interim advisory covering CVE-2023-48237; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-48236 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0002/

NetApp published this interim advisory covering CVE-2023-48236; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-48235 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0007/

NetApp published this interim advisory covering CVE-2023-48235; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-48234 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0004/

NetApp published this interim advisory covering CVE-2023-48234; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-48233 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0003/

NetApp published this interim advisory covering CVE-2023-48233; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-48232 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0006/

NetApp published this interim advisory covering CVE-2023-48232; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-48231 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0008/

NetApp published this interim advisory covering CVE-2023-48231; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2019-3773 Spring Web Services Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0011/

NetApp published this final advisory covering CVE-2019-3773; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-10158 Infinispan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0009/

NetApp published this final advisory covering CVE-2019-10158; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-8088 SLF4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0010/

NetApp published this final advisory covering CVE-2018-8088; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

November 2023 AsyncSSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231222-0001/

NetApp published this final advisory covering CVE-2023-46445, CVE-2023-46446; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Converged Systems Advisor Agent.

Open source
Advisory

CVE-2023-4809 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0009/

NetApp published this final advisory covering CVE-2023-4809; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-43665 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0001/

NetApp published this final advisory covering CVE-2023-43665; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3955 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0002/

NetApp published this final advisory covering CVE-2023-3955; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3893 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0004/

NetApp published this final advisory covering CVE-2023-3893; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-34055 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0010/

NetApp published this final advisory covering CVE-2023-34055; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28376 Intel Ethernet Controller Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0007/

NetApp published this final advisory covering CVE-2023-28376; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1194 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0006/

NetApp published this interim advisory covering CVE-2023-1194; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-3172 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0005/

NetApp published this final advisory covering CVE-2022-3172; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-25736 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0003/

NetApp published this final advisory covering CVE-2021-25736; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5978 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0003/

NetApp published this final advisory covering CVE-2023-5978; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5941 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0004/

NetApp published this final advisory covering CVE-2023-5941; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-50164 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0010/

NetApp published this final advisory covering CVE-2023-50164; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46848 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0005/

NetApp published this final advisory covering CVE-2023-46848; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46728 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0006/

NetApp published this final advisory covering CVE-2023-46728; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46695 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0001/

NetApp published this final advisory covering CVE-2023-46695; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-45283 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0008/

NetApp published this final advisory covering CVE-2023-45283; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Cloud Insights Telegraf Agent; NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2023-41164 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0002/

NetApp published this final advisory covering CVE-2023-41164; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-34053 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0007/

NetApp published this final advisory covering CVE-2023-34053; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2023 Supermicro BMC Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0009/

NetApp published this final advisory covering CVE-2023-40284, CVE-2023-40285, CVE-2023-40286, CVE-2023-40287, CVE-2023-40288, CVE-2023-40289, CVE-2023-40290; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

October 2023 Grub Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0002/

NetApp published this final advisory covering CVE-2023-4692, CVE-2023-4693; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-5178 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0004/

NetApp published this interim advisory covering CVE-2023-5178; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-5088 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0005/

NetApp published this final advisory covering CVE-2023-5088; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46724 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0001/

NetApp published this final advisory covering CVE-2023-46724; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46246 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0006/

NetApp published this interim advisory covering CVE-2023-46246; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4399 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0003/

NetApp published this final advisory covering CVE-2023-4399; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-34969 D-Bus Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0007/

NetApp published this interim advisory covering CVE-2023-34969; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS; NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-3138 libX11 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0008/

NetApp published this interim advisory covering CVE-2023-3138; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-27539 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0016/

NetApp published this final advisory covering CVE-2023-27539; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-27530 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0015/

NetApp published this final advisory covering CVE-2023-27530; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-44572 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0014/

NetApp published this final advisory covering CVE-2022-44572; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-44571 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0013/

NetApp published this final advisory covering CVE-2022-44571; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-44570 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0010/

NetApp published this final advisory covering CVE-2022-44570; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-30123 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0011/

NetApp published this final advisory covering CVE-2022-30123; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-30122 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0012/

NetApp published this final advisory covering CVE-2022-30122; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2023 X.Org X Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0004/

NetApp published this final advisory covering CVE-2023-5574, CVE-2023-5367, CVE-2023-5380; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2023 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0002/

NetApp published this final advisory covering CVE-2023-46847, CVE-2023-46846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5824 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0003/

NetApp published this final advisory covering CVE-2023-5824; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5678 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0010/

NetApp published this interim advisory covering CVE-2023-5678; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-45853 Zlib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0009/

NetApp published this interim advisory covering CVE-2023-45853; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4163 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20231130-0001/

NetApp published this final advisory covering CVE-2023-4163; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2023-3676 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0007/

NetApp published this final advisory covering CVE-2023-3676; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-31418 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0005/

NetApp published this final advisory covering CVE-2023-31418; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-31417 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0006/

NetApp published this final advisory covering CVE-2023-31417; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-4900 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0008/

NetApp published this final advisory covering CVE-2022-4900; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2023 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231124-0002/

NetApp published this final advisory covering CVE-2023-3961, CVE-2023-4154, CVE-2023-4091, CVE-2023-42669, CVE-2023-42670; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2023-5568 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231124-0007/

NetApp published this final advisory covering CVE-2023-5568; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5370 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231124-0005/

NetApp published this final advisory covering CVE-2023-5370; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5369 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231124-0009/

NetApp published this final advisory covering CVE-2023-5369; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5368 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231124-0004/

NetApp published this final advisory covering CVE-2023-5368; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46136 Werkzeug Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231124-0008/

NetApp published this final advisory covering CVE-2023-46136; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-4162 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20231124-0010/

NetApp published this final advisory covering CVE-2023-4162; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3489 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20231124-0003/

NetApp published this final advisory covering CVE-2023-3489; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2023-32252 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231124-0001/

NetApp published this final advisory covering CVE-2023-32252; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

October 2023 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0009/

NetApp published this final advisory covering CVE-2023-39331, CVE-2023-39332; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2023 IBM DB2 11.5.x Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0007/

NetApp published this final advisory covering CVE-2023-40372, CVE-2023-38740, CVE-2023-40374; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2023 IBM DB2 11.1.4.x and 11.5.x Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0005/

NetApp published this final advisory covering CVE-2023-38720, CVE-2023-30991; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2023 IBM DB2 10.5.0.x, 11.1.4.x, and 11.5.x Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0006/

NetApp published this final advisory covering CVE-2023-40373, CVE-2023-38728, CVE-2023-30987; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-45862 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0004/

NetApp published this interim advisory covering CVE-2023-45862; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-4527 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0012/

NetApp published this interim advisory covering CVE-2023-4527; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-45145 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0014/

NetApp published this interim advisory covering CVE-2023-45145; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2023-44466 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0003/

NetApp published this interim advisory covering CVE-2023-44466; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-38719 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0008/

NetApp published this final advisory covering CVE-2023-38719; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38552 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0013/

NetApp published this final advisory covering CVE-2023-38552; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-31419 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0010/

NetApp published this final advisory covering CVE-2023-31419; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2680 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0001/

NetApp published this final advisory covering CVE-2023-2680; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-23583 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0015/

NetApp published this interim advisory covering CVE-2023-23583; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - 2820; FAS/AFF BIOS - A900/9500; NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2022-48554 File Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0002/

NetApp published this final advisory covering CVE-2022-48554; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2023 Gradle Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0006/

NetApp published this final advisory covering CVE-2023-42445, CVE-2023-44387; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

October 2023 7-Zip Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0007/

NetApp published this final advisory covering CVE-2023-31102, CVE-2023-40481; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-4813 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0003/

NetApp published this interim advisory covering CVE-2023-4813; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-46604 Apache ActiveMQ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0010/

NetApp published this final advisory covering CVE-2023-46604; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Unified Manager and Web Services Proxy; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2023-45871 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0001/

NetApp published this final advisory covering CVE-2023-45871; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-40791 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0009/

NetApp published this interim advisory covering CVE-2023-40791; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-40745 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0005/

NetApp published this final advisory covering CVE-2023-40745; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-39325 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0008/

NetApp published this final advisory covering CVE-2023-39325; the API labels exploitation information as **Public**. The API currently lists affected products as: Trident; Trident Autosupport.

Open source
Advisory

CVE-2023-32636 Gnome Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0002/

NetApp published this final advisory covering CVE-2023-32636; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2023 GNU Binutils 2.40 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0003/

NetApp published this final advisory covering CVE-2023-25588, CVE-2023-25585, CVE-2023-25586; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

October 2023 libX11 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0006/

NetApp published this interim advisory covering CVE-2023-43785, CVE-2023-43786, CVE-2023-43787; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux.

Open source
Advisory

October 2023 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0007/

NetApp published this interim advisory covering CVE-2023-45648, CVE-2023-42795; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-4822 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0008/

NetApp published this final advisory covering CVE-2023-4822; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-42467 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0005/

NetApp published this final advisory covering CVE-2023-42467; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-32005 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0004/

NetApp published this final advisory covering CVE-2023-32005; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29499 Gnome Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0001/

NetApp published this interim advisory covering CVE-2023-29499; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-25584 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0002/

NetApp published this final advisory covering CVE-2023-25584; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

October 2023 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0009/

NetApp published this final advisory covering CVE-2023-22015, CVE-2023-22026, CVE-2023-22028, CVE-2023-22032, CVE-2023-22059, CVE-2023-22064, CVE-2023-22065, CVE-2023-22066, CVE-2023-22068, CVE-2023-22070, CVE-2023-22078, CVE-2023-22079, CVE-2023-22084, CVE-2023-22092, CVE-2023-22095, CVE-2023-22097, CVE-2023-22103, CVE-2023-22104, CVE-2023-22110, CVE-2023-22111, CVE-2023-22112, CVE-2023-22113, CVE-2023-22114, CVE-2023-22115, CVE-2023-2650, CVE-2023-38545; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2023 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0006/

NetApp published this interim advisory covering CVE-2023-22025, CVE-2023-22067, CVE-2023-22081; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS); OnCommand Workflow Automation.

Open source
Advisory

October 2023 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0011/

NetApp published this final advisory covering CVE-2023-31122, CVE-2023-43622, CVE-2023-45802; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5363 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0010/

NetApp published this interim advisory covering CVE-2023-5363; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4004 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0001/

NetApp published this final advisory covering CVE-2023-4004; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-32611 Gnome Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0005/

NetApp published this final advisory covering CVE-2023-32611; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3223 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0004/

NetApp published this interim advisory covering CVE-2023-3223; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-22102 MySQL Connector/J Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0007/

NetApp published this final advisory covering CVE-2023-22102; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2014-3577 Apache HttpComponents HttpClient Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0003/

NetApp published this final advisory covering CVE-2014-3577; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2023 Linux Kernel 6.5-rc5 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0002/

NetApp published this final advisory covering CVE-2023-4273, CVE-2023-4128, CVE-2023-4194; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

September 2023 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0008/

NetApp published this final advisory covering CVE-2023-3255, CVE-2023-3301; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2023 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0009/

NetApp published this final advisory covering CVE-2023-39318, CVE-2023-39319; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2023 Golang 1.21.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0004/

NetApp published this final advisory covering CVE-2023-39320, CVE-2023-39321, CVE-2023-39322; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-42503 Apache Commons Compress Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0003/

NetApp published this final advisory covering CVE-2023-42503; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-4147 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0006/

NetApp published this interim advisory covering CVE-2023-4147; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-4132 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0005/

NetApp published this final advisory covering CVE-2023-4132; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-40283 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0007/

NetApp published this final advisory covering CVE-2023-40283; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-39323 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0001/

NetApp published this final advisory covering CVE-2023-39323; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1260 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0010/

NetApp published this final advisory covering CVE-2023-1260; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1108 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0002/

NetApp published this final advisory covering CVE-2023-1108; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-44487 HTTP/2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231016-0001/

NetApp published this final advisory covering CVE-2023-44487; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; OnCommand Insight; Trident; Trident Autosupport.

Open source
Advisory

CVE-2023-4911 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231013-0006/

NetApp published this interim advisory covering CVE-2023-4911; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-4236 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231013-0004/

NetApp published this final advisory covering CVE-2023-4236; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-41835 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231013-0001/

NetApp published this final advisory covering CVE-2023-41835; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38039 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231013-0005/

NetApp published this final advisory covering CVE-2023-38039; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; ONTAP 9; ONTAP Antivirus Connector.

Open source
Advisory

CVE-2023-3341 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231013-0003/

NetApp published this final advisory covering CVE-2023-3341; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

October 2023 curl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231011-0001/

NetApp published this interim advisory covering CVE-2023-38545, CVE-2023-38546; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-27314 Denial of Service Vulnerability in ONTAP 9

Source: https://security.netapp.com/advisory/NTAP-20231009-0001/

NetApp published this final advisory covering CVE-2023-27314; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

CVE-2023-41105 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0015/

NetApp published this interim advisory covering CVE-2023-41105; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-40217 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0014/

NetApp published this interim advisory covering CVE-2023-40217; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-32559 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0006/

NetApp published this final advisory covering CVE-2023-32559; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-48566 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0013/

NetApp published this interim advisory covering CVE-2022-48566; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; NetApp Converged Systems Advisor Agent; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-48565 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0007/

NetApp published this interim advisory covering CVE-2022-48565; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); NetApp XCP NFS; NetApp XCP SMB.

Open source
Advisory

CVE-2022-45703 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0003/

NetApp published this final advisory covering CVE-2022-45703; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

CVE-2022-36648 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0004/

NetApp published this final advisory covering CVE-2022-36648; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-35205 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0010/

NetApp published this final advisory covering CVE-2022-35205; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

CVE-2021-32050 MongoDB Drivers Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0001/

NetApp published this final advisory covering CVE-2021-32050; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-35342 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0009/

NetApp published this final advisory covering CVE-2020-35342; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

CVE-2020-24165 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0012/

NetApp published this final advisory covering CVE-2020-24165; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-22218 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0002/

NetApp published this interim advisory covering CVE-2020-22218; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

August 2023 GNU Ncurses Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0005/

NetApp published this final advisory covering CVE-2020-19190, CVE-2020-19189, CVE-2020-19188, CVE-2020-19187, CVE-2020-19186, CVE-2020-19185; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2023 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0008/

NetApp published this final advisory covering CVE-2022-48063, CVE-2022-48064, CVE-2022-48065; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

CVE-2023-4863 Libwebp Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0011/

NetApp published this final advisory covering CVE-2023-4863; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-3212 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0005/

NetApp published this final advisory covering CVE-2023-3212; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-2898 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0002/

NetApp published this final advisory covering CVE-2023-2898; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-2269 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0004/

NetApp published this final advisory covering CVE-2023-2269; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1206 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0006/

NetApp published this interim advisory covering CVE-2023-1206; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-48564 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0009/

NetApp published this interim advisory covering CVE-2022-48564; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-48560 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0008/

NetApp published this final advisory covering CVE-2022-48560; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-4269 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0001/

NetApp published this final advisory covering CVE-2022-4269; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-32292 JSON-C Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0010/

NetApp published this final advisory covering CVE-2021-32292; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2020-21490 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0007/

NetApp published this final advisory covering CVE-2020-21490; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

April 2023 Linux Kernel 6.2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0003/

NetApp published this final advisory covering CVE-2023-31081, CVE-2023-31082, CVE-2023-31083, CVE-2023-31084, CVE-2023-31085; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-4807 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230921-0001/

NetApp published this interim advisory covering CVE-2023-4807; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-41080 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230921-0006/

NetApp published this interim advisory covering CVE-2023-41080; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-1409 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230921-0007/

NetApp published this final advisory covering CVE-2023-1409; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-35637 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230921-0003/

NetApp published this final advisory covering CVE-2022-35637; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-22483 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230921-0004/

NetApp published this final advisory covering CVE-2022-22483; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 Linux Kernel 6.3.9 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0011/

NetApp published this final advisory covering CVE-2023-32258, CVE-2023-32257, CVE-2023-32247; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4135 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0012/

NetApp published this final advisory covering CVE-2023-4135; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-40360 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0004/

NetApp published this final advisory covering CVE-2023-40360; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-39975 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0014/

NetApp published this final advisory covering CVE-2023-39975; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38426 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0010/

NetApp published this interim advisory covering CVE-2023-38426; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2023-32248 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0006/

NetApp published this final advisory covering CVE-2023-32248; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-25775 Intel Ethernet Controller Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0013/

NetApp published this final advisory covering CVE-2023-25775; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22276 Intel Ethernet Controller Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0007/

NetApp published this final advisory covering CVE-2023-22276; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-48522 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0008/

NetApp published this interim advisory covering CVE-2022-48522; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Workflow Automation; SRA Plugin for Linux.

Open source
Advisory

CVE-2022-41804 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0003/

NetApp published this interim advisory covering CVE-2022-41804; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2021-3236 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0001/

NetApp published this interim advisory covering CVE-2021-3236; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2023 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0002/

NetApp published this final advisory covering CVE-2023-39417, CVE-2023-39418; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2023 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0009/

NetApp published this final advisory covering CVE-2023-32002, CVE-2023-32003, CVE-2023-32004, CVE-2023-32006; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3611 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0002/

NetApp published this final advisory covering CVE-2023-3611; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-36054 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0004/

NetApp published this interim advisory covering CVE-2023-36054; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP 9; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-3269 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0001/

NetApp published this final advisory covering CVE-2023-3269; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-1255 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0006/

NetApp published this interim advisory covering CVE-2023-1255; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-24999 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0005/

NetApp published this final advisory covering CVE-2022-24999; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24963 Apache Portable Runtime (APR) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0008/

NetApp published this final advisory covering CVE-2022-24963; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9.

Open source
Advisory

August 2023 Brocade Fabric OS Vulnerabilities

Source: https://security.netapp.com/advisory/NTAP-20230908-0007/

NetApp published this final advisory covering CVE-2023-31425, CVE-2023-31426, CVE-2023-31427, CVE-2023-31428, CVE-2023-31429, CVE-2023-31430, CVE-2023-31431, CVE-2023-31432, CVE-2023-31926, CVE-2023-31927, CVE-2023-31928; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

July 2023 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0005/

NetApp published this final advisory covering CVE-2023-1386, CVE-2023-3019; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0007/

NetApp published this final advisory covering CVE-2023-37903, CVE-2023-37466; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-4009 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0013/

NetApp published this final advisory covering CVE-2023-4009; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3896 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0012/

NetApp published this final advisory covering CVE-2023-3896; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-38633 GNOME Librsvg Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0011/

NetApp published this final advisory covering CVE-2023-38633; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38432 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0002/

NetApp published this final advisory covering CVE-2023-38432; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-38430 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0003/

NetApp published this final advisory covering CVE-2023-38430; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-38428 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0001/

NetApp published this final advisory covering CVE-2023-38428; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3494 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0006/

NetApp published this final advisory covering CVE-2023-3494; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3180 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0008/

NetApp published this final advisory covering CVE-2023-3180; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29409 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0010/

NetApp published this final advisory covering CVE-2023-29409; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); Trident.

Open source
Advisory

CVE-2023-26045 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0004/

NetApp published this final advisory covering CVE-2023-26045; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2023 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0009/

NetApp published this final advisory covering CVE-2023-29407, CVE-2023-29408; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 Grub Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230825-0002/

NetApp published this final advisory covering CVE-2022-28733, CVE-2022-28734, CVE-2022-28735, CVE-2022-28736; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2023 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230825-0001/

NetApp published this final advisory covering CVE-2023-3823, CVE-2023-3824; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 Linux Kernel 6.4 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0004/

NetApp published this final advisory covering CVE-2023-32250, CVE-2023-32254; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

July 2023 Linux Kernel 6.3.7 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0011/

NetApp published this final advisory covering CVE-2023-38427, CVE-2023-38431; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

Intel SA-00813 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0001/

NetApp published this interim advisory covering CVE-2022-27879, CVE-2022-37343, CVE-2022-38083, CVE-2022-43505, CVE-2022-44611; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00783 CSME Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0002/

NetApp published this interim advisory covering CVE-2022-36392, CVE-2022-29871, CVE-2022-38102; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38325 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0010/

NetApp published this interim advisory covering CVE-2023-38325; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-3618 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0012/

NetApp published this final advisory covering CVE-2023-3618; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-35001 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0007/

NetApp published this final advisory covering CVE-2023-35001; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3338 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0005/

NetApp published this final advisory covering CVE-2023-3338; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3268 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0006/

NetApp published this final advisory covering CVE-2023-3268; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-23908 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0003/

NetApp published this interim advisory covering CVE-2023-23908; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2022-31693 VMware Tools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0009/

NetApp published this final advisory covering CVE-2022-31693; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-32256 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0013/

NetApp published this interim advisory covering CVE-2021-32256; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); SRA Plugin for Linux.

Open source
Advisory

July 2023 Linux Kernel 6.3 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0005/

NetApp published this final advisory covering CVE-2023-3609, CVE-2023-3610; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

July 2023 JetBrains Kotlin Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0012/

NetApp published this final advisory covering CVE-2019-10101, CVE-2019-10102, CVE-2019-10103; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

February 2023 Werkzeug Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0003/

NetApp published this final advisory covering CVE-2023-23934, CVE-2023-25577; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2023-38403 iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0016/

NetApp published this final advisory covering CVE-2023-38403; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-3817 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0014/

NetApp published this interim advisory covering CVE-2023-3817; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-35012 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0013/

NetApp published this final advisory covering CVE-2023-35012; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3390 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0004/

NetApp published this final advisory covering CVE-2023-3390; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-30861 Flask Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0006/

NetApp published this final advisory covering CVE-2023-30861; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-2976 Guava Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0008/

NetApp published this interim advisory covering CVE-2023-2976; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); NetApp Manageability SDK; OnCommand Insight.

Open source
Advisory

CVE-2023-27558 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0017/

NetApp published this final advisory covering CVE-2023-27558; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23221 H2 Database Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0011/

NetApp published this final advisory covering CVE-2022-23221; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1471 SnakeYAML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0015/

NetApp published this interim advisory covering CVE-2022-1471; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS); Spot PC.

Open source
Advisory

CVE-2021-40690 Apache XML Security for Java Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0002/

NetApp published this final advisory covering CVE-2021-40690; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23463 H2 Database Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0010/

NetApp published this final advisory covering CVE-2021-23463; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10650 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0007/

NetApp published this final advisory covering CVE-2020-10650; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-12402 Apache Commons Compress Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0001/

NetApp published this final advisory covering CVE-2019-12402; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 MegaRAC BMC Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0004/

NetApp published this interim advisory covering CVE-2023-34329, CVE-2023-34330; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

CVE-2023-36824 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0009/

NetApp published this interim advisory covering CVE-2023-36824; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-34034 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0008/

NetApp published this final advisory covering CVE-2023-34034; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29406 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0002/

NetApp published this final advisory covering CVE-2023-29406; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator; Trident; Trident Autosupport.

Open source
Advisory

CVE-2023-28953 IBM Cognos Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0001/

NetApp published this final advisory covering CVE-2023-28953; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2878 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0003/

NetApp published this final advisory covering CVE-2023-2878; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24834 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0006/

NetApp published this final advisory covering CVE-2022-24834; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2021-31294 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0007/

NetApp published this final advisory covering CVE-2021-31294; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-40982 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230811-0001/

NetApp published this interim advisory covering CVE-2022-40982; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - 2820; FAS/AFF BIOS - 8300/8700/A400/C400; FAS/AFF BIOS - A250/500f/C250; FAS/AFF BIOS - A320; FAS/AFF BIOS - A800/C800; FAS/AFF BIOS - A900/9500; NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Advisory

June 2023 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0002/

NetApp published this final advisory covering CVE-2023-35823, CVE-2023-35824, CVE-2023-35826, CVE-2023-35828, CVE-2023-35829; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

July 2023 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0004/

NetApp published this final advisory covering CVE-2023-2727, CVE-2023-2728; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 IBM DB2 JDBC Driver Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0006/

NetApp published this final advisory covering CVE-2023-27869, CVE-2023-27868, CVE-2023-27867; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38408 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0010/

NetApp published this interim advisory covering CVE-2023-38408; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-35947 Gradle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0007/

NetApp published this final advisory covering CVE-2023-35947; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-35827 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0003/

NetApp published this final advisory covering CVE-2023-35827; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-34462 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0001/

NetApp published this final advisory covering CVE-2023-34462; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-3446 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0011/

NetApp published this interim advisory covering CVE-2023-3446; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-34457 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0005/

NetApp published this final advisory covering CVE-2023-34457; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-30589 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0009/

NetApp published this final advisory covering CVE-2023-30589; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2023-30586 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0008/

NetApp published this final advisory covering CVE-2023-30586; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0010/

NetApp published this final advisory covering CVE-2022-2127, CVE-2023-3347, CVE-2023-34966, CVE-2023-34967, CVE-2023-34968; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0007/

NetApp published this final advisory covering CVE-2023-23487, CVE-2023-29256, CVE-2023-30431, CVE-2023-30442, CVE-2023-30443, CVE-2023-30445, CVE-2023-30446, CVE-2023-30447, CVE-2023-30448, CVE-2023-30449; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2023 MegaRAC BMC Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0008/

NetApp published this final advisory covering CVE-2022-26872, CVE-2022-40258; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

CVE-2023-35946 Gradle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0003/

NetApp published this final advisory covering CVE-2023-35946; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3389 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0001/

NetApp published this final advisory covering CVE-2023-3389; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3312 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0005/

NetApp published this interim advisory covering CVE-2023-3312; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-3090 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0002/

NetApp published this final advisory covering CVE-2023-3090; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-2908 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0004/

NetApp published this final advisory covering CVE-2023-2908; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-1295 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0006/

NetApp published this final advisory covering CVE-2023-1295; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2015-20109 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0009/

NetApp published this final advisory covering CVE-2015-20109; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

July 2023 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230725-0005/

NetApp published this final advisory covering CVE-2022-4899, CVE-2023-0361, CVE-2023-21950, CVE-2023-22005, CVE-2023-22007, CVE-2023-22008, CVE-2023-22033, CVE-2023-22038, CVE-2023-22046, CVE-2023-22048, CVE-2023-22053, CVE-2023-22054, CVE-2023-22056, CVE-2023-22057, CVE-2023-22058; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2023 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230725-0006/

NetApp published this interim advisory covering CVE-2023-22006, CVE-2023-22036, CVE-2023-22041, CVE-2023-22043, CVE-2023-22044, CVE-2023-22045, CVE-2023-22049, CVE-2023-25193; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-36617 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230725-0002/

NetApp published this final advisory covering CVE-2023-36617; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-2975 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230725-0004/

NetApp published this interim advisory covering CVE-2023-2975; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-20867 VMware Tools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230725-0001/

NetApp published this final advisory covering CVE-2023-20867; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-23064 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230725-0003/

NetApp published this final advisory covering CVE-2020-23064; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Brocade SAN Navigator (SANnav); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Virtual Desktop Service (VDS); Spot PC.

Open source
Advisory

CVE-2023-35788 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230714-0002/

NetApp published this final advisory covering CVE-2023-35788; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-34981 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230714-0003/

NetApp published this final advisory covering CVE-2023-34981; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3326 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230714-0005/

NetApp published this final advisory covering CVE-2023-3326; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3128 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230714-0004/

NetApp published this final advisory covering CVE-2023-3128; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0045 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230714-0001/

NetApp published this interim advisory covering CVE-2023-0045; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node.

Open source
Advisory

June 2023 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0006/

NetApp published this final advisory covering CVE-2023-2454, CVE-2023-2455; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

June 2023 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0002/

NetApp published this final advisory covering CVE-2023-2801, CVE-2023-2183; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2023 Apache Struts Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0005/

NetApp published this final advisory covering CVE-2023-34149, CVE-2023-34396; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3141 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0004/

NetApp published this final advisory covering CVE-2023-3141; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-2700 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0001/

NetApp published this final advisory covering CVE-2023-2700; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-26965 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0009/

NetApp published this final advisory covering CVE-2023-26965; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-3515 Libksba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0008/

NetApp published this final advisory covering CVE-2022-3515; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-36732 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0003/

NetApp published this final advisory covering CVE-2020-36732; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-35525 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0007/

NetApp published this final advisory covering CVE-2020-35525; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

May 2023 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0002/

NetApp published this final advisory covering CVE-2023-30775, CVE-2023-30774; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2023 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0010/

NetApp published this interim advisory covering CVE-2023-2828, CVE-2023-2829, CVE-2023-2911; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3111 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0007/

NetApp published this final advisory covering CVE-2023-3111; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-2953 OpenLDAP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0005/

NetApp published this interim advisory covering CVE-2023-2953; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP 9; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-2731 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0009/

NetApp published this final advisory covering CVE-2023-2731; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2650 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0001/

NetApp published this interim advisory covering CVE-2023-2650; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-2598 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0006/

NetApp published this final advisory covering CVE-2023-2598; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-20883 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0008/

NetApp published this final advisory covering CVE-2023-20883; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-48502 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0004/

NetApp published this final advisory covering CVE-2022-48502; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2015-20108 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0003/

NetApp published this final advisory covering CVE-2015-20108; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

May 2023 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0007/

NetApp published this final advisory covering CVE-2023-27563, CVE-2023-27564, CVE-2023-27562; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-33250 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0006/

NetApp published this final advisory covering CVE-2023-33250; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-31125 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0002/

NetApp published this final advisory covering CVE-2023-31125; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28410 Intel Graphics Drivers Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0004/

NetApp published this final advisory covering CVE-2023-28410; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2156 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0001/

NetApp published this final advisory covering CVE-2023-2156; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-2124 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0010/

NetApp published this final advisory covering CVE-2023-2124; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2020-36694 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0005/

NetApp published this interim advisory covering CVE-2020-36694; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2018-3745 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0009/

NetApp published this final advisory covering CVE-2018-3745; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Virtual Desktop Service (VDS); Spot PC.

Open source
Advisory

CVE-2023-32305 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230616-0006/

NetApp published this final advisory covering CVE-2023-32305; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-32233 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230616-0002/

NetApp published this final advisory covering CVE-2023-32233; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-31655 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230616-0005/

NetApp published this final advisory covering CVE-2023-31655; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-30086 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230616-0003/

NetApp published this final advisory covering CVE-2023-30086; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-40540 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230616-0001/

NetApp published this final advisory covering CVE-2022-40540; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

May 2023 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0009/

NetApp published this interim advisory covering CVE-2023-28319, CVE-2023-28320, CVE-2023-28321, CVE-2023-28322; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Antivirus Connector.

Open source
Advisory

May 2023 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0006/

NetApp published this final advisory covering CVE-2023-28724, CVE-2023-28656; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-31436 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0001/

NetApp published this final advisory covering CVE-2023-31436; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-31047 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0008/

NetApp published this final advisory covering CVE-2023-31047; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2235 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0002/

NetApp published this final advisory covering CVE-2023-2235; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-2197 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0007/

NetApp published this final advisory covering CVE-2023-2197; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2176 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0005/

NetApp published this final advisory covering CVE-2023-2176; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-2006 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0004/

NetApp published this final advisory covering CVE-2023-2006; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1387 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0003/

NetApp published this final advisory covering CVE-2023-1387; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31239 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0010/

NetApp published this final advisory covering CVE-2021-31239; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-30846 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0008/

NetApp published this final advisory covering CVE-2023-30846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28856 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0007/

NetApp published this interim advisory covering CVE-2023-28856; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2023-27043 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0003/

NetApp published this interim advisory covering CVE-2023-27043; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-2236 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0010/

NetApp published this final advisory covering CVE-2023-2236; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-20873 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0009/

NetApp published this interim advisory covering CVE-2023-20873; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-1989 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0004/

NetApp published this final advisory covering CVE-2023-1989; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1872 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0002/

NetApp published this final advisory covering CVE-2023-1872; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1829 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0001/

NetApp published this final advisory covering CVE-2023-1829; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-21216 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0005/

NetApp published this interim advisory covering CVE-2022-21216; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series BIOS; FAS/AFF BIOS - A900/9500; NetApp HCI Compute Node BIOS.

Open source
Advisory

April 2023 Libxml2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0006/

NetApp published this final advisory covering CVE-2023-28484, CVE-2023-29469; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SMI-S Provider; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

March 2023 Hashicorp Vault Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0008/

NetApp published this final advisory covering CVE-2023-25000, CVE-2023-0665, CVE-2023-0620; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29323 OpenBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0006/

NetApp published this final advisory covering CVE-2023-29323; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28756 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0004/

NetApp published this final advisory covering CVE-2023-28756; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-28755 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0003/

NetApp published this final advisory covering CVE-2023-28755; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-20862 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0002/

NetApp published this final advisory covering CVE-2023-20862; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-1670 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0010/

NetApp published this final advisory covering CVE-2023-1670; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-4744 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0009/

NetApp published this final advisory covering CVE-2022-4744; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2020-24736 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0005/

NetApp published this final advisory covering CVE-2020-24736; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

April 2023 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0007/

NetApp published this final advisory covering CVE-2023-24536, CVE-2023-24534; the API labels exploitation information as **Public**. The API currently lists affected products as: Trident.

Open source
Advisory

April 2023 Eclipse Jetty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0001/

NetApp published this interim advisory covering CVE-2023-26049, CVE-2023-26048; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

February 2023 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0001/

NetApp published this final advisory covering CVE-2023-0662, CVE-2023-0568; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

CVE-2023-29013 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0008/

NetApp published this final advisory covering CVE-2023-29013; the API labels exploitation information as **Public**. The API currently lists affected products as: Trident; Trident Autosupport.

Open source
Advisory

CVE-2023-28464 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0004/

NetApp published this final advisory covering CVE-2023-28464; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-26463 strongSwan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0010/

NetApp published this final advisory covering CVE-2023-26463; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2008 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0007/

NetApp published this final advisory covering CVE-2023-2008; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1838 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0003/

NetApp published this final advisory covering CVE-2023-1838; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0664 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0005/

NetApp published this final advisory covering CVE-2023-0664; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0210 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0002/

NetApp published this final advisory covering CVE-2023-0210; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-46880 LibreSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0006/

NetApp published this final advisory covering CVE-2021-46880; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-30456 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0007/

NetApp published this final advisory covering CVE-2023-30456; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1652 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0006/

NetApp published this final advisory covering CVE-2023-1652; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1579 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0009/

NetApp published this final advisory covering CVE-2023-1579; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); SRA Plugin for Linux.

Open source
Advisory

CVE-2023-1550 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0008/

NetApp published this final advisory covering CVE-2023-1550; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-1544 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0005/

NetApp published this final advisory covering CVE-2023-1544; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1380 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0001/

NetApp published this final advisory covering CVE-2023-1380; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1077 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0002/

NetApp published this interim advisory covering CVE-2023-1077; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0179 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0003/

NetApp published this final advisory covering CVE-2023-0179; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3162 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0004/

NetApp published this final advisory covering CVE-2022-3162; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2023 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0010/

NetApp published this final advisory covering CVE-2023-26021, CVE-2023-26022, CVE-2023-27559, CVE-2023-29255, CVE-2023-29257, CVE-2023-25930, CVE-2023-27555; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-26604 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0009/

NetApp published this final advisory covering CVE-2023-26604; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-26464 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0008/

NetApp published this interim advisory covering CVE-2023-26464; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24999 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0001/

NetApp published this final advisory covering CVE-2023-24999; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-20860 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0006/

NetApp published this final advisory covering CVE-2023-20860; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-1252 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0005/

NetApp published this final advisory covering CVE-2023-1252; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1078 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0004/

NetApp published this final advisory covering CVE-2023-1078; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-48424 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0002/

NetApp published this final advisory covering CVE-2022-48424; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-48423 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0003/

NetApp published this final advisory covering CVE-2022-48423; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3294 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0007/

NetApp published this final advisory covering CVE-2022-3294; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3116 Heimdal Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0010/

NetApp published this final advisory covering CVE-2022-3116; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28772 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0005/

NetApp published this final advisory covering CVE-2023-28772; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-28466 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0006/

NetApp published this final advisory covering CVE-2023-28466; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-27475 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0003/

NetApp published this final advisory covering CVE-2023-27475; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-21971 MySQL Connector/J Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0010/

NetApp published this final advisory covering CVE-2023-21971; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2023-1281 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0004/

NetApp published this final advisory covering CVE-2023-1281; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0482 RESTEasy Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0001/

NetApp published this final advisory covering CVE-2023-0482; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-0812 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0011/

NetApp published this final advisory covering CVE-2022-0812; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-39537 GNU Ncurses Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0012/

NetApp published this interim advisory covering CVE-2021-39537; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer; NetApp SolidFire & HCI Management Node.

Open source
Advisory

April 2023 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0007/

NetApp published this final advisory covering CVE-2022-37434, CVE-2022-43548, CVE-2022-43551, CVE-2023-0215, CVE-2023-21911, CVE-2023-21912, CVE-2023-21913, CVE-2023-21917, CVE-2023-21919, CVE-2023-21920, CVE-2023-21929, CVE-2023-21933, CVE-2023-21935, CVE-2023-21940, CVE-2023-21945, CVE-2023-21946, CVE-2023-21947, CVE-2023-21953, CVE-2023-21955, CVE-2023-21962, CVE-2023-21963, CVE-2023-21966, CVE-2023-21971, CVE-2023-21972, CVE-2023-21976, CVE-2023-21977, CVE-2023-21980, CVE-2023-21982; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2023 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0008/

NetApp published this interim advisory covering CVE-2023-21930, CVE-2023-21937, CVE-2023-21938, CVE-2023-21939, CVE-2023-21954, CVE-2023-21967, CVE-2023-21968; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Brocade SAN Navigator (SANnav); Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp SolidFire & HCI Management Node; OnCommand Insight.

Open source
Advisory

March 2023 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0010/

NetApp published this interim advisory covering CVE-2023-27535, CVE-2023-27536, CVE-2023-27537, CVE-2023-27538; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9.

Open source
Advisory

March 2023 Sudo Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0002/

NetApp published this interim advisory covering CVE-2023-28486, CVE-2023-28487; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-27534 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0012/

NetApp published this final advisory covering CVE-2023-27534; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-27533 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0011/

NetApp published this final advisory covering CVE-2023-27533; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2023-27490 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0006/

NetApp published this final advisory covering CVE-2023-27490; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-20861 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0007/

NetApp published this final advisory covering CVE-2023-20861; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Snap Creator Framework.

Open source
Advisory

CVE-2023-1410 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0003/

NetApp published this final advisory covering CVE-2023-1410; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1390 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0001/

NetApp published this final advisory covering CVE-2023-1390; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0386 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0004/

NetApp published this final advisory covering CVE-2023-0386; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-4095 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0005/

NetApp published this final advisory covering CVE-2022-4095; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-2097 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0008/

NetApp published this final advisory covering CVE-2022-2097; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

March 2023 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230414-0001/

NetApp published this interim advisory covering CVE-2023-0465, CVE-2023-0466; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Manageability SDK; NetApp SMI-S Provider; ONTAP 9; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-28531 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0008/

NetApp published this final advisory covering CVE-2023-28531; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28425 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0005/

NetApp published this final advisory covering CVE-2023-28425; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28155 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0007/

NetApp published this final advisory covering CVE-2023-28155; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-27320 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0009/

NetApp published this final advisory covering CVE-2023-27320; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-26053 Gradle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0002/

NetApp published this final advisory covering CVE-2023-26053; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-22462 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0004/

NetApp published this final advisory covering CVE-2023-22462; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1118 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0003/

NetApp published this final advisory covering CVE-2023-1118; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0507 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0001/

NetApp published this final advisory covering CVE-2023-0507; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0030 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0010/

NetApp published this final advisory covering CVE-2023-0030; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-48425 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0006/

NetApp published this final advisory covering CVE-2022-48425; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

March 2023 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0007/

NetApp published this final advisory covering CVE-2023-0614, CVE-2023-0922, CVE-2023-0225; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-27567 OpenBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0001/

NetApp published this final advisory covering CVE-2023-27567; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-26242 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0002/

NetApp published this final advisory covering CVE-2023-26242; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0464 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0006/

NetApp published this interim advisory covering CVE-2023-0464; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-3857 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0004/

NetApp published this interim advisory covering CVE-2022-3857; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3424 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0005/

NetApp published this final advisory covering CVE-2022-3424; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-36713 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0003/

NetApp published this final advisory covering CVE-2021-36713; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Virtual Desktop Service (VDS); SnapCenter; Spot PC.

Open source
Advisory

March 2023 Redis Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0002/

NetApp published this interim advisory covering CVE-2023-25155, CVE-2022-36021; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

Februray 2023 Linux Kernel 5.16 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0004/

NetApp published this final advisory covering CVE-2023-22995, CVE-2023-23000; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

February 2023 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0009/

NetApp published this final advisory covering CVE-2022-41724, CVE-2022-41725; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); StorageGRID (formerly StorageGRID Webscale); Trident.

Open source
Advisory

CVE-2023-28708 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0012/

NetApp published this final advisory covering CVE-2023-28708; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24532 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0011/

NetApp published this final advisory covering CVE-2023-24532; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-23003 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0003/

NetApp published this final advisory covering CVE-2023-23003; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0594 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0007/

NetApp published this final advisory covering CVE-2023-0594; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0567 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0008/

NetApp published this final advisory covering CVE-2023-0567; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0461 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0006/

NetApp published this final advisory covering CVE-2023-0461; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-4645 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0001/

NetApp published this final advisory covering CVE-2022-4645; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20251 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0005/

NetApp published this final advisory covering CVE-2021-20251; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24807 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0010/

NetApp published this final advisory covering CVE-2023-24807; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24329 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0004/

NetApp published this final advisory covering CVE-2023-24329; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-23931 Cryptography Project Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0007/

NetApp published this interim advisory covering CVE-2023-23931; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Converged Systems Advisor Agent; NetApp Virtual Desktop Service (VDS); Spot PC.

Open source
Advisory

CVE-2023-0804 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0009/

NetApp published this final advisory covering CVE-2023-0804; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0767 Libnss Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0008/

NetApp published this final advisory covering CVE-2023-0767; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-0361 GNU TLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0005/

NetApp published this final advisory covering CVE-2023-0361; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Converged Systems Advisor Agent; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-48282 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0003/

NetApp published this final advisory covering CVE-2022-48282; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-4492 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0002/

NetApp published this final advisory covering CVE-2022-4492; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-3219 GnuPG Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0001/

NetApp published this interim advisory covering CVE-2022-3219; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-12403 Libnss Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0006/

NetApp published this final advisory covering CVE-2020-12403; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

March 2023 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0003/

NetApp published this final advisory covering CVE-2023-0795, CVE-2023-0796, CVE-2023-0798, CVE-2023-0799; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

February 2023 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0008/

NetApp published this final advisory covering CVE-2023-23918, CVE-2023-23919, CVE-2023-23920; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2023 Linux Kernel 6.0.8 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0010/

NetApp published this final advisory covering CVE-2023-26544, CVE-2023-26606, CVE-2023-26605, CVE-2023-26607; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

February 2023 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0002/

NetApp published this final advisory covering CVE-2023-0800, CVE-2023-0801, CVE-2023-0802, CVE-2023-0803; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-26545 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0009/

NetApp published this final advisory covering CVE-2023-26545; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-24580 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0006/

NetApp published this final advisory covering CVE-2023-24580; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0751 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0004/

NetApp published this final advisory covering CVE-2023-0751; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0240 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0001/

NetApp published this final advisory covering CVE-2023-0240; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-47629 Libksba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0011/

NetApp published this final advisory covering CVE-2022-47629; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2006-20001 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0005/

NetApp published this final advisory covering CVE-2006-20001; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2023 Trusted Platform Module 2.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230314-0001/

NetApp published this final advisory covering CVE-2023-1017, CVE-2023-1018; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2023 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0006/

NetApp published this interim advisory covering CVE-2023-23914, CVE-2023-23915, CVE-2023-23916; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

CVE-2023-25136 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0003/

NetApp published this final advisory covering CVE-2023-25136; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-22474 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0005/

NetApp published this final advisory covering CVE-2023-22474; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-47015 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0009/

NetApp published this final advisory covering CVE-2022-47015; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-4139 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0004/

NetApp published this final advisory covering CVE-2022-4139; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-39324 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0010/

NetApp published this final advisory covering CVE-2022-39324; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-37708 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0008/

NetApp published this final advisory covering CVE-2022-37708; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23498 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0007/

NetApp published this final advisory covering CVE-2022-23498; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-1000802 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0002/

NetApp published this final advisory covering CVE-2018-1000802; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2023 Redis Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0006/

NetApp published this interim advisory covering CVE-2022-35977, CVE-2023-22458; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

January 2023 Linux Kernel 6.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0005/

NetApp published this interim advisory covering CVE-2023-0266, CVE-2023-0394; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

Intel SA-00717 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0011/

NetApp published this interim advisory covering CVE-2022-26343, CVE-2022-30539, CVE-2022-32231, CVE-2022-26837, CVE-2022-30704, CVE-2021-0187; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2023 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0009/

NetApp published this final advisory covering CVE-2022-43927, CVE-2022-43929, CVE-2022-43930; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-25139 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0010/

NetApp published this final advisory covering CVE-2023-25139; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-24998 Apache Commons FileUpload Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0013/

NetApp published this interim advisory covering CVE-2023-24998; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter; Snap Creator Framework.

Open source
Advisory

CVE-2023-23969 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0007/

NetApp published this final advisory covering CVE-2023-23969; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-23559 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0003/

NetApp published this final advisory covering CVE-2023-23559; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-22602 Apache Shiro Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0001/

NetApp published this final advisory covering CVE-2023-22602; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0122 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0002/

NetApp published this final advisory covering CVE-2023-0122; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-48281 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0004/

NetApp published this final advisory covering CVE-2022-48281; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-33972 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0012/

NetApp published this interim advisory covering CVE-2022-33972; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23552 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0008/

NetApp published this interim advisory covering CVE-2022-23552; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2022 Net-SNMP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0011/

NetApp published this interim advisory covering CVE-2022-44792, CVE-2022-44793; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SMI-S Provider.

Open source
Advisory

January 2023 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0009/

NetApp published this final advisory covering CVE-2022-3094, CVE-2022-3488, CVE-2022-3736, CVE-2022-3924; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-4696 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0003/

NetApp published this final advisory covering CVE-2022-4696; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-4379 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0004/

NetApp published this final advisory covering CVE-2022-4379; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-42898 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0001/

NetApp published this final advisory covering CVE-2022-42898; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp E-Series Performance Analyzer; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-41858 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0006/

NetApp published this final advisory covering CVE-2022-41858; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3977 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0005/

NetApp published this final advisory covering CVE-2022-3977; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-31631 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0007/

NetApp published this final advisory covering CVE-2022-31631; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23491 Python-Certifi Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0010/

NetApp published this final advisory covering CVE-2022-23491; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp E-Series Performance Analyzer; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-2196 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0002/

NetApp published this final advisory covering CVE-2022-2196; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2018-14628 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0008/

NetApp published this final advisory covering CVE-2018-14628; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

January 2023 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0007/

NetApp published this final advisory covering CVE-2022-36760, CVE-2022-37436; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2022 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0004/

NetApp published this final advisory covering CVE-2022-41317, CVE-2022-41318; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2022 Heimdal Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0008/

NetApp published this final advisory covering CVE-2022-42898, CVE-2022-3437, CVE-2022-41916, CVE-2021-44758, CVE-2021-3671, CVE-2022-44640, CVE-2019-14870; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp E-Series Performance Analyzer; ONTAP Select Deploy administration utility.

Open source
Advisory

December 2015 PCRE Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0002/

NetApp published this final advisory covering CVE-2015-8391, CVE-2015-8383, CVE-2015-8386, CVE-2015-8387, CVE-2015-8389, CVE-2015-8390, CVE-2015-8393, CVE-2015-8394; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-47943 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0006/

NetApp published this final advisory covering CVE-2022-47943; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2022-45143 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0009/

NetApp published this final advisory covering CVE-2022-45143; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-4415 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0010/

NetApp published this final advisory covering CVE-2022-4415; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-41966 XStream Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0005/

NetApp published this final advisory covering CVE-2022-41966; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3176 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0003/

NetApp published this final advisory covering CVE-2022-3176; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2017-1000158 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0001/

NetApp published this final advisory covering CVE-2017-1000158; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2022 Linux Kernel 5.17 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0006/

NetApp published this final advisory covering CVE-2022-1729, CVE-2022-2977, CVE-2022-3239; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

February 2023 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0011/

NetApp published this interim advisory covering CVE-2023-0286, CVE-2022-4304, CVE-2022-4203, CVE-2023-0215, CVE-2022-4450, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; OnCommand Workflow Automation; SnapManager for Hyper-V; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

December 2022 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0002/

NetApp published this interim advisory covering CVE-2022-43551, CVE-2022-43552; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

CVE-2022-41222 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0008/

NetApp published this final advisory covering CVE-2022-41222; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-40897 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0001/

NetApp published this interim advisory covering CVE-2022-40897; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP Mediator; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-39189 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0007/

NetApp published this final advisory covering CVE-2022-39189; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3649 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0009/

NetApp published this final advisory covering CVE-2022-3649; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-35065 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0010/

NetApp published this final advisory covering CVE-2021-35065; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2022 Linux Kernel 5.19 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0004/

NetApp published this final advisory covering CVE-2022-2961, CVE-2022-3028, CVE-2022-2590; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

August 2022 Linux Kernel 5.18 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0005/

NetApp published this final advisory covering CVE-2022-1976, CVE-2022-2503, CVE-2022-2959; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

August 2022 Linux Kernel 5.17 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0003/

NetApp published this final advisory covering CVE-2022-1205, CVE-2022-1158; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

January 2023 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230208-0002/

NetApp published this final advisory covering CVE-2022-32221, CVE-2023-21836, CVE-2023-21840, CVE-2023-21860, CVE-2023-21863, CVE-2023-21864, CVE-2023-21865, CVE-2023-21866, CVE-2023-21867, CVE-2023-21868, CVE-2023-21869, CVE-2023-21870, CVE-2023-21871, CVE-2023-21872, CVE-2023-21873, CVE-2023-21874, CVE-2023-21875, CVE-2023-21876, CVE-2023-21877, CVE-2023-21878, CVE-2023-21879, CVE-2023-21880, CVE-2023-21881, CVE-2023-21882, CVE-2023-21883, CVE-2023-21887; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2023 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230208-0001/

NetApp published this interim advisory covering CVE-2023-21830, CVE-2023-21835, CVE-2023-21843; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav).

Open source
Advisory

October 2022 Linux Kernel 5.19.15 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0008/

NetApp published this final advisory covering CVE-2022-42719, CVE-2022-42720, CVE-2022-42721, CVE-2022-42722; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2022-46908 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0005/

NetApp published this final advisory covering CVE-2022-46908; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-4293 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0007/

NetApp published this interim advisory covering CVE-2022-4293; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3996 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0003/

NetApp published this final advisory covering CVE-2022-3996; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SMI-S Provider; ONTAP 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-37454 Keccak XKCP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0001/

NetApp published this interim advisory covering CVE-2022-37454; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-3570 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0002/

NetApp published this final advisory covering CVE-2022-3570; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32149 Golang Text Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0006/

NetApp published this final advisory covering CVE-2022-32149; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2601 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0004/

NetApp published this final advisory covering CVE-2022-2601; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2327 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0009/

NetApp published this final advisory covering CVE-2022-2327; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

December 2022 X.Org X Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230127-0011/

NetApp published this final advisory covering CVE-2022-4283, CVE-2022-46340, CVE-2022-46341, CVE-2022-46342, CVE-2022-46343, CVE-2022-46344; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22809 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230127-0015/

NetApp published this final advisory covering CVE-2023-22809; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-4172 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230127-0013/

NetApp published this final advisory covering CVE-2022-4172; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-4144 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230127-0012/

NetApp published this final advisory covering CVE-2022-4144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-33185 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0010/

NetApp published this final advisory covering CVE-2022-33185; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33184 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0009/

NetApp published this final advisory covering CVE-2022-33184; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33183 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0008/

NetApp published this final advisory covering CVE-2022-33183; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33182 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0007/

NetApp published this final advisory covering CVE-2022-33182; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33181 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0006/

NetApp published this final advisory covering CVE-2022-33181; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33180 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0005/

NetApp published this final advisory covering CVE-2022-33180; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33179 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0004/

NetApp published this final advisory covering CVE-2022-33179; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33178 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0003/

NetApp published this final advisory covering CVE-2022-33178; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-28170 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0002/

NetApp published this final advisory covering CVE-2022-28170; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-28169 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0001/

NetApp published this final advisory covering CVE-2022-28169; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

April 2022 OWASP Enterprise Security API Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230127-0014/

NetApp published this interim advisory covering CVE-2022-23457, CVE-2022-24891; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

October 2022 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0005/

NetApp published this final advisory covering CVE-2022-41741, CVE-2022-41742; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

October 2022 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0006/

NetApp published this final advisory covering CVE-2022-2879, CVE-2022-2880, CVE-2022-41715; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent.

Open source
Advisory

Linux Kernel 5.18 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0001/

NetApp published this final advisory covering CVE-2022-2318, CVE-2022-1973, CVE-2022-2873; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

December 2022 JsonWebToken Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0009/

NetApp published this final advisory covering CVE-2022-23529, CVE-2022-23539, CVE-2022-23540, CVE-2022-23541; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2022 Apache CXF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0002/

NetApp published this final advisory covering CVE-2022-46363, CVE-2022-46364; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

CVE-2022-43548 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0004/

NetApp published this final advisory covering CVE-2022-43548; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-41717 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0008/

NetApp published this final advisory covering CVE-2022-41717; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Astra Trident; NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2022-41716 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0007/

NetApp published this final advisory covering CVE-2022-41716; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2022-41296 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0003/

NetApp published this final advisory covering CVE-2022-41296; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2022 Linux Kernel 6.0.9 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0006/

NetApp published this final advisory covering CVE-2022-45884, CVE-2022-45885, CVE-2022-45886, CVE-2022-45887, CVE-2022-45888; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

November 2022 Linux Kernel 6.0.10 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0008/

NetApp published this final advisory covering CVE-2022-45919, CVE-2022-45934; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

December 2022 Linux Kernel 6.0.11 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0007/

NetApp published this final advisory covering CVE-2022-47518, CVE-2022-47519, CVE-2022-47520, CVE-2022-47521; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

December 2022 Apache Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0004/

NetApp published this final advisory covering CVE-2022-41881, CVE-2022-41915; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights and Data Secure Storage Workload Security Agent; E-Series SANtricity Unified Manager and Web Services Proxy; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter; SnapCenter.

Open source
Advisory

CVE-2022-4292 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0005/

NetApp published this final advisory covering CVE-2022-4292; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-35255 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0002/

NetApp published this final advisory covering CVE-2022-35255; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2964 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0001/

NetApp published this final advisory covering CVE-2022-2964; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

October 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0001/

NetApp published this final advisory covering CVE-2022-3626, CVE-2022-3627, CVE-2022-3597, CVE-2022-3598, CVE-2022-3599; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

Linux Kernel through 5.19.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0004/

NetApp published this final advisory covering CVE-2022-47939, CVE-2022-47938, CVE-2022-47941; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

Linux Kernel prior to 5.19.2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0005/

NetApp published this final advisory covering CVE-2022-47940, CVE-2022-47942; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

December 2022 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0006/

NetApp published this interim advisory covering CVE-2022-32221, CVE-2022-35260; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

December 2022 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0003/

NetApp published this final advisory covering CVE-2022-38023, CVE-2022-37966, CVE-2022-37967, CVE-2022-45141; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2021-22600 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0002/

NetApp published this final advisory covering CVE-2021-22600; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-38178 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0009/

NetApp published this final advisory covering CVE-2022-38178; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-38177 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0010/

NetApp published this final advisory covering CVE-2022-38177; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-3541 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0001/

NetApp published this final advisory covering CVE-2022-3541; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3202 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0007/

NetApp published this final advisory covering CVE-2022-3202; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1199 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0006/

NetApp published this final advisory covering CVE-2022-1199; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4204 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0003/

NetApp published this final advisory covering CVE-2021-4204; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4028 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0002/

NetApp published this interim advisory covering CVE-2021-4028; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

CVE-2021-33621 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0004/

NetApp published this final advisory covering CVE-2021-33621; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2016-2338 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0005/

NetApp published this final advisory covering CVE-2016-2338; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0008/

NetApp published this final advisory covering CVE-2022-0865, CVE-2022-0891, CVE-2022-1056; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-42252 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0005/

NetApp published this final advisory covering CVE-2022-42252; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3920 HashiCorp Consul Vulnerability Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0010/

NetApp published this final advisory covering CVE-2022-3920; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3705 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0004/

NetApp published this final advisory covering CVE-2022-3705; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-3564 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0001/

NetApp published this final advisory covering CVE-2022-3564; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2022-3545 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0003/

NetApp published this final advisory covering CVE-2022-3545; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3165 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0006/

NetApp published this final advisory covering CVE-2022-3165; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31630 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0008/

NetApp published this final advisory covering CVE-2022-31630; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2938 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0002/

NetApp published this final advisory covering CVE-2022-2938; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-46784 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0007/

NetApp published this final advisory covering CVE-2021-46784; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31693 VMware Tools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0009/

NetApp published this final advisory covering CVE-2021-31693; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2022 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0001/

NetApp published this final advisory covering CVE-2022-35957, CVE-2022-36062; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2022 Spring Security Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0010/

NetApp published this final advisory covering CVE-2022-31690, CVE-2022-31692; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

November 2022 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0004/

NetApp published this final advisory covering CVE-2022-39306, CVE-2022-39307; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

December 2022 MegaRAC BMC Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0007/

NetApp published this interim advisory covering CVE-2022-40259, CVE-2022-40242, CVE-2022-2827; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

CVE-2022-43945 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0006/

NetApp published this final advisory covering CVE-2022-43945; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3970 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0009/

NetApp published this final advisory covering CVE-2022-3970; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-39328 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0003/

NetApp published this final advisory covering CVE-2022-39328; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3872 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0005/

NetApp published this final advisory covering CVE-2022-3872; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3671 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0002/

NetApp published this final advisory covering CVE-2021-3671; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2014-0144 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0008/

NetApp published this final advisory covering CVE-2014-0144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2022 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0001/

NetApp published this final advisory covering CVE-2022-31628, CVE-2022-31629; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2022 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0010/

NetApp published this interim advisory covering CVE-2022-42915, CVE-2022-42916; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; ONTAP 9.

Open source
Advisory

November 2022 Libxml2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0003/

NetApp published this interim advisory covering CVE-2022-40303, CVE-2022-40304; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-45061 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0007/

NetApp published this interim advisory covering CVE-2022-45061; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp E-Series Performance Analyzer; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-42919 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0006/

NetApp published this final advisory covering CVE-2022-42919; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31176 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0004/

NetApp published this final advisory covering CVE-2022-31176; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23093 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0009/

NetApp published this final advisory covering CVE-2022-23093; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2012-4244 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0008/

NetApp published this final advisory covering CVE-2012-4244; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

August 2022 Util-linux Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0002/

NetApp published this final advisory covering CVE-2021-3995, CVE-2021-3996; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-41316 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221201-0001/

NetApp published this final advisory covering CVE-2022-41316; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3975 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221201-0002/

NetApp published this final advisory covering CVE-2021-3975; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3859 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221201-0004/

NetApp published this final advisory covering CVE-2021-3859; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2021-25642 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221201-0003/

NetApp published this final advisory covering CVE-2021-25642; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-43936 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20221128-0006/

NetApp published this final advisory covering CVE-2022-43936; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-43935 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20221128-0005/

NetApp published this final advisory covering CVE-2022-43935; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-43934 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20221128-0004/

NetApp published this final advisory covering CVE-2022-43934; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-43933 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20221128-0003/

NetApp published this final advisory covering CVE-2022-43933; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-42898 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221128-0001/

NetApp published this final advisory covering CVE-2022-42898; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-33187 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20221128-0002/

NetApp published this final advisory covering CVE-2022-33187; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-42003 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221124-0004/

NetApp published this interim advisory covering CVE-2022-42003; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-41323 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221124-0001/

NetApp published this final advisory covering CVE-2022-41323; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31123 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221124-0002/

NetApp published this final advisory covering CVE-2022-31123; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-3770 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221124-0003/

NetApp published this final advisory covering CVE-2021-3770; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-43680 libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221118-0007/

NetApp published this interim advisory covering CVE-2022-43680; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 10; OnCommand Workflow Automation; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2022-42004 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221118-0008/

NetApp published this interim advisory covering CVE-2022-42004; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-22577 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221118-0002/

NetApp published this final advisory covering CVE-2022-22577; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-21831 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221118-0001/

NetApp published this final advisory covering CVE-2022-21831; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-46848 GNU Libtasn1 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221118-0006/

NetApp published this final advisory covering CVE-2021-46848; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3796 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221118-0004/

NetApp published this final advisory covering CVE-2021-3796; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3778 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221118-0003/

NetApp published this final advisory covering CVE-2021-3778; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

Intel SA-00688 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221111-0006/

NetApp published this final advisory covering CVE-2022-26006, CVE-2022-21198; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-40186 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221111-0008/

NetApp published this final advisory covering CVE-2022-40186; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-28131 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221111-0009/

NetApp published this final advisory covering CVE-2022-28131; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2022-2526 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221111-0005/

NetApp published this final advisory covering CVE-2022-2526; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2022-24903 Rsyslog Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221111-0002/

NetApp published this final advisory covering CVE-2022-24903; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2021-43618 GMP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221111-0001/

NetApp published this final advisory covering CVE-2021-43618; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4203 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221111-0003/

NetApp published this interim advisory covering CVE-2021-4203; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-35527 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221111-0007/

NetApp published this final advisory covering CVE-2020-35527; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

September 2022 X.Org X Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0003/

NetApp published this final advisory covering CVE-2022-2319, CVE-2022-2320; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-39046 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0002/

NetApp published this interim advisory covering CVE-2022-39046; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-38791 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0008/

NetApp published this final advisory covering CVE-2022-38791; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-38533 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0007/

NetApp published this final advisory covering CVE-2022-38533; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2022-36033 jsoup Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0006/

NetApp published this final advisory covering CVE-2022-36033; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-1552 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0005/

NetApp published this final advisory covering CVE-2022-1552; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-4189 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0004/

NetApp published this final advisory covering CVE-2021-4189; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3999 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0001/

NetApp published this final advisory covering CVE-2021-3999; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp NFS Plug-in for VMware VAAI; ONTAP Select Deploy administration utility.

Open source
Advisory

November 2022 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221102-0001/

NetApp published this interim advisory covering CVE-2022-3602, CVE-2022-3786; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

October 2022 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0011/

NetApp published this final advisory covering CVE-2022-3437, CVE-2022-3592; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

October 2022 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0013/

NetApp published this final advisory covering CVE-2022-21589, CVE-2022-21592, CVE-2022-21594, CVE-2022-21595, CVE-2022-21599, CVE-2022-21600, CVE-2022-21604, CVE-2022-21605, CVE-2022-21607, CVE-2022-21608, CVE-2022-21611, CVE-2022-21617, CVE-2022-21625, CVE-2022-21632, CVE-2022-21633, CVE-2022-21635, CVE-2022-21637, CVE-2022-21638, CVE-2022-21640, CVE-2022-21641, CVE-2022-39400, CVE-2022-39408, CVE-2022-39410; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2022 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0012/

NetApp published this interim advisory covering CVE-2022-21618, CVE-2022-21619, CVE-2022-21624, CVE-2022-21626, CVE-2022-21628, CVE-2022-39399; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter.

Open source
Advisory

June 2022 PCRE Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0009/

NetApp published this final advisory covering CVE-2022-1586, CVE-2022-1587; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-40674 libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0008/

NetApp published this interim advisory covering CVE-2022-40674; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2022-34339 IBM Cognos Analytics Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0016/

NetApp published this final advisory covering CVE-2022-34339; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3358 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0014/

NetApp published this final advisory covering CVE-2022-3358; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-26336 Apache POI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0006/

NetApp published this final advisory covering CVE-2022-26336; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-25258 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0007/

NetApp published this final advisory covering CVE-2022-25258; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3800 GNOME GLib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0004/

NetApp published this final advisory covering CVE-2021-3800; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2021-3753 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0003/

NetApp published this interim advisory covering CVE-2021-3753; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-14155 PCRE Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0010/

NetApp published this final advisory covering CVE-2020-14155; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SteelStore Cloud Integrated Storage; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-13990 Quartz Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0002/

NetApp published this final advisory covering CVE-2019-13990; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Insights Storage Workload Security Agent.

Open source
Advisory

CVE-2018-14550 libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0001/

NetApp published this final advisory covering CVE-2018-14550; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; OnCommand API Services.

Open source
Advisory

September 2022 BlueZ Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221020-0002/

NetApp published this final advisory covering CVE-2022-39176, CVE-2022-39177; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-35951 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221020-0005/

NetApp published this final advisory covering CVE-2022-35951; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1012 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221020-0006/

NetApp published this interim advisory covering CVE-2022-1012; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-4214 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221020-0001/

NetApp published this final advisory covering CVE-2021-4214; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3998 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221020-0003/

NetApp published this final advisory covering CVE-2021-3998; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-36067 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221017-0002/

NetApp published this final advisory covering CVE-2022-36067; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00709 AMT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221014-0004/

NetApp published this final advisory covering CVE-2022-30601, CVE-2022-30944, CVE-2022-28697; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31129 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221014-0003/

NetApp published this final advisory covering CVE-2022-31129; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2953 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221014-0008/

NetApp published this final advisory covering CVE-2022-2953; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-43466 Thymeleaf Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221014-0001/

NetApp published this final advisory covering CVE-2021-43466; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3807 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221014-0002/

NetApp published this final advisory covering CVE-2021-3807; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2022 Undertow Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221014-0006/

NetApp published this interim advisory covering CVE-2022-1259, CVE-2022-1319, CVE-2022-2764; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

August 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221014-0007/

NetApp published this final advisory covering CVE-2022-1354, CVE-2022-1355; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

August 2022 IBM Cognos Analytics Vulnerabilities

Source: https://security.netapp.com/advisory/NTAP-20221014-0005/

NetApp published this final advisory covering CVE-2020-4301, CVE-2021-20468, CVE-2021-29823, CVE-2021-39009, CVE-2021-39045, CVE-2022-30614, CVE-2022-36773; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2022-29901 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0007/

NetApp published this final advisory covering CVE-2022-29901; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-28693 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0006/

NetApp published this final advisory covering CVE-2022-28693; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-26373 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0005/

NetApp published this final advisory covering CVE-2022-26373; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24407 Cyrus SASL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0003/

NetApp published this final advisory covering CVE-2022-24407; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-1664 Dpkg Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0002/

NetApp published this final advisory covering CVE-2022-1664; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-0358 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0008/

NetApp published this final advisory covering CVE-2022-0358; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-46828 libtirpc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0004/

NetApp published this final advisory covering CVE-2021-46828; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3772 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0001/

NetApp published this interim advisory covering CVE-2021-3772; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

July 2022 Grub Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0001/

NetApp published this final advisory covering CVE-2021-3695, CVE-2021-3696, CVE-2021-3697; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-35252 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0005/

NetApp published this interim advisory covering CVE-2022-35252; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9.

Open source
Advisory

CVE-2022-34526 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0002/

NetApp published this final advisory covering CVE-2022-34526; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-26074 Intel SPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0003/

NetApp published this interim advisory covering CVE-2022-26074; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-1619 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0007/

NetApp published this interim advisory covering CVE-2022-1619; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2022-1271 GNU Gzip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0006/

NetApp published this final advisory covering CVE-2022-1271; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32189 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220923-0003/

NetApp published this final advisory covering CVE-2022-32189; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-28948 Go-Yaml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220923-0006/

NetApp published this final advisory covering CVE-2022-28948; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident; Astra Trident Autosupport.

Open source
Advisory

CVE-2022-27664 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220923-0004/

NetApp published this final advisory covering CVE-2022-27664; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Astra Control Center - NetApp Kubernetes Monitoring Operator; BeeGFS CSI Driver; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator; Trident; Trident Autosupport.

Open source
Advisory

CVE-2022-21233 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220923-0002/

NetApp published this final advisory covering CVE-2022-21233; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-20824 Cisco Discovery Protocol Denial of Service and Arbitrary Code Execution Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20220923-0001/

NetApp published this final advisory covering CVE-2022-20824; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1996 go-restful Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220923-0005/

NetApp published this final advisory covering CVE-2022-1996; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2022 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0001/

NetApp published this final advisory covering CVE-2022-32212, CVE-2022-32213, CVE-2022-32214, CVE-2022-32215, CVE-2022-32222, CVE-2022-32223; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2022 Libcurl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0003/

NetApp published this interim advisory covering CVE-2022-32208, CVE-2022-32207, CVE-2022-32206, CVE-2022-32205; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

July 2022 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0004/

NetApp published this final advisory covering CVE-2022-30629, CVE-2022-30634; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2022-36359 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0008/

NetApp published this final advisory covering CVE-2022-36359; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-35737 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0009/

NetApp published this final advisory covering CVE-2022-35737; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-31150 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0002/

NetApp published this final advisory covering CVE-2022-31150; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-25168 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0007/

NetApp published this final advisory covering CVE-2022-25168; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2309 lxml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0006/

NetApp published this final advisory covering CVE-2022-2309; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-4209 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0005/

NetApp published this interim advisory covering CVE-2021-4209; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

April 2022 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0010/

NetApp published this final advisory covering CVE-2022-24675, CVE-2022-28327; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-36313 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0005/

NetApp published this final advisory covering CVE-2022-36313; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31160 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0007/

NetApp published this final advisory covering CVE-2022-31160; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Virtual Desktop Service (VDS); SnapCenter.

Open source
Advisory

CVE-2022-31151 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0006/

NetApp published this final advisory covering CVE-2022-31151; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31144 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0002/

NetApp published this final advisory covering CVE-2022-31144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2191 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0003/

NetApp published this final advisory covering CVE-2022-2191; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-17498 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0004/

NetApp published this interim advisory covering CVE-2019-17498; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

July 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0007/

NetApp published this interim advisory covering CVE-2022-36879, CVE-2022-36946; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

July 2022 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0010/

NetApp published this final advisory covering CVE-2022-31097, CVE-2022-31107; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2022-37434 Zlib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0005/

NetApp published this final advisory covering CVE-2022-37434; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; OnCommand Workflow Automation; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2022-36129 HashiCorp Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0011/

NetApp published this final advisory covering CVE-2022-36129; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-36123 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0003/

NetApp published this final advisory covering CVE-2022-36123; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-25647 Google Gson Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0009/

NetApp published this final advisory covering CVE-2022-25647; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2022-23240 Improper Authorization Vulnerability in Active IQ Unified Manager

Source: https://security.netapp.com/advisory/NTAP-20220901-0002/

NetApp published this final advisory covering CVE-2022-23240; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-1671 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0004/

NetApp published this final advisory covering CVE-2022-1671; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1651 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0008/

NetApp published this final advisory covering CVE-2022-1651; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2020-28445 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0012/

NetApp published this final advisory covering CVE-2020-28445; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2022 Eclipse Jetty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0006/

NetApp published this interim advisory covering CVE-2022-2047, CVE-2022-2048; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); SnapCenter.

Open source
Advisory

June 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0001/

NetApp published this final advisory covering CVE-2022-2056, CVE-2022-2057, CVE-2022-2058; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-34918 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0004/

NetApp published this final advisory covering CVE-2022-34918; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-34903 GnuPG Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0005/

NetApp published this final advisory covering CVE-2022-34903; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-32086 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0007/

NetApp published this final advisory covering CVE-2022-32086; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32083 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0006/

NetApp published this final advisory covering CVE-2022-32083; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31627 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0008/

NetApp published this final advisory covering CVE-2022-31627; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-40663 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0002/

NetApp published this final advisory covering CVE-2021-40663; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220818-0005/

NetApp published this final advisory covering CVE-2022-32089, CVE-2022-32081, CVE-2022-32088, CVE-2022-32087, CVE-2022-32082, CVE-2022-32085, CVE-2022-32084, CVE-2022-32091; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00601 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220818-0003/

NetApp published this final advisory covering CVE-2021-0153, CVE-2021-0154, CVE-2021-0155, CVE-2021-0159, CVE-2021-0188, CVE-2021-0189, CVE-2021-0190, CVE-2021-33103, CVE-2021-33122, CVE-2021-33123, CVE-2021-33124; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00598 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220818-0004/

NetApp published this final advisory covering CVE-2022-0001, CVE-2022-0002; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-34265 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220818-0006/

NetApp published this final advisory covering CVE-2022-34265; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-33879 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220812-0004/

NetApp published this final advisory covering CVE-2022-33879; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32532 Apache Shiro Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220812-0002/

NetApp published this final advisory covering CVE-2022-32532; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-29582 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220812-0006/

NetApp published this final advisory covering CVE-2022-29582; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-26477 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220812-0003/

NetApp published this final advisory covering CVE-2022-26477; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23055 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220812-0001/

NetApp published this final advisory covering CVE-2021-23055; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2022-29078 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220804-0001/

NetApp published this final advisory covering CVE-2022-29078; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-25169 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220804-0004/

NetApp published this final advisory covering CVE-2022-25169; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3717 Wildfly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220804-0002/

NetApp published this final advisory covering CVE-2021-3717; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3597 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220804-0003/

NetApp published this final advisory covering CVE-2021-3597; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2017-20052 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220804-0005/

NetApp published this final advisory covering CVE-2017-20052; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2022 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0007/

NetApp published this final advisory covering CVE-2022-22389, CVE-2022-22390; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2022 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0010/

NetApp published this final advisory covering CVE-2022-2031, CVE-2022-32742, CVE-2022-32744, CVE-2022-32745, CVE-2022-32746; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2022 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0004/

NetApp published this final advisory covering CVE-2018-25032, CVE-2022-1292, CVE-2022-21455, CVE-2022-21509, CVE-2022-21515, CVE-2022-21517, CVE-2022-21519, CVE-2022-21522, CVE-2022-21525, CVE-2022-21526, CVE-2022-21527, CVE-2022-21528, CVE-2022-21529, CVE-2022-21530, CVE-2022-21531, CVE-2022-21534, CVE-2022-21537, CVE-2022-21538, CVE-2022-21539, CVE-2022-21547, CVE-2022-21550, CVE-2022-21553, CVE-2022-21556, CVE-2022-21569, CVE-2022-21824, CVE-2022-27778; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2022 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0009/

NetApp published this interim advisory covering CVE-2022-21540, CVE-2022-21541, CVE-2022-21549, CVE-2022-34169; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-34305 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0006/

NetApp published this final advisory covering CVE-2022-34305; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-33105 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0005/

NetApp published this final advisory covering CVE-2022-33105; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23708 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0003/

NetApp published this final advisory covering CVE-2022-23708; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3629 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0008/

NetApp published this final advisory covering CVE-2021-3629; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

July 2022 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0005/

NetApp published this final advisory covering CVE-2022-31625, CVE-2022-31626; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32981 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0006/

NetApp published this final advisory covering CVE-2022-32981; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-30973 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0004/

NetApp published this final advisory covering CVE-2022-30973; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-29244 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0007/

NetApp published this final advisory covering CVE-2022-29244; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1786 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0001/

NetApp published this final advisory covering CVE-2022-1786; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1652 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0002/

NetApp published this final advisory covering CVE-2022-1652; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-33036 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0003/

NetApp published this final advisory covering CVE-2021-33036; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2022 Redis Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0003/

NetApp published this final advisory covering CVE-2022-24735, CVE-2022-24736; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2022-32275 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0008/

NetApp published this final advisory covering CVE-2022-32275; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32250 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0005/

NetApp published this final advisory covering CVE-2022-32250; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-29968 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0009/

NetApp published this final advisory covering CVE-2022-29968; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2022-29824 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0006/

NetApp published this interim advisory covering CVE-2022-29824; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-2274 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0010/

NetApp published this final advisory covering CVE-2022-2274; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; SnapCenter.

Open source
Advisory

CVE-2022-2097 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0011/

NetApp published this final advisory covering CVE-2022-2097; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SMI-S Provider; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapCenter; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-1882 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0002/

NetApp published this final advisory covering CVE-2022-1882; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1678 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0001/

NetApp published this final advisory covering CVE-2022-1678; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; E-Series SANtricity OS Controller Software 11.x; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2021-37404 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0007/

NetApp published this final advisory covering CVE-2021-37404; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-33473 Ruby Gem Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0004/

NetApp published this final advisory covering CVE-2021-33473; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2022 Spring Security Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0003/

NetApp published this final advisory covering CVE-2022-22978, CVE-2022-22976; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

June 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0006/

NetApp published this final advisory covering CVE-2022-31621, CVE-2022-31622, CVE-2022-31623, CVE-2022-31624; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-30594 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0001/

NetApp published this final advisory covering CVE-2022-30594; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-29170 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0005/

NetApp published this final advisory covering CVE-2022-29170; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-28660 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0004/

NetApp published this final advisory covering CVE-2022-28660; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23712 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0010/

NetApp published this final advisory covering CVE-2022-23712; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2068 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0008/

NetApp published this interim advisory covering CVE-2022-2068; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-1998 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0009/

NetApp published this final advisory covering CVE-2022-1998; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1734 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0007/

NetApp published this final advisory covering CVE-2022-1734; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1183 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0002/

NetApp published this final advisory covering CVE-2022-1183; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

May 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0001/

NetApp published this final advisory covering CVE-2022-1353, CVE-2022-1048; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-30689 HashiCorp Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0006/

NetApp published this final advisory covering CVE-2022-30689; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-29885 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0002/

NetApp published this final advisory covering CVE-2022-29885; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-29581 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0005/

NetApp published this final advisory covering CVE-2022-29581; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-29218 RubyGems Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0010/

NetApp published this final advisory covering CVE-2022-29218; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-25844 AngularJS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0009/

NetApp published this interim advisory covering CVE-2022-25844; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Virtual Desktop Service (VDS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-25762 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0003/

NetApp published this final advisory covering CVE-2022-25762; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1679 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0007/

NetApp published this final advisory covering CVE-2022-1679; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1116 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0004/

NetApp published this final advisory covering CVE-2022-1116; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2018-10237 Guava Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0008/

NetApp published this interim advisory covering CVE-2018-10237; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Insights Acquisition Unit; Cloud Insights Storage Workload Security Agent; OnCommand Insight.

Open source
Advisory

CVE-2022-28168 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20220627-0003/

NetApp published this final advisory covering CVE-2022-28168; the API labels exploitation information as **Not public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-28167 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20220627-0002/

NetApp published this final advisory covering CVE-2022-28167; the API labels exploitation information as **Not public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-28166 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20220627-0001/

NetApp published this final advisory covering CVE-2022-28166; the API labels exploitation information as **Not public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

May 2022 Ruby Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0002/

NetApp published this final advisory covering CVE-2022-28738, CVE-2022-28739; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2022 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0005/

NetApp published this final advisory covering CVE-2022-28615, CVE-2022-29404, CVE-2022-30522, CVE-2022-26377, CVE-2022-31813, CVE-2022-30556, CVE-2022-28330, CVE-2022-28614; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

Intel SA-00615 Intel Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0008/

NetApp published this final advisory covering CVE-2022-21123, CVE-2022-21125, CVE-2022-21127, CVE-2022-21166; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-30126 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0004/

NetApp published this final advisory covering CVE-2022-30126; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-21180 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0006/

NetApp published this final advisory covering CVE-2022-21180; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3750 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0003/

NetApp published this final advisory covering CVE-2021-3750; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3611 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0001/

NetApp published this final advisory covering CVE-2021-3611; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220616-0005/

NetApp published this final advisory covering CVE-2022-1622, CVE-2022-1623; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-29176 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220616-0002/

NetApp published this final advisory covering CVE-2022-29176; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24823 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220616-0004/

NetApp published this final advisory covering CVE-2022-24823; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2022-22970 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220616-0006/

NetApp published this final advisory covering CVE-2022-22970; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); OnCommand Insight.

Open source
Advisory

CVE-2015-20107 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220616-0001/

NetApp published this interim advisory covering CVE-2015-20107; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility; SnapCenter.

Open source
Advisory

May 2022 Libcurl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0008/

NetApp published this interim advisory covering CVE-2022-22576, CVE-2022-27774, CVE-2022-27775, CVE-2022-27776; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

May 2022 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0006/

NetApp published this final advisory covering CVE-2021-25745, CVE-2021-25746; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2022 Libcurl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0009/

NetApp published this interim advisory covering CVE-2022-27778, CVE-2022-27779, CVE-2022-27780, CVE-2022-27781, CVE-2022-27782, CVE-2022-30115; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

CVE-2022-29155 OpenLDAP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0007/

NetApp published this final advisory covering CVE-2022-29155; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-28346 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0002/

NetApp published this final advisory covering CVE-2022-28346; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24857 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0003/

NetApp published this final advisory covering CVE-2022-24857; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-41303 Apache Shiro Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0001/

NetApp published this final advisory covering CVE-2021-41303; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3503 WildFly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0004/

NetApp published this final advisory covering CVE-2021-3503; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2021-32040 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0005/

NetApp published this final advisory covering CVE-2021-32040; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2022 Systemd Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0008/

NetApp published this final advisory covering CVE-2022-29799, CVE-2022-29800; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2022 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0009/

NetApp published this interim advisory covering CVE-2022-1292, CVE-2022-1343, CVE-2022-1434, CVE-2022-1473; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

March 2022 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0003/

NetApp published this final advisory covering CVE-2021-20464, CVE-2021-29824, CVE-2021-38886, CVE-2021-38903, CVE-2021-38904, CVE-2021-38905, CVE-2021-38946; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2022-29156 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0002/

NetApp published this final advisory covering CVE-2022-29156; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-29153 HashiCorp Consul Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0005/

NetApp published this final advisory covering CVE-2022-29153; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-22968 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0004/

NetApp published this final advisory covering CVE-2022-22968; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; MetroCluster Tiebreaker for clustered Data ONTAP; Snap Creator Framework.

Open source
Advisory

CVE-2022-0435 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0001/

NetApp published this final advisory covering CVE-2022-0435; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-4197 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0006/

NetApp published this final advisory covering CVE-2021-4197; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4157 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0007/

NetApp published this final advisory covering CVE-2021-4157; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

May 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0006/

NetApp published this final advisory covering CVE-2022-27452, CVE-2022-27451, CVE-2022-27449, CVE-2022-27447, CVE-2022-27446, CVE-2022-27445, CVE-2022-27444, CVE-2022-27448; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-28893 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0002/

NetApp published this final advisory covering CVE-2022-28893; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-27385 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0008/

NetApp published this final advisory covering CVE-2022-27385; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-27379 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0005/

NetApp published this final advisory covering CVE-2022-27379; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0330 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0001/

NetApp published this final advisory covering CVE-2022-0330; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-29752 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0003/

NetApp published this final advisory covering CVE-2021-29752; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-25032 Zlib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0009/

NetApp published this interim advisory covering CVE-2018-25032; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; OnCommand Workflow Automation.

Open source
Advisory

April 2022 MariaDB v10.6.3 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0007/

NetApp published this final advisory covering CVE-2022-27377, CVE-2022-27380, CVE-2022-27455, CVE-2022-27456, CVE-2022-27457, CVE-2022-27458; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0004/

NetApp published this final advisory covering CVE-2022-27378, CVE-2022-27382, CVE-2022-27386, CVE-2022-27387; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0006/

NetApp published this final advisory covering CVE-2022-27381, CVE-2022-27383, CVE-2022-27384; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-27376 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0007/

NetApp published this final advisory covering CVE-2022-27376; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-26612 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0004/

NetApp published this final advisory covering CVE-2022-26612; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24812 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0005/

NetApp published this final advisory covering CVE-2022-24812; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0897 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0002/

NetApp published this final advisory covering CVE-2022-0897; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-0500 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0001/

NetApp published this final advisory covering CVE-2022-0500; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-20295 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0003/

NetApp published this final advisory covering CVE-2021-20295; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2022 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0008/

NetApp published this final advisory covering CVE-2022-27007, CVE-2022-27008, CVE-2022-28049; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2022-24785 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0006/

NetApp published this final advisory covering CVE-2022-24785; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ mobile app.

Open source
Advisory

CVE-2022-1210 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0005/

NetApp published this final advisory covering CVE-2022-1210; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-0998 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0003/

NetApp published this final advisory covering CVE-2022-0998; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4202 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0002/

NetApp published this final advisory covering CVE-2021-4202; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4147 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0004/

NetApp published this final advisory covering CVE-2021-4147; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

April 2022 Linux Kernel 5.17.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0001/

NetApp published this final advisory covering CVE-2022-28388, CVE-2022-28389, CVE-2022-28390; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

March 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0002/

NetApp published this final advisory covering CVE-2022-0907, CVE-2022-0908, CVE-2022-0909, CVE-2022-0924; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-1055 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0007/

NetApp published this final advisory covering CVE-2022-1055; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2020-36518 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0004/

NetApp published this final advisory covering CVE-2020-36518; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); OnCommand Insight; OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

CVE-2019-5188 E2fsprogs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0001/

NetApp published this interim advisory covering CVE-2019-5188; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2017-12652 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0003/

NetApp published this final advisory covering CVE-2017-12652; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

April 2022 OpenBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0005/

NetApp published this final advisory covering CVE-2022-27881, CVE-2022-27882; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0006/

NetApp published this interim advisory covering CVE-2022-28356, CVE-2022-28796; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

March 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0001/

NetApp published this final advisory covering CVE-2022-27666, CVE-2022-0995; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-27191 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0002/

NetApp published this final advisory covering CVE-2022-27191; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-26490 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0004/

NetApp published this final advisory covering CVE-2022-26490; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3582 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0003/

NetApp published this final advisory covering CVE-2021-3582; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2022 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0005/

NetApp published this final advisory covering CVE-2021-22570, CVE-2022-0778, CVE-2022-21412, CVE-2022-21413, CVE-2022-21414, CVE-2022-21415, CVE-2022-21417, CVE-2022-21418, CVE-2022-21423, CVE-2022-21425, CVE-2022-21427, CVE-2022-21435, CVE-2022-21436, CVE-2022-21437, CVE-2022-21438, CVE-2022-21440, CVE-2022-21444, CVE-2022-21451, CVE-2022-21452, CVE-2022-21454, CVE-2022-21457, CVE-2022-21459, CVE-2022-21460, CVE-2022-21462, CVE-2022-21478, CVE-2022-21479, CVE-2022-21482, CVE-2022-21483, CVE-2022-21484, CVE-2022-21485, CVE-2022-21486, CVE-2022-21489, CVE-2022-21490; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2022 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0006/

NetApp published this interim advisory covering CVE-2022-21426, CVE-2022-21434, CVE-2022-21443, CVE-2022-21449, CVE-2022-21476, CVE-2022-21496; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

March 2022 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220425-0003/

NetApp published this final advisory covering CVE-2022-26353, CVE-2022-26354, CVE-2021-20257; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-26148 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220425-0005/

NetApp published this final advisory covering CVE-2022-26148; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1011 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220425-0002/

NetApp published this final advisory covering CVE-2022-1011; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-0742 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220425-0001/

NetApp published this final advisory covering CVE-2022-0742; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3748 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220425-0004/

NetApp published this final advisory covering CVE-2021-3748; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31805 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220420-0001/

NetApp published this final advisory covering CVE-2021-31805; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220419-0001/

NetApp published this final advisory covering CVE-2022-26966, CVE-2022-27223; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

February 2022 Linux Kernel 5.15.2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220419-0003/

NetApp published this final advisory covering CVE-2021-3640, CVE-2021-45868; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-26488 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220419-0005/

NetApp published this final advisory covering CVE-2022-26488; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-0492 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220419-0002/

NetApp published this final advisory covering CVE-2022-0492; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-3609 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220419-0004/

NetApp published this interim advisory covering CVE-2021-3609; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

March 2022 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220408-0001/

NetApp published this final advisory covering CVE-2021-25220, CVE-2022-0396, CVE-2022-0635, CVE-2022-0667; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

February 2022 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0004/

NetApp published this final advisory covering CVE-2021-46708, CVE-2018-25031; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23812 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0005/

NetApp published this final advisory covering CVE-2022-23812; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3743 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0007/

NetApp published this final advisory covering CVE-2021-3743; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3739 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0006/

NetApp published this final advisory covering CVE-2021-3739; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3737 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0009/

NetApp published this final advisory covering CVE-2021-3737; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp XCP NFS; NetApp XCP SMB; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3733 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0001/

NetApp published this interim advisory covering CVE-2021-3733; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3677 Postgresql Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0008/

NetApp published this final advisory covering CVE-2021-3677; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3658 BlueZ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0002/

NetApp published this final advisory covering CVE-2021-3658; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3638 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0003/

NetApp published this final advisory covering CVE-2021-3638; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-22950 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220401-0001/

NetApp published this final advisory covering CVE-2022-22950; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); MetroCluster Tiebreaker for clustered Data ONTAP; OnCommand Insight; Snap Creator Framework; SnapManager for Oracle.

Open source
Advisory

CVE-2022-25365 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0001/

NetApp published this final advisory covering CVE-2022-25365; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24687 HashiCorp Consul Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0006/

NetApp published this final advisory covering CVE-2022-24687; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24685 HashiCorp Nomad Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0007/

NetApp published this final advisory covering CVE-2022-24685; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23308 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0008/

NetApp published this interim advisory covering CVE-2022-23308; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-22965 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0011/

NetApp published this final advisory covering CVE-2022-22965; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0563 Util-linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0002/

NetApp published this final advisory covering CVE-2022-0563; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-0543 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0004/

NetApp published this final advisory covering CVE-2022-0543; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0516 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0009/

NetApp published this final advisory covering CVE-2022-0516; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3667 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0005/

NetApp published this final advisory covering CVE-2021-3667; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3631 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0010/

NetApp published this final advisory covering CVE-2021-3631; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-36516 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0003/

NetApp published this interim advisory covering CVE-2020-36516; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

March 2022 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0007/

NetApp published this final advisory covering CVE-2022-21824, CVE-2021-44531, CVE-2021-44532, CVE-2021-44533; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2022 NPM Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0006/

NetApp published this final advisory covering CVE-2022-0686, CVE-2022-0691; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2021 Grub2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0001/

NetApp published this final advisory covering CVE-2020-25632, CVE-2020-25647, CVE-2020-27749, CVE-2020-27779, CVE-2021-20225, CVE-2021-20233; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-25636 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0002/

NetApp published this final advisory covering CVE-2022-25636; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-24921 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0010/

NetApp published this final advisory covering CVE-2022-24921; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Astra Trident; Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2022-23710 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0009/

NetApp published this final advisory covering CVE-2022-23710; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23395 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0008/

NetApp published this final advisory covering CVE-2022-23395; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0847 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0005/

NetApp published this final advisory covering CVE-2022-0847; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-25217 ISC DHCP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0011/

NetApp published this final advisory covering CVE-2021-25217; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-21708 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0004/

NetApp published this final advisory covering CVE-2021-21708; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-14844 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0003/

NetApp published this final advisory covering CVE-2019-14844; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23235 Information Disclosure Vulnerability in Active IQ Unified Manager

Source: https://security.netapp.com/advisory/NTAP-20220324-0001/

NetApp published this final advisory covering CVE-2022-23235; the API labels exploitation information as **Not public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

March 2022 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220321-0001/

NetApp published this final advisory covering CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0778 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220321-0002/

NetApp published this interim advisory covering CVE-2022-0778; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; Cloud Volumes ONTAP Mediator; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Service Processor - 2554/2552/2520; FAS/AFF Service Processor - 8080/8060/8040/8020; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp Storage Encryption; ONTAP 9; ONTAP Antivirus Connector; ONTAP tools for VMware vSphere 9; SnapManager for Hyper-V; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

February 2022 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0002/

NetApp published this final advisory covering CVE-2021-3607, CVE-2021-3608; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0004/

NetApp published this final advisory covering CVE-2022-24048, CVE-2022-24050, CVE-2022-24051, CVE-2022-24052; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0001/

NetApp published this final advisory covering CVE-2022-0561, CVE-2022-0562; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

February 2022 HashiCorp Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0008/

NetApp published this final advisory covering CVE-2022-24683, CVE-2022-24684, CVE-2022-24686; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-25265 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0005/

NetApp published this interim advisory covering CVE-2022-25265; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2022-0646 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0006/

NetApp published this final advisory covering CVE-2022-0646; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4090 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0010/

NetApp published this final advisory covering CVE-2021-4090; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3947 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0003/

NetApp published this final advisory covering CVE-2021-3947; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3760 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0007/

NetApp published this final advisory covering CVE-2021-3760; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3752 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0009/

NetApp published this final advisory covering CVE-2021-3752; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-22844 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220311-0002/

NetApp published this final advisory covering CVE-2022-22844; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-21724 PostgreSQL JDBC Driver Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220311-0005/

NetApp published this final advisory covering CVE-2022-21724; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-46659 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220311-0003/

NetApp published this final advisory covering CVE-2021-46659; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-4145 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220311-0004/

NetApp published this final advisory covering CVE-2021-4145; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-33150 Intel Trace Hub Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220311-0001/

NetApp published this final advisory covering CVE-2021-33150; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2022 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220303-0007/

NetApp published this final advisory covering CVE-2022-25139, CVE-2021-46461, CVE-2021-46462, CVE-2021-46463; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

February 2022 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220303-0005/

NetApp published this final advisory covering CVE-2022-21702, CVE-2022-21703, CVE-2022-21713; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

February 2022 Expat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220303-0008/

NetApp published this interim advisory covering CVE-2022-25235, CVE-2022-25236, CVE-2022-25313, CVE-2022-25314, CVE-2022-25315; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; ONTAP 9; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-21673 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220303-0004/

NetApp published this final advisory covering CVE-2022-21673; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-45346 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220303-0001/

NetApp published this final advisory covering CVE-2021-45346; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-41816 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220303-0006/

NetApp published this final advisory covering CVE-2021-41816; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20322 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220303-0002/

NetApp published this interim advisory covering CVE-2021-20322; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

February 2022 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0006/

NetApp published this final advisory covering CVE-2022-23772, CVE-2022-23773, CVE-2022-23806; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; BeeGFS CSI Driver; Cloud Insights Telegraf Agent; NetApp Kubernetes Monitoring Operator; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2022-24958 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0008/

NetApp published this interim advisory covering CVE-2022-24958; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

CVE-2022-0391 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0009/

NetApp published this interim advisory covering CVE-2022-0391; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-0185 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0003/

NetApp published this final advisory covering CVE-2022-0185; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-44521 Apache Cassandra Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0001/

NetApp published this final advisory covering CVE-2021-44521; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-4154 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0004/

NetApp published this final advisory covering CVE-2021-4154; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2021-3930 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0007/

NetApp published this final advisory covering CVE-2021-3930; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20373 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0005/

NetApp published this final advisory covering CVE-2021-20373; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8562 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0002/

NetApp published this final advisory covering CVE-2020-8562; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-41842 InsydeH2O Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220223-0002/

NetApp published this final advisory covering CVE-2021-41842; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/A200/2650/2620/C190/A220/2720/2750/A150.

Open source
Advisory

CVE-2020-5956 InsydeH2O Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220223-0001/

NetApp published this final advisory covering CVE-2020-5956; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-5955 InsydeH2O Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220223-0003/

NetApp published this final advisory covering CVE-2020-5955; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-12532 InsydeH2O Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220223-0004/

NetApp published this final advisory covering CVE-2019-12532; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-41837 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220222-0003/

NetApp published this final advisory covering CVE-2021-41837; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/C190/A220/2720/2750/A150; FAS/AFF BIOS - A700/9000; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2021-33627 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220222-0002/

NetApp published this final advisory covering CVE-2021-33627; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/A200/2650/2620/C190/A220/2720/2750.

Open source
Advisory

CVE-2021-33625 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220222-0004/

NetApp published this final advisory covering CVE-2021-33625; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-5953 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220222-0005/

NetApp published this final advisory covering CVE-2020-5953; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220221-0002/

NetApp published this final advisory covering CVE-2021-46657, CVE-2021-46658, CVE-2021-46661, CVE-2021-46662, CVE-2021-46663, CVE-2021-46664, CVE-2021-46665, CVE-2021-46666, CVE-2021-46667, CVE-2021-46668, CVE-2021-46669; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2022 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220221-0003/

NetApp published this final advisory covering CVE-2022-22818, CVE-2022-23833; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24122 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220221-0001/

NetApp published this final advisory covering CVE-2022-24122; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2019-16884 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220221-0004/

NetApp published this final advisory covering CVE-2019-16884; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23852 Expat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0001/

NetApp published this interim advisory covering CVE-2022-23852; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP 9.

Open source
Advisory

CVE-2022-23222 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0002/

NetApp published this interim advisory covering CVE-2022-23222; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2022-23181 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0010/

NetApp published this final advisory covering CVE-2022-23181; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-43323 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0013/

NetApp published this final advisory covering CVE-2021-43323; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/C190/A220/2720/2750/A150; FAS/AFF BIOS - A700/9000; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2021-42060 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0015/

NetApp published this final advisory covering CVE-2021-42060; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/C190/A220/2720/2750/A150; FAS/AFF BIOS - A700/9000.

Open source
Advisory

CVE-2021-41841 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0012/

NetApp published this interim advisory covering CVE-2021-41841; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/A200/2650/2620/C190/A220/2720/2750; FAS/AFF BIOS - A700/9000; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2021-41840 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0014/

NetApp published this final advisory covering CVE-2021-41840; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-4083 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0005/

NetApp published this interim advisory covering CVE-2021-4083; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2021-39293 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0009/

NetApp published this final advisory covering CVE-2021-39293; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2021-34866 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0008/

NetApp published this final advisory covering CVE-2021-34866; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2021-29632 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0004/

NetApp published this final advisory covering CVE-2021-29632; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-25743 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0003/

NetApp published this final advisory covering CVE-2021-25743; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2022 InsydeH2O Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0004/

NetApp published this final advisory covering CVE-2021-45969, CVE-2021-45970, CVE-2021-45971; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2022-24069 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0002/

NetApp published this final advisory covering CVE-2022-24069; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/C190/A220/2720/2750/A150; FAS/AFF BIOS - A700/9000; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2022-24030 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0011/

NetApp published this final advisory covering CVE-2022-24030; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/C190/A220/2720/2750/A150; FAS/AFF BIOS - A700/9000; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2021-43615 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0010/

NetApp published this final advisory covering CVE-2021-43615; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-43522 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0003/

NetApp published this final advisory covering CVE-2021-43522; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-42554 InsydeH2O Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0007/

NetApp published this interim advisory covering CVE-2021-42554; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/A200/2650/2620/C190/A220/2720/2750; FAS/AFF BIOS - A700/9000; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2021-42113 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0012/

NetApp published this final advisory covering CVE-2021-42113; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-42059 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0008/

NetApp published this final advisory covering CVE-2021-42059; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-27339 InsydeH2O Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0005/

NetApp published this final advisory covering CVE-2020-27339; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-19343 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220211-0002/

NetApp published this final advisory covering CVE-2019-19343; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-14888 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220211-0001/

NetApp published this final advisory covering CVE-2019-14888; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

Intel SA-00571 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0010/

NetApp published this final advisory covering CVE-2021-33061, CVE-2021-33096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00527 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0007/

NetApp published this interim advisory covering CVE-2021-0091, CVE-2021-0092, CVE-2021-0093, CVE-2021-0099, CVE-2021-0103, CVE-2021-0107, CVE-2021-0111, CVE-2021-0114, CVE-2021-0115, CVE-2021-0116, CVE-2021-0117, CVE-2021-0118, CVE-2021-0119, CVE-2021-0124, CVE-2021-0125, CVE-2021-0156; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series BIOS; FAS/AFF BIOS - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

February 2022 Undertow Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0014/

NetApp published this final advisory covering CVE-2020-10705, CVE-2020-10719; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

February 2022 Apache Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0012/

NetApp published this final advisory covering CVE-2021-37136, CVE-2021-37137; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Cloud Insights Storage Workload Security Agent; OnCommand Insight; SnapCenter.

Open source
Advisory

CVE-2021-37714 jsoup Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0022/

NetApp published this final advisory covering CVE-2021-37714; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2021-3690 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0021/

NetApp published this final advisory covering CVE-2021-3690; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2021-33068 Intel AMT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0006/

NetApp published this final advisory covering CVE-2021-33068; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-29425 Apache Commons IO Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0004/

NetApp published this final advisory covering CVE-2021-29425; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2021-21290 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0011/

NetApp published this final advisory covering CVE-2021-21290; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2021-20220 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0013/

NetApp published this final advisory covering CVE-2021-20220; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2021-0145 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0009/

NetApp published this final advisory covering CVE-2021-0145; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-0127 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0008/

NetApp published this interim advisory covering CVE-2021-0127; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series BIOS; FAS/AFF BIOS - 8300/8700/A400; NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

CVE-2021-0060 Intel SPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0005/

NetApp published this interim advisory covering CVE-2021-0060; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

CVE-2020-8908 Guava Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0003/

NetApp published this final advisory covering CVE-2020-8908; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2020-25711 Infinispan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0023/

NetApp published this final advisory covering CVE-2020-25711; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2020-1954 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0001/

NetApp published this final advisory covering CVE-2020-1954; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Workflow Automation; SnapManager for SAP.

Open source
Advisory

CVE-2020-13956 Apache HttpClient Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0002/

NetApp published this final advisory covering CVE-2020-13956; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

CVE-2020-10687 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0015/

NetApp published this final advisory covering CVE-2020-10687; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2019-3888 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0019/

NetApp published this final advisory covering CVE-2019-3888; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-14900 Hibernate ORM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0020/

NetApp published this final advisory covering CVE-2019-14900; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-10219 Hibernate Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0024/

NetApp published this final advisory covering CVE-2019-10219; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-10212 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0017/

NetApp published this final advisory covering CVE-2019-10212; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-10184 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0016/

NetApp published this final advisory covering CVE-2019-10184; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-10174 Infinispan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0018/

NetApp published this final advisory covering CVE-2019-10174; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-21676 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220209-0002/

NetApp published this final advisory covering CVE-2022-21676; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2020 Apache Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220204-0001/

NetApp published this final advisory covering CVE-2019-20445, CVE-2019-20444, CVE-2020-7238, CVE-2019-16869; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Data Availability Services; OnCommand API Services; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2022-23990 Expat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220204-0006/

NetApp published this interim advisory covering CVE-2022-23990; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; ONTAP 9.

Open source
Advisory

CVE-2021-4160 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220204-0005/

NetApp published this final advisory covering CVE-2021-4160; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SMI-S Provider; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

CVE-2020-25638 Hibernate ORM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220204-0003/

NetApp published this final advisory covering CVE-2020-25638; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Snap Creator Framework.

Open source
Advisory

CVE-2022-0336 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220201-0003/

NetApp published this final advisory covering CVE-2022-0336; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-44142 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220201-0002/

NetApp published this final advisory covering CVE-2021-44142; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-44141 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220201-0001/

NetApp published this final advisory covering CVE-2021-44141; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2022 GNU C Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220131-0003/

NetApp published this final advisory covering CVE-2022-23218, CVE-2022-23219; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

January 2022 Expat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220131-0004/

NetApp published this interim advisory covering CVE-2022-22822, CVE-2022-22823, CVE-2022-22824, CVE-2022-22825, CVE-2022-22826, CVE-2022-22827; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; ONTAP 9; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-22846 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220131-0005/

NetApp published this interim advisory covering CVE-2022-22846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-41817 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220131-0002/

NetApp published this final advisory covering CVE-2021-41817; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22060 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220131-0001/

NetApp published this final advisory covering CVE-2021-22060; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Element Plug-in for vCenter Server; MetroCluster Tiebreaker for clustered Data ONTAP; OnCommand Insight; Snap Creator Framework; SnapCenter.

Open source
Advisory

CVE-2021-4034 PolicyKit Privilege Escalation Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220128-0001/

NetApp published this final advisory covering CVE-2021-4034; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2022 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0008/

NetApp published this final advisory covering CVE-2021-22946, CVE-2022-21245, CVE-2022-21249, CVE-2022-21253, CVE-2022-21254, CVE-2022-21256, CVE-2022-21264, CVE-2022-21265, CVE-2022-21270, CVE-2022-21278, CVE-2022-21279, CVE-2022-21280, CVE-2022-21284, CVE-2022-21285, CVE-2022-21286, CVE-2022-21287, CVE-2022-21288, CVE-2022-21289, CVE-2022-21290, CVE-2022-21297, CVE-2022-21301, CVE-2022-21302, CVE-2022-21303, CVE-2022-21304, CVE-2022-21307, CVE-2022-21308, CVE-2022-21309, CVE-2022-21310, CVE-2022-21311, CVE-2022-21312, CVE-2022-21313, CVE-2022-21314, CVE-2022-21315, CVE-2022-21316, CVE-2022-21317, CVE-2022-21318, CVE-2022-21319, CVE-2022-21320, CVE-2022-21321, CVE-2022-21322, CVE-2022-21323, CVE-2022-21324, CVE-2022-21325, CVE-2022-21326, CVE-2022-21327, CVE-2022-21328, CVE-2022-21329, CVE-2022-21330, CVE-2022-21331, CVE-2022-21332, CVE-2022-21333, CVE-2022-21334, CVE-2022-21335, CVE-2022-21336, CVE-2022-21337, CVE-2022-21339, CVE-2022-21342, CVE-2022-21344, CVE-2022-21348, CVE-2022-21351, CVE-2022-21352, CVE-2022-21355, CVE-2022-21356, CVE-2022-21357, CVE-2022-21358, CVE-2022-21362, CVE-2022-21367, CVE-2022-21368, CVE-2022-21370, CVE-2022-21372, CVE-2022-21374, CVE-2022-21378, CVE-2022-21379, CVE-2022-21380; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2022 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0007/

NetApp published this interim advisory covering CVE-2022-21248, CVE-2022-21271, CVE-2022-21277, CVE-2022-21282, CVE-2022-21283, CVE-2022-21291, CVE-2022-21293, CVE-2022-21294, CVE-2022-21296, CVE-2022-21299, CVE-2022-21305, CVE-2022-21340, CVE-2022-21341, CVE-2022-21349, CVE-2022-21360, CVE-2022-21365, CVE-2022-21366; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Cloud Insights Acquisition Unit; Cloud Insights Storage Workload Security Agent; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

January 2022 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0005/

NetApp published this final advisory covering CVE-2021-45115, CVE-2021-45116, CVE-2021-45452; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-46143 Expat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0006/

NetApp published this interim advisory covering CVE-2021-46143; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; ONTAP 9; OnCommand Workflow Automation.

Open source
Advisory

CVE-2021-45960 Expat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0004/

NetApp published this interim advisory covering CVE-2021-45960; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; OnCommand Workflow Automation.

Open source
Advisory

CVE-2021-45485 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0001/

NetApp published this interim advisory covering CVE-2021-45485; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-44716 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0002/

NetApp published this final advisory covering CVE-2021-44716; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Astra Control Center - NetApp Kubernetes Monitoring Operator; Cloud Insights Telegraf Agent; NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2021-41819 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0003/

NetApp published this final advisory covering CVE-2021-41819; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-42392 H2 Database Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220119-0001/

NetApp published this final advisory covering CVE-2021-42392; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2022 X.Org X Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220114-0004/

NetApp published this final advisory covering CVE-2021-4008, CVE-2021-4009, CVE-2021-4010, CVE-2021-4011; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220114-0003/

NetApp published this final advisory covering CVE-2021-44733, CVE-2021-45469; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

December 2021 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220114-0002/

NetApp published this final advisory covering CVE-2021-29678, CVE-2021-38926, CVE-2021-39002; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2021-44548 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220114-0005/

NetApp published this final advisory covering CVE-2021-44548; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-38931 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220114-0001/

NetApp published this final advisory covering CVE-2021-38931; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-43566 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220110-0001/

NetApp published this final advisory covering CVE-2021-43566; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20316 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220110-0002/

NetApp published this final advisory covering CVE-2021-20316; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2022 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220107-0006/

NetApp published this final advisory covering CVE-2021-43813, CVE-2021-43815; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-45459 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220107-0004/

NetApp published this final advisory covering CVE-2021-45459; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-45100 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220107-0001/

NetApp published this final advisory covering CVE-2021-45100; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-45078 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220107-0002/

NetApp published this final advisory covering CVE-2021-45078; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-43818 lxml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220107-0005/

NetApp published this interim advisory covering CVE-2021-43818; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-44832 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220104-0001/

NetApp published this final advisory covering CVE-2021-44832; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2021 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211229-0004/

NetApp published this final advisory covering CVE-2021-41090, CVE-2021-43798; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-44420 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211229-0006/

NetApp published this final advisory covering CVE-2021-44420; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-43527 Libnss Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211229-0002/

NetApp published this final advisory covering CVE-2021-43527; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-42550 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211229-0001/

NetApp published this final advisory covering CVE-2021-42550; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp BlueXP; NetApp Service Level Manager; Snap Creator Framework.

Open source
Advisory

CVE-2021-41805 HashiCorp Consul Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211229-0007/

NetApp published this final advisory covering CVE-2021-41805; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-4044 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211229-0003/

NetApp published this final advisory covering CVE-2021-4044; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp E-Series Performance Analyzer; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP Select Deploy administration utility; SnapCenter.

Open source
Advisory

CVE-2018-25020 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211229-0005/

NetApp published this final advisory covering CVE-2018-25020; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

November 2021 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211223-0006/

NetApp published this final advisory covering CVE-2021-20470, CVE-2021-20493, CVE-2021-29716, CVE-2021-29719, CVE-2021-29756, CVE-2021-29867, CVE-2021-38909; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

November 2021 BusyBox Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211223-0002/

NetApp published this final advisory covering CVE-2021-42373, CVE-2021-42374, CVE-2021-42375, CVE-2021-42376, CVE-2021-42377, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381, CVE-2021-42382, CVE-2021-42383, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2021-41244 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211223-0001/

NetApp published this final advisory covering CVE-2021-41244; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-4104 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211223-0007/

NetApp published this final advisory covering CVE-2021-4104; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23732 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211223-0004/

NetApp published this final advisory covering CVE-2021-23732; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-21707 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211223-0005/

NetApp published this final advisory covering CVE-2021-21707; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

CVE-2017-5123 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211223-0003/

NetApp published this final advisory covering CVE-2017-5123; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-45105 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211218-0001/

NetApp published this final advisory covering CVE-2021-45105; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager; Cloud Secure Agent; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere.

Open source
Advisory

CVE-2021-45046 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211215-0001/

NetApp published this final advisory covering CVE-2021-45046; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Cloud Insights Acquisition Unit; Cloud Manager; Cloud Secure Agent; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere; OnCommand Insight; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

November 2021 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211210-0001/

NetApp published this final advisory covering CVE-2021-43975, CVE-2021-43976; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

November 2021 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211210-0003/

NetApp published this interim advisory covering CVE-2021-41771, CVE-2021-41772; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00555 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211210-0005/

NetApp published this final advisory covering CVE-2021-33058, CVE-2021-33059, CVE-2021-33098; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00554 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211210-0004/

NetApp published this final advisory covering CVE-2021-0197, CVE-2021-0198, CVE-2021-0199, CVE-2021-0200; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-44228 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211210-0007/

NetApp published this final advisory covering CVE-2021-44228; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Cloud Insights Acquisition Unit; Cloud Manager; Cloud Secure Agent; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere; OnCommand Insight; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2021-43616 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211210-0002/

NetApp published this final advisory covering CVE-2021-43616; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2021 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211206-0001/

NetApp published this final advisory covering CVE-2016-2124, CVE-2020-25717, CVE-2020-25718, CVE-2020-25719, CVE-2020-25721, CVE-2020-25722, CVE-2021-23192, CVE-2021-3738; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2021 BlueZ Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211203-0002/

NetApp published this final advisory covering CVE-2019-8921, CVE-2019-8922; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-41229 BlueZ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211203-0004/

NetApp published this final advisory covering CVE-2021-41229; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3715 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211203-0003/

NetApp published this final advisory covering CVE-2021-3715; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-25742 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211203-0001/

NetApp published this final advisory covering CVE-2021-25742; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23718 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211203-0005/

NetApp published this final advisory covering CVE-2021-23718; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-43267 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211125-0002/

NetApp published this final advisory covering CVE-2021-43267; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-43057 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211125-0001/

NetApp published this final advisory covering CVE-2021-43057; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-41174 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211125-0003/

NetApp published this final advisory covering CVE-2021-41174; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22096 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211125-0005/

NetApp published this final advisory covering CVE-2021-22096; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; MetroCluster Tiebreaker for clustered Data ONTAP; OnCommand Insight; Snap Creator Framework; SnapCenter.

Open source
Advisory

CVE-2011-1075 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211125-0004/

NetApp published this final advisory covering CVE-2011-1075; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

October 2021 jQuery Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211118-0004/

NetApp published this final advisory covering CVE-2021-41182, CVE-2021-41183, CVE-2021-41184; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Virtual Desktop Service (VDS); SnapCenter.

Open source
Advisory

CVE-2021-42739 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211118-0001/

NetApp published this final advisory covering CVE-2021-42739; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-42327 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211118-0005/

NetApp published this final advisory covering CVE-2021-42327; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-38297 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211118-0006/

NetApp published this final advisory covering CVE-2021-38297; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-25219 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211118-0002/

NetApp published this final advisory covering CVE-2021-25219; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-21703 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211118-0003/

NetApp published this final advisory covering CVE-2021-21703; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

October 2021 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211112-0003/

NetApp published this final advisory covering CVE-2021-32028, CVE-2021-32029; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2021 Libwebp Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211112-0001/

NetApp published this final advisory covering CVE-2018-25010, CVE-2018-25012, CVE-2018-25013, CVE-2020-36328, CVE-2020-36329, CVE-2020-36331; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-42252 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211112-0006/

NetApp published this final advisory covering CVE-2021-42252; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-22930 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211112-0002/

NetApp published this final advisory covering CVE-2021-22930; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2021 Redis Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211104-0003/

NetApp published this final advisory covering CVE-2021-32628, CVE-2021-41099, CVE-2021-32672, CVE-2021-32762, CVE-2021-32626, CVE-2021-32627, CVE-2021-32765, CVE-2021-32687, CVE-2021-32675; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

October 2021 Libwebp Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211104-0004/

NetApp published this final advisory covering CVE-2018-25009, CVE-2018-25011, CVE-2018-25014, CVE-2020-36330, CVE-2020-36332; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-42340 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211104-0001/

NetApp published this final advisory covering CVE-2021-42340; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2021-42008 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211104-0002/

NetApp published this final advisory covering CVE-2021-42008; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3580 Nettle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211104-0006/

NetApp published this final advisory covering CVE-2021-3580; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3520 lz4 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211104-0005/

NetApp published this final advisory covering CVE-2021-3520; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-33910 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211104-0008/

NetApp published this final advisory covering CVE-2021-33910; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

September 2021 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211029-0003/

NetApp published this final advisory covering CVE-2021-22945, CVE-2021-22946, CVE-2021-22947; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

September 2021 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211029-0006/

NetApp published this final advisory covering CVE-2021-21704, CVE-2021-21705; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

September 2021 IBM Db2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211029-0005/

NetApp published this final advisory covering CVE-2021-29825, CVE-2021-29763; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2021 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211029-0009/

NetApp published this final advisory covering CVE-2021-42013, CVE-2021-41773, CVE-2021-41524; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-41864 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211029-0004/

NetApp published this interim advisory covering CVE-2021-41864; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-39226 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211029-0008/

NetApp published this final advisory covering CVE-2021-39226; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23449 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211029-0010/

NetApp published this final advisory covering CVE-2021-23449; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-21706 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211029-0007/

NetApp published this final advisory covering CVE-2021-21706; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2021 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211022-0003/

NetApp published this final advisory covering CVE-2021-22926, CVE-2021-22931, CVE-2021-2478, CVE-2021-2479, CVE-2021-2481, CVE-2021-35537, CVE-2021-35546, CVE-2021-35575, CVE-2021-35577, CVE-2021-35583, CVE-2021-35584, CVE-2021-35590, CVE-2021-35591, CVE-2021-35592, CVE-2021-35593, CVE-2021-35594, CVE-2021-35596, CVE-2021-35598, CVE-2021-35602, CVE-2021-35604, CVE-2021-35607, CVE-2021-35608, CVE-2021-35610, CVE-2021-35612, CVE-2021-35613, CVE-2021-35618, CVE-2021-35621, CVE-2021-35622, CVE-2021-35623, CVE-2021-35624, CVE-2021-35625, CVE-2021-35626, CVE-2021-35627, CVE-2021-35628, CVE-2021-35629, CVE-2021-35630, CVE-2021-35631, CVE-2021-35632, CVE-2021-35633, CVE-2021-35634, CVE-2021-35635, CVE-2021-35636, CVE-2021-35637, CVE-2021-35638, CVE-2021-35639, CVE-2021-35640, CVE-2021-35641, CVE-2021-35642, CVE-2021-35643, CVE-2021-35644, CVE-2021-35645, CVE-2021-35646, CVE-2021-35647, CVE-2021-35648, CVE-2021-36222, CVE-2021-3711; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2021 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211022-0004/

NetApp published this interim advisory covering CVE-2021-3517, CVE-2021-35560, CVE-2021-35567, CVE-2021-35550, CVE-2021-3522, CVE-2021-35586, CVE-2021-35564, CVE-2021-35556, CVE-2021-35559, CVE-2021-35561, CVE-2021-35565, CVE-2021-35578, CVE-2021-35603, CVE-2021-35588; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Insights Acquisition Unit; Cloud Secure Agent; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; OnCommand Insight; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP; SolidFire Storage Replication Adapter.

Open source
Advisory

July 2021 Apache Commons Compress Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211022-0001/

NetApp published this final advisory covering CVE-2021-36090, CVE-2021-35515, CVE-2021-35516, CVE-2021-35517; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Insights Acquisition Unit; OnCommand Insight.

Open source
Advisory

CVE-2021-35597 MySQL Client Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211022-0005/

NetApp published this final advisory covering CVE-2021-35597; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2021-20305 Nettle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211022-0002/

NetApp published this final advisory covering CVE-2021-20305; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-41617 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211014-0004/

NetApp published this interim advisory covering CVE-2021-41617; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-41073 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211014-0003/

NetApp published this final advisory covering CVE-2021-41073; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-25740 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211014-0001/

NetApp published this final advisory covering CVE-2021-25740; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8561 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211014-0002/

NetApp published this final advisory covering CVE-2020-8561; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2016-20012 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211014-0005/

NetApp published this final advisory covering CVE-2016-20012; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2021 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211008-0004/

NetApp published this final advisory covering CVE-2021-34798, CVE-2021-36160, CVE-2021-39275, CVE-2021-40438; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); ONTAP 9; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2021-41079 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211008-0005/

NetApp published this final advisory covering CVE-2021-41079; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2021-40839 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211008-0001/

NetApp published this final advisory covering CVE-2021-40839; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-38300 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211008-0003/

NetApp published this final advisory covering CVE-2021-38300; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-25741 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211008-0006/

NetApp published this final advisory covering CVE-2021-25741; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22147 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211008-0002/

NetApp published this final advisory covering CVE-2021-22147; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2021 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211004-0005/

NetApp published this final advisory covering CVE-2020-19143, CVE-2020-19144; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-40490 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211004-0001/

NetApp published this interim advisory covering CVE-2021-40490; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3634 libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211004-0003/

NetApp published this final advisory covering CVE-2021-3634; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-25737 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211004-0004/

NetApp published this final advisory covering CVE-2021-25737; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-16871 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211004-0002/

NetApp published this final advisory covering CVE-2018-16871; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3713 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210923-0006/

NetApp published this final advisory covering CVE-2021-3713; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29631 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210923-0004/

NetApp published this final advisory covering CVE-2021-29631; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-29630 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210923-0005/

NetApp published this final advisory covering CVE-2021-29630; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

August 2021 XStream Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210923-0003/

NetApp published this interim advisory covering CVE-2021-39139, CVE-2021-39140, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145, CVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149, CVE-2021-39150, CVE-2021-39151, CVE-2021-39152, CVE-2021-39153, CVE-2021-39154; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

August 2021 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210923-0001/

NetApp published this final advisory covering CVE-2021-22931, CVE-2021-22940; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-37576 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210917-0005/

NetApp published this final advisory covering CVE-2021-37576; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-33193 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210917-0004/

NetApp published this final advisory covering CVE-2021-33193; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-31810 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210917-0001/

NetApp published this final advisory covering CVE-2021-31810; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-30468 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210917-0002/

NetApp published this final advisory covering CVE-2021-30468; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22939 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210917-0003/

NetApp published this final advisory covering CVE-2021-22939; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-38604 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210909-0005/

NetApp published this interim advisory covering CVE-2021-38604; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-38166 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210909-0001/

NetApp published this interim advisory covering CVE-2021-38166; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-36770 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210909-0003/

NetApp published this final advisory covering CVE-2021-36770; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility; Snap Creator Framework.

Open source
Advisory

CVE-2021-25218 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210909-0002/

NetApp published this final advisory covering CVE-2021-25218; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2020-22403 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210909-0004/

NetApp published this final advisory covering CVE-2020-22403; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-38207 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0007/

NetApp published this final advisory covering CVE-2021-38207; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-37600 Util-linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0002/

NetApp published this final advisory covering CVE-2021-37600; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3682 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0006/

NetApp published this final advisory covering CVE-2021-3682; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-33195 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0005/

NetApp published this final advisory covering CVE-2021-33195; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2021-29657 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0008/

NetApp published this final advisory covering CVE-2021-29657; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2012-2666 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0009/

NetApp published this final advisory covering CVE-2012-2666; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2021 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0003/

NetApp published this interim advisory covering CVE-2021-22922, CVE-2021-22923, CVE-2021-22924, CVE-2021-22925, CVE-2021-22926; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

August 2021 Ruby Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0004/

NetApp published this final advisory covering CVE-2021-28966, CVE-2021-31799, CVE-2021-32066; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2021 Linux Kernel 5.13.4 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0010/

NetApp published this interim advisory covering CVE-2021-38160, CVE-2021-38199, CVE-2021-38201, CVE-2021-38202, CVE-2021-38203; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

July 2021 Elasticsearch Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0006/

NetApp published this final advisory covering CVE-2021-22144, CVE-2021-22145; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2021 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0007/

NetApp published this final advisory covering CVE-2021-30639, CVE-2021-30640, CVE-2021-33037; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

Intel SA-00515 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0008/

NetApp published this final advisory covering CVE-2021-0002, CVE-2021-0003, CVE-2021-0084; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00479 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0009/

NetApp published this final advisory covering CVE-2021-0004, CVE-2021-0005, CVE-2021-0006, CVE-2021-0007, CVE-2021-0008, CVE-2021-0009; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-35942 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0005/

NetApp published this final advisory covering CVE-2021-35942; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-32761 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0004/

NetApp published this final advisory covering CVE-2021-32761; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

August 2021 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0010/

NetApp published this interim advisory covering CVE-2021-3711, CVE-2021-3712; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Global File Cache; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Converged Systems Advisor Agent; NetApp E-Series Performance Analyzer; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp Storage Encryption; ONTAP 9; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

May 2021 Brocade Fabric OS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0002/

NetApp published this final advisory covering CVE-2021-27792, CVE-2021-27791, CVE-2021-27790, CVE-2021-27789, CVE-2020-15388, CVE-2020-15386, CVE-2020-15383; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

July 2021 Brocade Fabric OS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0001/

NetApp published this final advisory covering CVE-2021-27793, CVE-2021-27794; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

July 2021 Apache Ant Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0007/

NetApp published this final advisory covering CVE-2021-36373, CVE-2021-36374; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-37159 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0003/

NetApp published this final advisory covering CVE-2021-37159; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-34429 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0006/

NetApp published this final advisory covering CVE-2021-34429; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; SANtricity Storage Plugin for vCenter; Snap Creator Framework; SnapCenter Plug-in for VMware vSphere/BlueXP backup and Recovery for Virtual Machine.

Open source
Advisory

CVE-2021-33909 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0004/

NetApp published this final advisory covering CVE-2021-33909; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-22146 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0005/

NetApp published this final advisory covering CVE-2021-22146; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-35039 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210813-0004/

NetApp published this final advisory covering CVE-2021-35039; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-34558 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210813-0005/

NetApp published this final advisory covering CVE-2021-34558; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident; Cloud Insights Telegraf Agent; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2021-34428 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210813-0003/

NetApp published this final advisory covering CVE-2021-34428; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; NetApp SANtricity Cloud Connector; SANtricity Storage Plugin for vCenter; Snap Creator Framework; SnapManager for SAP.

Open source
Advisory

CVE-2021-32078 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210813-0002/

NetApp published this final advisory covering CVE-2021-32078; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-31535 X.Org X Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210813-0001/

NetApp published this final advisory covering CVE-2021-31535; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

June 2021 Ruby Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0009/

NetApp published this final advisory covering CVE-2021-22904, CVE-2021-22880, CVE-2021-22885; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2021 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0004/

NetApp published this final advisory covering CVE-2021-3592, CVE-2021-3593, CVE-2021-3594, CVE-2021-3595; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2021 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0003/

NetApp published this final advisory covering CVE-2021-22918, CVE-2021-22921; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3612 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0005/

NetApp published this final advisory covering CVE-2021-3612; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3541 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0007/

NetApp published this interim advisory covering CVE-2021-3541; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Manageability SDK; NetApp SMI-S Provider; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix; SnapManager for Hyper-V.

Open source
Advisory

CVE-2021-35042 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0008/

NetApp published this final advisory covering CVE-2021-35042; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28691 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0002/

NetApp published this final advisory covering CVE-2021-28691; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-22555 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0010/

NetApp published this interim advisory covering CVE-2021-22555; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-28097 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0001/

NetApp published this final advisory covering CVE-2020-28097; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2017-20005 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0006/

NetApp published this final advisory covering CVE-2017-20005; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

June 2021 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0007/

NetApp published this final advisory covering CVE-2021-22897, CVE-2021-22901; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

June 2021 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0004/

NetApp published this final advisory covering CVE-2021-33203, CVE-2021-33571; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28169 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0009/

NetApp published this final advisory covering CVE-2021-28169; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Management Services for Element Software and NetApp HCI; Snap Creator Framework.

Open source
Advisory

CVE-2020-36387 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0006/

NetApp published this final advisory covering CVE-2020-36387; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-12067 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0001/

NetApp published this final advisory covering CVE-2019-12067; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2013-4536 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0002/

NetApp published this final advisory covering CVE-2013-4536; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2002-2438 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0003/

NetApp published this final advisory covering CVE-2002-2438; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

July 2021 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210723-0001/

NetApp published this final advisory covering CVE-2019-17543, CVE-2021-22884, CVE-2021-22901, CVE-2021-2339, CVE-2021-2340, CVE-2021-2342, CVE-2021-2352, CVE-2021-2354, CVE-2021-2356, CVE-2021-2357, CVE-2021-2367, CVE-2021-2370, CVE-2021-2372, CVE-2021-2374, CVE-2021-2383, CVE-2021-2384, CVE-2021-2385, CVE-2021-2387, CVE-2021-2389, CVE-2021-2390, CVE-2021-2399, CVE-2021-2402, CVE-2021-2410, CVE-2021-2411, CVE-2021-2412, CVE-2021-2417, CVE-2021-2418, CVE-2021-2422, CVE-2021-2424, CVE-2021-2425, CVE-2021-2426, CVE-2021-2427, CVE-2021-2429, CVE-2021-2437, CVE-2021-2440, CVE-2021-2441, CVE-2021-2444; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2021 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210723-0002/

NetApp published this interim advisory covering CVE-2021-2388, CVE-2021-2369, CVE-2021-2432, CVE-2021-2341; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Secure Agent; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

June 2021 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0008/

NetApp published this final advisory covering CVE-2021-3544, CVE-2021-3545, CVE-2021-3546, CVE-2020-35503; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2021 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0006/

NetApp published this final advisory covering CVE-2020-4885, CVE-2020-4945, CVE-2021-20579, CVE-2021-29703, CVE-2021-29777; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29702 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0005/

NetApp published this final advisory covering CVE-2021-29702; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20181 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0009/

NetApp published this final advisory covering CVE-2021-20181; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-36385 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0004/

NetApp published this final advisory covering CVE-2020-36385; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27661 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0010/

NetApp published this final advisory covering CVE-2020-27661; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-25045 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0003/

NetApp published this interim advisory covering CVE-2019-25045; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2018-25015 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0002/

NetApp published this final advisory covering CVE-2018-25015; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

June 2021 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0007/

NetApp published this final advisory covering CVE-2021-28651, CVE-2021-31806, CVE-2021-31807, CVE-2021-31808; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

June 2021 OpenLDAP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0003/

NetApp published this final advisory covering CVE-2020-25709, CVE-2020-25710; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

June 2021 Linux Kernel 5.12.4 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0004/

NetApp published this final advisory covering CVE-2021-3489, CVE-2021-3490, CVE-2021-3491; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3530 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0006/

NetApp published this final advisory covering CVE-2021-3530; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3516 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0005/

NetApp published this final advisory covering CVE-2021-3516; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SMI-S Provider; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-26707 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0008/

NetApp published this final advisory covering CVE-2021-26707; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-0129 Intel BlueZ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0002/

NetApp published this final advisory covering CVE-2021-0129; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-0051 Intel SPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0001/

NetApp published this final advisory covering CVE-2021-0051; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

May 2021 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210713-0006/

NetApp published this final advisory covering CVE-2020-35504, CVE-2020-35505, CVE-2020-35506; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-32027 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210713-0004/

NetApp published this final advisory covering CVE-2021-32027; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29629 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210713-0003/

NetApp published this final advisory covering CVE-2021-29629; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29628 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210713-0002/

NetApp published this final advisory covering CVE-2021-29628; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3527 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0008/

NetApp published this final advisory covering CVE-2021-3527; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-30465 Opencontainers-runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0003/

NetApp published this final advisory covering CVE-2021-30465; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29505 XStream Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0007/

NetApp published this final advisory covering CVE-2021-29505; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2021-23017 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0006/

NetApp published this final advisory covering CVE-2021-23017; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-22543 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0002/

NetApp published this final advisory covering CVE-2021-22543; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-20221 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0005/

NetApp published this final advisory covering CVE-2021-20221; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20196 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0004/

NetApp published this final advisory covering CVE-2021-20196; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10701 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0001/

NetApp published this final advisory covering CVE-2020-10701; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3559 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0006/

NetApp published this final advisory covering CVE-2021-3559; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-33587 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0007/

NetApp published this final advisory covering CVE-2021-33587; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-33502 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0001/

NetApp published this final advisory covering CVE-2021-33502; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-33200 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0004/

NetApp published this final advisory covering CVE-2021-33200; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-32640 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0005/

NetApp published this final advisory covering CVE-2021-32640; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-31440 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0003/

NetApp published this final advisory covering CVE-2021-31440; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-10688 RESTEasy Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0008/

NetApp published this final advisory covering CVE-2020-10688; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2021 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0008/

NetApp published this final advisory covering CVE-2020-25670, CVE-2020-25671, CVE-2020-25672, CVE-2020-25673; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

June 2021 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0001/

NetApp published this final advisory covering CVE-2019-17567, CVE-2020-13938, CVE-2020-13950, CVE-2020-35452, CVE-2021-26690, CVE-2021-26691, CVE-2021-30641; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

Intel SA-00463 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0002/

NetApp published this interim advisory covering CVE-2020-8670, CVE-2020-8700, CVE-2020-12357, CVE-2020-12358, CVE-2020-12359, CVE-2020-12360, CVE-2020-24486; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series BIOS; FAS/AFF BIOS - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

CVE-2021-33623 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0007/

NetApp published this final advisory covering CVE-2021-33623; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2020-27815 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0004/

NetApp published this final advisory covering CVE-2020-27815; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25724 RESTEasy Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0003/

NetApp published this final advisory covering CVE-2020-25724; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25669 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0006/

NetApp published this final advisory covering CVE-2020-25669; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25668 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0005/

NetApp published this final advisory covering CVE-2020-25668; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3483 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0002/

NetApp published this final advisory covering CVE-2021-3483; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3426 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0003/

NetApp published this final advisory covering CVE-2021-3426; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility; SnapCenter.

Open source
Advisory

CVE-2021-33574 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0005/

NetApp published this final advisory covering CVE-2021-33574; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-22138 Logstash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0001/

NetApp published this final advisory covering CVE-2021-22138; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-14301 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0007/

NetApp published this final advisory covering CVE-2020-14301; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-4588 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0004/

NetApp published this final advisory covering CVE-2019-4588; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-25044 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0006/

NetApp published this final advisory covering CVE-2019-25044; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

May 2021 Libxml2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0002/

NetApp published this final advisory covering CVE-2021-3517, CVE-2021-3518, CVE-2021-3537; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Manageability SDK; NetApp SMI-S Provider; ONTAP 9; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

May 2021 Elasticsearch Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0003/

NetApp published this final advisory covering CVE-2021-22135, CVE-2021-22137; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-33204 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0006/

NetApp published this final advisory covering CVE-2021-33204; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-32606 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0001/

NetApp published this final advisory covering CVE-2021-32606; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-23134 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0007/

NetApp published this final advisory covering CVE-2021-23134; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-0095 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0009/

NetApp published this final advisory covering CVE-2021-0095; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2020-27830 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0004/

NetApp published this final advisory covering CVE-2020-27830; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-24516 Intel CSME Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0008/

NetApp published this final advisory covering CVE-2020-24516; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2020-13529 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0005/

NetApp published this interim advisory covering CVE-2020-13529; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

June 2021 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0004/

NetApp published this final advisory covering CVE-2019-4471, CVE-2019-4653, CVE-2019-4722, CVE-2019-4723, CVE-2019-4724, CVE-2019-4730, CVE-2020-4300, CVE-2020-4354, CVE-2020-4520, CVE-2020-4561; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

February 2021 MySQL Client Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0001/

NetApp published this final advisory covering CVE-2020-14550, CVE-2021-2006, CVE-2021-2007, CVE-2021-2010, CVE-2021-2011; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2021-32399 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0006/

NetApp published this final advisory covering CVE-2021-32399; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-29921 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0003/

NetApp published this final advisory covering CVE-2021-29921; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp XCP NFS; NetApp XCP SMB; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-29491 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0002/

NetApp published this final advisory covering CVE-2021-29491; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29489 Highcharts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0005/

NetApp published this final advisory covering CVE-2021-29489; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2020-15522 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0007/

NetApp published this final advisory covering CVE-2020-15522; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; OnCommand Insight; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter; SnapCenter.

Open source
Advisory

CVE-2021-3501 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0008/

NetApp published this final advisory covering CVE-2021-3501; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-31879 GNU Wget Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0002/

NetApp published this interim advisory covering CVE-2021-31879; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-31597 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0004/

NetApp published this final advisory covering CVE-2021-31597; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31542 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0001/

NetApp published this final advisory covering CVE-2021-31542; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31542 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0010/

NetApp published this final advisory covering CVE-2021-31542; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29484 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0006/

NetApp published this final advisory covering CVE-2021-29484; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28860 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0005/

NetApp published this final advisory covering CVE-2021-28860; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23383 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0007/

NetApp published this final advisory covering CVE-2021-23383; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-21414 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0003/

NetApp published this final advisory covering CVE-2021-21414; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-35519 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0009/

NetApp published this final advisory covering CVE-2020-35519; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

Intel SA-00464 Intel Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0005/

NetApp published this final advisory covering CVE-2020-24511, CVE-2020-24512; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

Intel SA-00459 CSME Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0004/

NetApp published this final advisory covering CVE-2020-8703, CVE-2020-24506, CVE-2020-24507; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-3506 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0007/

NetApp published this final advisory covering CVE-2021-3506; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-32052 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0002/

NetApp published this final advisory covering CVE-2021-32052; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31231 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0001/

NetApp published this final advisory covering CVE-2021-31231; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29469 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0010/

NetApp published this final advisory covering CVE-2021-29469; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-27905 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0009/

NetApp published this final advisory covering CVE-2021-27905; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23133 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0008/

NetApp published this final advisory covering CVE-2021-23133; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-24509 Intel SPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0003/

NetApp published this final advisory covering CVE-2020-24509; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

April 2021 Eclipse Jetty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0006/

NetApp published this final advisory covering CVE-2021-28163, CVE-2021-28164, CVE-2021-28165; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; NetApp BlueXP; NetApp E-Series Performance Analyzer; NetApp SANtricity Cloud Connector; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; ONTAP tools for VMware vSphere 9; SANtricity Storage Plugin for vCenter; SnapCenter; SnapCenter Plug-in for VMware vSphere/BlueXP backup and Recovery for Virtual Machine; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above.

Open source
Advisory

March 2021 Apache Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0003/

NetApp published this final advisory covering CVE-2021-21295, CVE-2021-21409; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand API Services; OnCommand Workflow Automation.

Open source
Advisory

CVE-2021-29662 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0002/

NetApp published this final advisory covering CVE-2021-29662; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); SnapCenter.

Open source
Advisory

CVE-2021-29424 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0007/

NetApp published this final advisory covering CVE-2021-29424; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-29418 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0001/

NetApp published this final advisory covering CVE-2021-29418; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29154 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0006/

NetApp published this final advisory covering CVE-2021-29154; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-26073 Node.JS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0004/

NetApp published this final advisory covering CVE-2021-26073; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23369 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0008/

NetApp published this final advisory covering CVE-2021-23369; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-36313 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0005/

NetApp published this final advisory covering CVE-2020-36313; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-15225 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0010/

NetApp published this final advisory covering CVE-2020-15225; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2021 Apache Solr Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0009/

NetApp published this final advisory covering CVE-2021-29943, CVE-2021-29262; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3507 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0005/

NetApp published this final advisory covering CVE-2021-3507; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-30638 Apache Tapestry Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0004/

NetApp published this final advisory covering CVE-2021-30638; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28965 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0003/

NetApp published this final advisory covering CVE-2021-28965; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28918 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0010/

NetApp published this final advisory covering CVE-2021-28918; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28658 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0001/

NetApp published this final advisory covering CVE-2021-28658; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-27850 Apache Tapestry Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0002/

NetApp published this final advisory covering CVE-2021-27850; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-21267 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0006/

NetApp published this final advisory covering CVE-2021-21267; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer; OnCommand Insight.

Open source
Advisory

CVE-2021-20197 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0009/

NetApp published this final advisory covering CVE-2021-20197; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

March 2021 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0009/

NetApp published this final advisory covering CVE-2020-35521, CVE-2020-35522, CVE-2020-35523, CVE-2020-35524; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-20284 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0010/

NetApp published this final advisory covering CVE-2021-20284; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-27825 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0008/

NetApp published this final advisory covering CVE-2020-27825; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-17516 Apache Cassandra Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0002/

NetApp published this final advisory covering CVE-2020-17516; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-12762 JSON-C Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0001/

NetApp published this final advisory covering CVE-2020-12762; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2021 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0007/

NetApp published this interim advisory covering CVE-2021-22876, CVE-2021-22890; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software).

Open source
Advisory

April 2021 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0006/

NetApp published this final advisory covering CVE-2021-25214, CVE-2021-25215, CVE-2021-25216; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-29266 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0005/

NetApp published this final advisory covering CVE-2021-29266; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-28092 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0008/

NetApp published this final advisory covering CVE-2021-28092; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-27358 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0007/

NetApp published this final advisory covering CVE-2021-27358; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-23926 Apache XMLBeans Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0004/

NetApp published this final advisory covering CVE-2021-23926; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager Core Package; Snap Creator Framework; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2020-35508 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0006/

NetApp published this final advisory covering CVE-2020-35508; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-13954 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0010/

NetApp published this final advisory covering CVE-2020-13954; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; Snap Creator Framework.

Open source
Advisory

April 2021 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0002/

NetApp published this final advisory covering CVE-2020-1971, CVE-2021-3449, CVE-2020-28196, CVE-2021-23841, CVE-2021-2144, CVE-2021-2172, CVE-2021-2298, CVE-2021-2178, CVE-2021-2202, CVE-2021-2307, CVE-2021-2304, CVE-2021-2180, CVE-2021-2194, CVE-2021-2154, CVE-2021-2166, CVE-2021-2196, CVE-2021-2300, CVE-2021-2305, CVE-2021-2179, CVE-2021-2226, CVE-2021-2160, CVE-2021-2164, CVE-2021-2169, CVE-2021-2170, CVE-2021-2193, CVE-2021-2203, CVE-2021-2212, CVE-2021-2213, CVE-2021-2278, CVE-2021-2299, CVE-2021-2230, CVE-2021-2146, CVE-2021-2201, CVE-2021-2208, CVE-2021-2215, CVE-2021-2217, CVE-2021-2293, CVE-2021-2174, CVE-2021-2171, CVE-2021-2162, CVE-2021-2301, CVE-2021-2308, CVE-2021-2232; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2021 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0001/

NetApp published this interim advisory covering CVE-2021-2161, CVE-2021-2163; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Secure Agent; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

March 2021 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0001/

NetApp published this final advisory covering CVE-2021-3392, CVE-2021-3409; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3393 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0006/

NetApp published this final advisory covering CVE-2021-3393; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28660 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0008/

NetApp published this final advisory covering CVE-2021-28660; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-28657 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0004/

NetApp published this final advisory covering CVE-2021-28657; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20255 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0003/

NetApp published this final advisory covering CVE-2021-20255; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-36309 OpenResty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0005/

NetApp published this final advisory covering CVE-2020-36309; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2021 Unbound Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0007/

NetApp published this final advisory covering CVE-2019-25031, CVE-2019-25032, CVE-2019-25033, CVE-2019-25034, CVE-2019-25035, CVE-2019-25036, CVE-2019-25037, CVE-2019-25038, CVE-2019-25039, CVE-2019-25040, CVE-2019-25041, CVE-2019-25042; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2021 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0002/

NetApp published this final advisory covering CVE-2021-3416, CVE-2021-20263; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2021 XStream Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0002/

NetApp published this final advisory covering CVE-2021-21341, CVE-2021-21342, CVE-2021-21343, CVE-2021-21344, CVE-2021-21345, CVE-2021-21346, CVE-2021-21347, CVE-2021-21348, CVE-2021-21349, CVE-2021-21350, CVE-2021-21351; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

March 2021 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0004/

NetApp published this final advisory covering CVE-2019-10127, CVE-2019-10128; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2021 Linux Kernel 5.11.8 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0003/

NetApp published this final advisory covering CVE-2021-28951, CVE-2021-28952, CVE-2021-28964, CVE-2021-28971, CVE-2021-28972; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

March 2021 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0005/

NetApp published this final advisory covering CVE-2021-28147, CVE-2021-28148; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22134 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0006/

NetApp published this final advisory covering CVE-2021-22134; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20254 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0001/

NetApp published this final advisory covering CVE-2021-20254; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29627 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0007/

NetApp published this final advisory covering CVE-2021-29627; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29626 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0008/

NetApp published this final advisory covering CVE-2021-29626; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20227 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0010/

NetApp published this final advisory covering CVE-2021-20227; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25584 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0009/

NetApp published this final advisory covering CVE-2020-25584; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25583 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0004/

NetApp published this final advisory covering CVE-2020-25583; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25582 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0003/

NetApp published this final advisory covering CVE-2020-25582; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25581 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0006/

NetApp published this final advisory covering CVE-2020-25581; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25580 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0005/

NetApp published this final advisory covering CVE-2020-25580; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25577 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0001/

NetApp published this final advisory covering CVE-2020-25577; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2021 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0002/

NetApp published this final advisory covering CVE-2020-25578, CVE-2020-25579; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2021 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0001/

NetApp published this final advisory covering CVE-2021-22883, CVE-2021-22884; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

March 2021 GnuTLS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0005/

NetApp published this final advisory covering CVE-2021-20231, CVE-2021-20232; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-3444 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0006/

NetApp published this final advisory covering CVE-2021-3444; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-28153 GNOME GLib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0003/

NetApp published this final advisory covering CVE-2021-28153; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2021-28041 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0002/

NetApp published this interim advisory covering CVE-2021-28041; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-14372 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0004/

NetApp published this final advisory covering CVE-2020-14372; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

March 2021 Linux Kernel 5.11.3 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0001/

NetApp published this final advisory covering CVE-2021-27363, CVE-2021-27364, CVE-2021-27365, CVE-2021-28038, CVE-2021-28039; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

March 2021 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0003/

NetApp published this final advisory covering CVE-2020-4976, CVE-2020-5024, CVE-2020-5025; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

March 2021 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0002/

NetApp published this final advisory covering CVE-2021-25329, CVE-2021-25122; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Storage Workload Security Agent; Element Plug-in for vCenter Server.

Open source
Advisory

December 2020 XStream Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0005/

NetApp published this final advisory covering CVE-2020-26258, CVE-2020-26259; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20268 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0006/

NetApp published this final advisory covering CVE-2021-20268; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-26217 XStream Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0004/

NetApp published this final advisory covering CVE-2020-26217; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2021-3189 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210401-0004/

NetApp published this final advisory covering CVE-2021-3189; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28375 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210401-0003/

NetApp published this interim advisory covering CVE-2021-28375; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27618 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210401-0006/

NetApp published this final advisory covering CVE-2020-27618; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-27543 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210401-0002/

NetApp published this final advisory covering CVE-2020-27543; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-27223 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210401-0005/

NetApp published this final advisory covering CVE-2020-27223; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; NetApp SolidFire & HCI Management Node; SANtricity Storage Plugin for vCenter; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

March 2021 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0007/

NetApp published this final advisory covering CVE-2021-20277, CVE-2020-27840; the API labels exploitation information as **Not public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2021 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0006/

NetApp published this final advisory covering CVE-2021-3449, CVE-2021-3450; the API labels exploitation information as **Not public**. The API currently lists affected products as: Cloud Volumes ONTAP Mediator; Global File Cache; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp E-Series Performance Analyzer; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility; OnCommand Workflow Automation; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

February 2021 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0001/

NetApp published this final advisory covering CVE-2021-26930, CVE-2021-26931, CVE-2021-26932, CVE-2021-26934; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-27405 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0002/

NetApp published this final advisory covering CVE-2021-27405; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23336 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0004/

NetApp published this final advisory covering CVE-2021-23336; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility; SnapCenter.

Open source
Advisory

CVE-2021-20229 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0005/

NetApp published this final advisory covering CVE-2021-20229; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20194 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0003/

NetApp published this final advisory covering CVE-2021-20194; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

February 2021 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210319-0002/

NetApp published this final advisory covering CVE-2021-27185, CVE-2021-27191; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2021 GNOME GLib Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210319-0004/

NetApp published this final advisory covering CVE-2021-27218, CVE-2021-27219; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-27212 OpenLDAP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210319-0005/

NetApp published this final advisory covering CVE-2021-27212; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-8625 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210319-0001/

NetApp published this final advisory covering CVE-2020-8625; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2020-7021 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210319-0003/

NetApp published this final advisory covering CVE-2020-7021; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-26987 SpringBoot Framework Remote Code Execution Vulnerability in Management Software for Element Software and NetApp HCI

Source: https://security.netapp.com/advisory/NTAP-20210315-0001/

NetApp published this final advisory covering CVE-2021-26987; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; NetApp SolidFire & HCI Management Node.

Open source
Advisory

June 2020 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0001/

NetApp published this final advisory covering CVE-2020-14058, CVE-2020-14059, CVE-2020-15049; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

February 2021 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0005/

NetApp published this final advisory covering CVE-2020-7071, CVE-2021-21702; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.

Open source
Advisory

February 2021 Lodash Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0006/

NetApp published this final advisory covering CVE-2020-28500, CVE-2021-23337; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; System Manager 9.x.

Open source
Advisory

CVE-2021-26708 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0008/

NetApp published this final advisory covering CVE-2021-26708; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-21315 Node.JS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0007/

NetApp published this final advisory covering CVE-2021-21315; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-35517 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0002/

NetApp published this final advisory covering CVE-2020-35517; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-17380 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0003/

NetApp published this final advisory covering CVE-2020-17380; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2020 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0002/

NetApp published this final advisory covering CVE-2020-8449, CVE-2020-8450, CVE-2020-8517; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

CVE-2021-3347 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0005/

NetApp published this final advisory covering CVE-2021-3347; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3326 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0007/

NetApp published this final advisory covering CVE-2021-3326; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-9492 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0001/

NetApp published this final advisory covering CVE-2020-9492; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-29443 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0003/

NetApp published this final advisory covering CVE-2020-29443; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-16119 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0006/

NetApp published this final advisory covering CVE-2020-16119; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

February 2021 OpenLDAP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210226-0002/

NetApp published this final advisory covering CVE-2020-36221, CVE-2020-36222, CVE-2020-36223, CVE-2020-36224, CVE-2020-36225, CVE-2020-36226, CVE-2020-36227, CVE-2020-36228, CVE-2020-36229, CVE-2020-36230; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

February 2021 Docker Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210226-0005/

NetApp published this final advisory covering CVE-2021-21284, CVE-2021-21285; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x.

Open source
Advisory

CVE-2021-3177 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210226-0003/

NetApp published this final advisory covering CVE-2021-3177; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-28488 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210226-0001/

NetApp published this final advisory covering CVE-2020-28488; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2020 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210226-0006/

NetApp published this final advisory covering CVE-2020-15810, CVE-2020-15811, CVE-2020-24606; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

September 2020 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0007/

NetApp published this final advisory covering CVE-2020-15811, CVE-2020-15810, CVE-2020-24606; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

January 2021 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0003/

NetApp published this final advisory covering CVE-2021-1998, CVE-2021-2001, CVE-2021-2002, CVE-2021-2009, CVE-2021-2012, CVE-2021-2014, CVE-2021-2016, CVE-2021-2019, CVE-2021-2020, CVE-2021-2021, CVE-2021-2022, CVE-2021-2024, CVE-2021-2028, CVE-2021-2030, CVE-2021-2031, CVE-2021-2032, CVE-2021-2036, CVE-2021-2038, CVE-2021-2042, CVE-2021-2046, CVE-2021-2048, CVE-2021-2055, CVE-2021-2056, CVE-2021-2058, CVE-2021-2060, CVE-2021-2061, CVE-2021-2065, CVE-2021-2070, CVE-2021-2072, CVE-2021-2076, CVE-2021-2081, CVE-2021-2087, CVE-2021-2088, CVE-2021-2122; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

February 2021 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0009/

NetApp published this final advisory covering CVE-2021-23839, CVE-2021-23840, CVE-2021-23841; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Service Processor - 8080/8060/8040/8020; Global File Cache; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Antivirus Connector; OnCommand Workflow Automation; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

February 2021 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0001/

NetApp published this final advisory covering CVE-2021-3114, CVE-2021-3115; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2021-3121 GoGo Protobuf Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0006/

NetApp published this final advisory covering CVE-2021-3121; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22132 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0004/

NetApp published this final advisory covering CVE-2021-22132; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-21252 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0005/

NetApp published this final advisory covering CVE-2021-21252; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); SnapCenter.

Open source
Advisory

CVE-2021-20190 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0008/

NetApp published this final advisory covering CVE-2021-20190; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Element Plug-in for vCenter Server; NetApp Cloud Backup (formerly AltaVault); NetApp Service Level Manager; OnCommand API Services; OnCommand Insight.

Open source
Advisory

CVE-2020-28374 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0002/

NetApp published this final advisory covering CVE-2020-28374; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

January 2021 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0003/

NetApp published this final advisory covering CVE-2020-8265, CVE-2020-8287; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2021 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0004/

NetApp published this final advisory covering CVE-2020-28851, CVE-2020-28852; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2021 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0007/

NetApp published this final advisory covering CVE-2020-35493, CVE-2020-35494, CVE-2020-35495, CVE-2020-35496, CVE-2020-35507; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

Intel SA-00456 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0005/

NetApp published this final advisory covering CVE-2020-24492, CVE-2020-24493, CVE-2020-24494, CVE-2020-24495, CVE-2020-24496, CVE-2020-24497, CVE-2020-24498, CVE-2020-24500, CVE-2020-24501, CVE-2020-24505; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00438 Graphics Drivers Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0006/

NetApp published this final advisory covering CVE-2020-0544, CVE-2020-0521, CVE-2020-12362, CVE-2020-12361, CVE-2020-24450, CVE-2020-8678, CVE-2020-0518, CVE-2020-12367, CVE-2020-12368, CVE-2020-12369, CVE-2020-12365, CVE-2020-12366, CVE-2020-24448, CVE-2020-12386, CVE-2020-12385, CVE-2020-12384, CVE-2020-12363, CVE-2020-12364, CVE-2020-12370, CVE-2020-12371, CVE-2020-12372, CVE-2020-12373; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-36158 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0002/

NetApp published this final advisory covering CVE-2020-36158; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-11947 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0001/

NetApp published this final advisory covering CVE-2020-11947; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2021 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0006/

NetApp published this final advisory covering CVE-2019-12519, CVE-2019-12520, CVE-2019-12521, CVE-2019-12522, CVE-2019-12524; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

January 2021 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0005/

NetApp published this final advisory covering CVE-2020-36179, CVE-2020-36180, CVE-2020-36181, CVE-2020-36182, CVE-2020-36183, CVE-2020-36184, CVE-2020-36185, CVE-2020-36186, CVE-2020-36187, CVE-2020-36188, CVE-2020-36189; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; NetApp Cloud Backup (formerly AltaVault); NetApp Service Level Manager.

Open source
Advisory

CVE-2020-29569 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0001/

NetApp published this final advisory covering CVE-2020-29569; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27846 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0002/

NetApp published this final advisory covering CVE-2020-27846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-25013 GNU C (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0004/

NetApp published this final advisory covering CVE-2019-25013; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-20808 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0003/

NetApp published this final advisory covering CVE-2019-20808; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2021 Treck TCP/IP Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210201-0003/

NetApp published this final advisory covering CVE-2020-25066, CVE-2020-27337, CVE-2020-27338, CVE-2020-27336; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2021 Sudo Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0010/

NetApp published this final advisory covering CVE-2021-23239, CVE-2021-23240; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node.

Open source
Advisory

December 2020 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0006/

NetApp published this final advisory covering CVE-2020-29509, CVE-2020-29510, CVE-2020-29511; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident.

Open source
Advisory

CVE-2020-4642 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0009/

NetApp published this final advisory covering CVE-2020-4642; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-35728 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0007/

NetApp published this final advisory covering CVE-2020-35728; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; NetApp Cloud Backup (formerly AltaVault); NetApp Service Level Manager.

Open source
Advisory

CVE-2020-35448 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0008/

NetApp published this final advisory covering CVE-2020-35448; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-11724 OpenResty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0002/

NetApp published this final advisory covering CVE-2020-11724; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10732 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0005/

NetApp published this final advisory covering CVE-2020-10732; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-19462 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0004/

NetApp published this final advisory covering CVE-2019-19462; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-17006 Libnss Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0001/

NetApp published this final advisory covering CVE-2019-17006; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-3156 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210128-0002/

NetApp published this final advisory covering CVE-2021-3156; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

Intel SA-00390 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0008/

NetApp published this final advisory covering CVE-2020-8764, CVE-2020-8738, CVE-2020-8740, CVE-2020-8739; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

December 2020 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0007/

NetApp published this final advisory covering CVE-2020-8284, CVE-2020-8285, CVE-2020-8286; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

December 2020 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0001/

NetApp published this final advisory covering CVE-2020-29660, CVE-2020-29661; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

December 2020 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0006/

NetApp published this final advisory covering CVE-2020-8563, CVE-2020-8564, CVE-2020-8566; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2020 GNU C Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0004/

NetApp published this final advisory covering CVE-2020-29562, CVE-2020-29573; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

December 2020 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0003/

NetApp published this final advisory covering CVE-2020-16593, CVE-2020-16599; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

December 2020 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0005/

NetApp published this final advisory covering CVE-2020-35490, CVE-2020-35491; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; NetApp Cloud Backup (formerly AltaVault); NetApp Service Level Manager.

Open source
Advisory

CVE-2020-27786 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0002/

NetApp published this final advisory covering CVE-2020-27786; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

December 2020 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0003/

NetApp published this final advisory covering CVE-2020-16590, CVE-2020-16591, CVE-2020-16592, CVE-2020-16598; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-29374 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0002/

NetApp published this final advisory covering CVE-2020-29374; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-29369 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0001/

NetApp published this final advisory covering CVE-2020-29369; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27821 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0006/

NetApp published this final advisory covering CVE-2020-27821; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-27730 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0004/

NetApp published this final advisory covering CVE-2020-27730; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2020-25613 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0008/

NetApp published this final advisory covering CVE-2020-25613; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-17531 Apache Tapestry Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0007/

NetApp published this final advisory covering CVE-2020-17531; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-17530 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0005/

NetApp published this final advisory covering CVE-2020-17530; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8584 Arbitrary Code Execution Vulnerability in Element OS

Source: https://security.netapp.com/advisory/NTAP-20210108-0008/

NetApp published this final advisory covering CVE-2020-8584; the API labels exploitation information as **Not public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-29368 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0002/

NetApp published this final advisory covering CVE-2020-29368; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-28974 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0003/

NetApp published this final advisory covering CVE-2020-28974; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27350 APT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0005/

NetApp published this final advisory covering CVE-2020-27350; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25692 OpenLDAP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0006/

NetApp published this final advisory covering CVE-2020-25692; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25649 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0007/

NetApp published this final advisory covering CVE-2020-25649; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; OnCommand API Services; OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

CVE-2015-9251 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0004/

NetApp published this interim advisory covering CVE-2015-9251; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-11612 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201223-0001/

NetApp published this final advisory covering CVE-2020-11612; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand API Services; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2020-1749 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201222-0001/

NetApp published this final advisory covering CVE-2020-1749; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-29370 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201218-0001/

NetApp published this final advisory covering CVE-2020-29370; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27218 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201218-0003/

NetApp published this final advisory covering CVE-2020-27218; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand System Manager 3.x; Snap Creator Framework.

Open source
Advisory

CVE-2020-25723 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201218-0004/

NetApp published this final advisory covering CVE-2020-25723; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-1971 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201218-0005/

NetApp published this final advisory covering CVE-2020-1971; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Data ONTAP operating in 7-Mode; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Global File Cache; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Antivirus Connector; OnCommand Unified Manager Core Package; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

CVE-2020-15436 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201218-0002/

NetApp published this final advisory covering CVE-2020-15436; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25705 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201210-0002/

NetApp published this final advisory covering CVE-2020-25705; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25640 WildFly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201210-0001/

NetApp published this final advisory covering CVE-2020-25640; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager.

Open source
Advisory

CVE-2020-25624 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201210-0005/

NetApp published this final advisory covering CVE-2020-25624; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-17527 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201210-0003/

NetApp published this final advisory covering CVE-2020-17527; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; OnCommand System Manager 3.x.

Open source
Advisory

CVE-2020-14305 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201210-0004/

NetApp published this final advisory covering CVE-2020-14305; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

November 2020 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201202-0002/

NetApp published this final advisory covering CVE-2020-27616, CVE-2020-27617; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2020 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201202-0003/

NetApp published this final advisory covering CVE-2020-25694, CVE-2020-25695; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2020 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201202-0004/

NetApp published this final advisory covering CVE-2020-28362, CVE-2020-28366, CVE-2020-28367; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident; Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2020-7020 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201123-0001/

NetApp published this final advisory covering CVE-2020-7020; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-27619 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201123-0004/

NetApp published this final advisory covering CVE-2020-27619; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-27216 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201123-0005/

NetApp published this final advisory covering CVE-2020-27216; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand System Manager 3.x; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2020-25689 WildFly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201123-0006/

NetApp published this final advisory covering CVE-2020-25689; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; OnCommand Insight.

Open source
Advisory

CVE-2020-24352 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201123-0003/

NetApp published this final advisory covering CVE-2020-24352; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-24303 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201123-0002/

NetApp published this final advisory covering CVE-2020-24303; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00391 SPS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201113-0004/

NetApp published this final advisory covering CVE-2020-8705, CVE-2020-8744, CVE-2020-8755; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; FAS/AFF BIOS; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

Intel SA-00391 Intel TXE Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201113-0005/

NetApp published this final advisory covering CVE-2020-8705, CVE-2020-8744, CVE-2020-8745, CVE-2020-8750, CVE-2020-8751, CVE-2020-12297, CVE-2020-12303, CVE-2020-12355; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

Intel SA-00391 CSME Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201113-0002/

NetApp published this final advisory covering CVE-2020-8705, CVE-2020-8744, CVE-2020-8745, CVE-2020-8751, CVE-2020-8755, CVE-2020-8756, CVE-2020-8761, CVE-2020-12303, CVE-2020-12297; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

Intel SA-00391 AMT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201113-0003/

NetApp published this final advisory covering CVE-2020-8746, CVE-2020-8747, CVE-2020-8749, CVE-2020-8752, CVE-2020-8753, CVE-2020-8754, CVE-2020-8757, CVE-2020-8760, CVE-2020-12354, CVE-2020-12356; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

Intel SA-00381 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201113-0006/

NetApp published this final advisory covering CVE-2020-8696, CVE-2020-8698; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; FAS/AFF BIOS; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

Intel SA-00358 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201113-0001/

NetApp published this final advisory covering CVE-2020-0590, CVE-2020-0587, CVE-2020-0591, CVE-2020-0593, CVE-2020-0588, CVE-2020-0592; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; FAS/AFF BIOS; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

October 2020 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201103-0001/

NetApp published this final advisory covering CVE-2020-14318, CVE-2020-14323, CVE-2020-14383; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25645 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201103-0004/

NetApp published this final advisory covering CVE-2020-25645; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25643 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201103-0002/

NetApp published this final advisory covering CVE-2020-25643; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2018-11764 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201103-0003/

NetApp published this final advisory covering CVE-2018-11764; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2020 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201023-0003/

NetApp published this final advisory covering CVE-2020-8174, CVE-2020-14672, CVE-2020-14760, CVE-2020-14765, CVE-2020-14769, CVE-2020-14771, CVE-2020-14773, CVE-2020-14775, CVE-2020-14776, CVE-2020-14777, CVE-2020-14785, CVE-2020-14786, CVE-2020-14789, CVE-2020-14790, CVE-2020-14791, CVE-2020-14793, CVE-2020-14794, CVE-2020-14799, CVE-2020-14800, CVE-2020-14804, CVE-2020-14809, CVE-2020-14812, CVE-2020-14814, CVE-2020-14821, CVE-2020-14827, CVE-2020-14828, CVE-2020-14829, CVE-2020-14830, CVE-2020-14836, CVE-2020-14837, CVE-2020-14838, CVE-2020-14839, CVE-2020-14844, CVE-2020-14845, CVE-2020-14846, CVE-2020-14848, CVE-2020-14852, CVE-2020-14853, CVE-2020-14860, CVE-2020-14861, CVE-2020-14866, CVE-2020-14867, CVE-2020-14868, CVE-2020-14869, CVE-2020-14870, CVE-2020-14873, CVE-2020-14878, CVE-2020-14888, CVE-2020-14891, CVE-2020-14893, CVE-2020-4051; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2020 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201023-0004/

NetApp published this interim advisory covering CVE-2020-14779, CVE-2020-14781, CVE-2020-14782, CVE-2020-14792, CVE-2020-14796, CVE-2020-14797, CVE-2020-14798, CVE-2020-14803; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Insights Acquisition Unit; Cloud Secure Agent; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer; NetApp HCI Compute Node (Bootstrap OS); NetApp Plug-in for Symantec NetBackup; NetApp SANtricity Cloud Connector; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Unified Manager Core Package; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2020-26116 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201023-0001/

NetApp published this interim advisory covering CVE-2020-26116; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-13957 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201023-0002/

NetApp published this final advisory covering CVE-2020-13957; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2020 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201016-0001/

NetApp published this final advisory covering CVE-2020-7069, CVE-2020-7070; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2020 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201016-0002/

NetApp published this final advisory covering CVE-2020-7461, CVE-2020-7462, CVE-2020-7463, CVE-2020-7464, CVE-2020-7467, CVE-2020-7468, CVE-2020-24718; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.

Open source
Advisory

Intel SA-00435 BlueZ Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201016-0006/

NetApp published this final advisory covering CVE-2020-12351, CVE-2020-12352, CVE-2020-24490; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25644 WildFly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201016-0004/

NetApp published this final advisory covering CVE-2020-25644; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Service Level Manager; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2020-25626 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201016-0003/

NetApp published this final advisory covering CVE-2020-25626; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-11765 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201016-0005/

NetApp published this final advisory covering CVE-2018-11765; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2020 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201009-0005/

NetApp published this final advisory covering CVE-2020-25625, CVE-2020-25085, CVE-2020-25084, CVE-2020-25741; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2020 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201009-0004/

NetApp published this final advisory covering CVE-2020-8251, CVE-2020-8201, CVE-2020-8252; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25285 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201009-0002/

NetApp published this final advisory covering CVE-2020-25285; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25211 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201009-0001/

NetApp published this interim advisory covering CVE-2020-25211; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-24750 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201009-0003/

NetApp published this final advisory covering CVE-2020-24750; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8608 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201001-0002/

NetApp published this final advisory covering CVE-2020-8608; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25221 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201001-0003/

NetApp published this final advisory covering CVE-2020-25221; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25220 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201001-0004/

NetApp published this final advisory covering CVE-2020-25220; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-1748 WildFly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201001-0005/

NetApp published this final advisory covering CVE-2020-1748; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10756 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201001-0001/

NetApp published this final advisory covering CVE-2020-10756; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10733 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201001-0006/

NetApp published this final advisory covering CVE-2020-10733; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8648 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200924-0004/

NetApp published this final advisory covering CVE-2020-8648; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-24977 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200924-0001/

NetApp published this final advisory covering CVE-2020-24977; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; NetApp Cloud Backup (formerly AltaVault); NetApp Manageability SDK; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

CVE-2020-24553 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200924-0003/

NetApp published this final advisory covering CVE-2020-24553; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-16845 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200924-0002/

NetApp published this final advisory covering CVE-2020-16845; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-14364 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200924-0006/

NetApp published this final advisory covering CVE-2020-14364; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-19543 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200924-0005/

NetApp published this final advisory covering CVE-2019-19543; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

September 2020 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200918-0004/

NetApp published this final advisory covering CVE-2020-24583, CVE-2020-24584; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-7068 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200918-0005/

NetApp published this final advisory covering CVE-2020-7068; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-19499 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200918-0003/

NetApp published this final advisory covering CVE-2019-19499; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2020 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200918-0002/

NetApp published this final advisory covering CVE-2020-14349, CVE-2020-14350; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2020 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200918-0001/

NetApp published this final advisory covering CVE-2020-24346, CVE-2020-24347, CVE-2020-24348, CVE-2020-24349; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2020-8758 Intel AMT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200911-0005/

NetApp published this final advisory covering CVE-2020-8758; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-8231 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200911-0003/

NetApp published this final advisory covering CVE-2020-8231; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-8177 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200911-0001/

NetApp published this final advisory covering CVE-2020-8177; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-8169 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200911-0002/

NetApp published this final advisory covering CVE-2020-8169; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-24659 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200911-0006/

NetApp published this final advisory covering CVE-2020-24659; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2020-1968 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200911-0004/

NetApp published this final advisory covering CVE-2020-1968; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

CVE-2020-24394 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200904-0003/

NetApp published this final advisory covering CVE-2020-24394; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-14356 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200904-0002/

NetApp published this final advisory covering CVE-2020-14356; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-14892 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200904-0005/

NetApp published this final advisory covering CVE-2019-14892; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-1000873 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200904-0004/

NetApp published this final advisory covering CVE-2018-1000873; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

August 2020 Net-SNMP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200904-0001/

NetApp published this final advisory covering CVE-2020-15861, CVE-2020-15862; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node.

Open source
Advisory

August 2020 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200904-0006/

NetApp published this final advisory covering CVE-2020-9546, CVE-2020-9547, CVE-2020-9548, CVE-2020-24616; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2020-7019 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200827-0001/

NetApp published this final advisory covering CVE-2020-7019; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-11985 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200827-0002/

NetApp published this final advisory covering CVE-2020-11985; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-15173 Nmap Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200827-0004/

NetApp published this final advisory covering CVE-2018-15173; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2020 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200827-0003/

NetApp published this final advisory covering CVE-2020-8620, CVE-2020-8621, CVE-2020-8622, CVE-2020-8623, CVE-2020-8624; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-8558 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200821-0001/

NetApp published this final advisory covering CVE-2020-8558; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8557 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200821-0002/

NetApp published this final advisory covering CVE-2020-8557; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-16092 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200821-0006/

NetApp published this final advisory covering CVE-2020-16092; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2020 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200821-0005/

NetApp published this final advisory covering CVE-2020-7459, CVE-2020-7460; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2020 Apache Struts 2.x Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200821-0004/

NetApp published this final advisory covering CVE-2019-0230, CVE-2019-0233; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00386 Server Board Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200814-0003/

NetApp published this final advisory covering CVE-2020-8733, CVE-2020-8734; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00384 Server Boards, Systems and Compute Module Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200814-0002/

NetApp published this final advisory covering CVE-2020-8708, CVE-2020-8730, CVE-2020-8731, CVE-2020-8707, CVE-2020-8719, CVE-2020-8721, CVE-2020-8710, CVE-2020-8711, CVE-2020-8712, CVE-2020-8718, CVE-2020-8722, CVE-2020-8732, CVE-2020-8709, CVE-2020-8723, CVE-2020-8713, CVE-2020-8706, CVE-2020-8729, CVE-2020-8715, CVE-2020-8716, CVE-2020-8714, CVE-2020-8717, CVE-2020-8720; the API labels exploitation information as **Not public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00367 Server Board Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200814-0001/

NetApp published this final advisory covering CVE-2020-12299, CVE-2020-12300, CVE-2020-12301; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-16166 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200814-0004/

NetApp published this interim advisory covering CVE-2020-16166; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; StorageGRID9 (9.x and prior).

Open source
Advisory

August 2020 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200814-0005/

NetApp published this final advisory covering CVE-2020-9490, CVE-2020-11984, CVE-2020-11993; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8559 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200810-0004/

NetApp published this final advisory covering CVE-2020-8559; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-15852 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200810-0001/

NetApp published this final advisory covering CVE-2020-15852; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-11110 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200810-0002/

NetApp published this final advisory covering CVE-2020-11110; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2019-11255 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200810-0003/

NetApp published this final advisory covering CVE-2019-11255; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8575 Denial of Service Vulnerability in Active IQ Unified Manager for VMware vSphere and Windows

Source: https://security.netapp.com/advisory/NTAP-20200803-0002/

NetApp published this final advisory covering CVE-2020-8575; the API labels exploitation information as **Not public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above.

Open source
Advisory

July 2020 Grub2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200731-0008/

NetApp published this final advisory covering CVE-2020-10713, CVE-2020-14308, CVE-2020-14309, CVE-2020-14310, CVE-2020-14311, CVE-2020-15705, CVE-2020-15706, CVE-2020-15707; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

July 2020 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200731-0005/

NetApp published this final advisory covering CVE-2020-15586, CVE-2020-14039; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-15778 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200731-0007/

NetApp published this final advisory covering CVE-2020-15778; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-14725 MySQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200731-0006/

NetApp published this final advisory covering CVE-2020-14725; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2020-14001 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200731-0004/

NetApp published this final advisory covering CVE-2020-14001; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10761 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200731-0001/

NetApp published this final advisory covering CVE-2020-10761; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-20907 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200731-0002/

NetApp published this final advisory covering CVE-2019-20907; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; MAX Data.

Open source
Advisory

June 2020 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200724-0001/

NetApp published this final advisory covering CVE-2020-14966, CVE-2020-14967, CVE-2020-14968; the API labels exploitation information as **Public**. The API currently lists affected products as: MAX Data.

Open source
Advisory

July 2020 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200724-0002/

NetApp published this final advisory covering CVE-2020-7457, CVE-2020-7458; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2020 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200724-0003/

NetApp published this final advisory covering CVE-2020-13934, CVE-2020-13935; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand System Manager 3.x.

Open source
Advisory

CVE-2020-8555 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200724-0005/

NetApp published this final advisory covering CVE-2020-8555; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8203 Lodash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200724-0006/

NetApp published this final advisory covering CVE-2020-8203; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager.

Open source
Advisory

CVE-2020-14422 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200724-0004/

NetApp published this final advisory covering CVE-2020-14422; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; MAX Data.

Open source
Advisory

CVE-2020-10702 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200724-0007/

NetApp published this final advisory covering CVE-2020-10702; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2020 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200717-0001/

NetApp published this final advisory covering CVE-2020-13800, CVE-2020-13791; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2020 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200717-0004/

NetApp published this final advisory covering CVE-2020-1967, CVE-2020-14663, CVE-2020-14678, CVE-2020-14697, CVE-2020-14539, CVE-2020-14540, CVE-2020-14547, CVE-2020-14553, CVE-2020-14559, CVE-2020-14567, CVE-2020-14568, CVE-2020-14575, CVE-2020-14576, CVE-2020-14586, CVE-2020-14591, CVE-2020-14597, CVE-2020-14614, CVE-2020-14619, CVE-2020-14620, CVE-2020-14623, CVE-2020-14624, CVE-2020-14631, CVE-2020-14632, CVE-2020-14633, CVE-2020-14634, CVE-2020-14641, CVE-2020-14643, CVE-2020-14651, CVE-2020-14654, CVE-2020-14656, CVE-2020-14680, CVE-2020-14702; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2020 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200717-0005/

NetApp published this final advisory covering CVE-2020-14664, CVE-2020-14583, CVE-2020-14593, CVE-2020-14556, CVE-2020-14562, CVE-2020-14573, CVE-2020-14577, CVE-2020-14578, CVE-2020-14579, CVE-2020-14581, CVE-2020-14621; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Secure Agent; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer; NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; OnCommand Insight; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2020-14002 PuTTY Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200717-0003/

NetApp published this final advisory covering CVE-2020-14002; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager Core Package.

Open source
Advisory

CVE-2020-13401 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200717-0002/

NetApp published this final advisory covering CVE-2020-13401; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2020-15358 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200709-0001/

NetApp published this final advisory covering CVE-2020-15358; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2020-14303 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200709-0003/

NetApp published this final advisory covering CVE-2020-14303; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-14145 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200709-0004/

NetApp published this interim advisory covering CVE-2020-14145; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility.

Open source
Advisory

June 2020 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200702-0001/

NetApp published this final advisory covering CVE-2020-10730, CVE-2020-10745, CVE-2020-10760; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2020 Libxml2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200702-0005/

NetApp published this final advisory covering CVE-2019-20388, CVE-2020-7595; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp SteelStore Cloud Integrated Storage; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility; SnapDrive for Windows.

Open source
Advisory

June 2020 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200702-0003/

NetApp published this final advisory covering CVE-2020-14060, CVE-2020-14061, CVE-2020-14062, CVE-2020-14195; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-15025 Network Time Protocol Daemon (ntpd) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200702-0002/

NetApp published this final advisory covering CVE-2020-15025; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-12662 Unbound Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200702-0006/

NetApp published this final advisory covering CVE-2020-12662; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10757 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200702-0004/

NetApp published this final advisory covering CVE-2020-10757; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-8573 Default Account Vulnerability in the NetApp HCI Baseboard Management Controller (BMC) - H610C, H615C and H610S

Source: https://security.netapp.com/advisory/NTAP-20200626-0001/

NetApp published this final advisory covering CVE-2020-8573; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

June 2020 Treck TCP/IP Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200625-0006/

NetApp published this final advisory covering CVE-2020-11908, CVE-2020-11903, CVE-2020-11900, CVE-2020-11896, CVE-2020-11898, CVE-2020-11899, CVE-2020-11902, CVE-2020-11904, CVE-2020-11905, CVE-2020-11906, CVE-2020-11907, CVE-2020-11909, CVE-2020-11910, CVE-2020-11911, CVE-2020-11912, CVE-2020-11913, CVE-2020-11914; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2020 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200625-0003/

NetApp published this final advisory covering CVE-2020-8618, CVE-2020-8619; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-13817 NTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200625-0004/

NetApp published this final advisory covering CVE-2020-13817; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; ONTAP tools for VMware vSphere.

Open source
Advisory

CVE-2020-10933 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200625-0001/

NetApp published this final advisory covering CVE-2020-10933; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-7014 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200619-0003/

NetApp published this final advisory covering CVE-2020-7014; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-13871 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200619-0002/

NetApp published this final advisory covering CVE-2020-13871; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-13777 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200619-0004/

NetApp published this final advisory covering CVE-2020-13777; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-13765 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200619-0006/

NetApp published this final advisory covering CVE-2020-13765; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-13692 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200619-0005/

NetApp published this final advisory covering CVE-2020-13692; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-20806 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200619-0001/

NetApp published this final advisory covering CVE-2019-20806; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

June 2020 Perl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200611-0001/

NetApp published this final advisory covering CVE-2020-10878, CVE-2020-12723, CVE-2020-10543; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

June 2020 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200611-0002/

NetApp published this final advisory covering CVE-2020-13254, CVE-2020-13596; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage; SRA Plugin for Linux.

Open source
Advisory

Intel SA-00295 TXE Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200611-0005/

NetApp published this final advisory covering CVE-2020-0566; the API labels exploitation information as **Not public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00295 SPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200611-0004/

NetApp published this final advisory covering CVE-2020-0586; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00295 CSME Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200611-0006/

NetApp published this final advisory covering CVE-2020-0533, CVE-2020-0534, CVE-2020-0536, CVE-2020-0539, CVE-2020-0541, CVE-2020-0542, CVE-2020-0545; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00295 AMT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200611-0007/

NetApp published this final advisory covering CVE-2020-0594, CVE-2020-0538, CVE-2020-0532, CVE-2020-0597, CVE-2020-0535, CVE-2020-0540, CVE-2020-0537, CVE-2020-8674, CVE-2020-0531, CVE-2020-0595, CVE-2020-0596; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-13776 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200611-0003/

NetApp published this final advisory covering CVE-2020-13776; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

May 2020 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200608-0001/

NetApp published this final advisory covering CVE-2020-10711, CVE-2020-13143, CVE-2020-12888, CVE-2020-12826, CVE-2020-12771, CVE-2020-12770, CVE-2020-12769, CVE-2019-20794, CVE-2019-14898, CVE-2020-12659, CVE-2020-12657, CVE-2020-12655, CVE-2020-12653, CVE-2020-12654, CVE-2020-12652, CVE-2020-12114, CVE-2020-12465, CVE-2020-12464, CVE-2020-11884, CVE-2019-11599, CVE-2020-10690; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

June 2020 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200608-0002/

NetApp published this final advisory covering CVE-2020-13630, CVE-2020-13631, CVE-2020-13632; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

June 2020 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200608-0003/

NetApp published this final advisory covering CVE-2020-13361, CVE-2020-13362; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2020 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200608-0007/

NetApp published this final advisory covering CVE-2020-13754, CVE-2020-13659; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2020 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200608-0008/

NetApp published this final advisory covering CVE-2018-18623, CVE-2018-18624, CVE-2018-18625; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-13645 GNOME GLib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200608-0004/

NetApp published this final advisory covering CVE-2020-13645; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2020-13379 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200608-0006/

NetApp published this final advisory covering CVE-2020-13379; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2020-10703 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200608-0005/

NetApp published this final advisory covering CVE-2020-10703; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2020 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200528-0004/

NetApp published this final advisory covering CVE-2020-13435, CVE-2020-13434; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-7656 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200528-0001/

NetApp published this final advisory covering CVE-2020-7656; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); OnCommand System Manager 3.x; Snap Creator Framework.

Open source
Advisory

CVE-2020-13430 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200528-0003/

NetApp published this final advisory covering CVE-2020-13430; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-13388 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200528-0002/

NetApp published this final advisory covering CVE-2020-13388; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-11048 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200528-0006/

NetApp published this final advisory covering CVE-2019-11048; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2020 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200522-0002/

NetApp published this final advisory covering CVE-2020-8616, CVE-2020-8617; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SteelStore Cloud Integrated Storage; Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above.

Open source
Advisory

CVE-2020-5895 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200522-0001/

NetApp published this final advisory covering CVE-2020-5895; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

May 2020 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0005/

NetApp published this final advisory covering CVE-2019-15879, CVE-2020-7454, CVE-2020-7455; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-12459 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0004/

NetApp published this final advisory covering CVE-2020-12459; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-12458 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0001/

NetApp published this final advisory covering CVE-2020-12458; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-12430 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0003/

NetApp published this final advisory covering CVE-2020-12430; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10683 Dom4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0002/

NetApp published this final advisory covering CVE-2020-10683; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Service Level Manager; OnCommand API Services; OnCommand System Manager 3.x; OnCommand Workflow Automation; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2019-15880 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0008/

NetApp published this final advisory covering CVE-2019-15880; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-15878 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0007/

NetApp published this final advisory covering CVE-2019-15878; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-8956 Network Time Protocol Daemon (ntpd) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0006/

NetApp published this final advisory covering CVE-2018-8956; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

May 2020 jQuery Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200511-0006/

NetApp published this final advisory covering CVE-2020-11022, CVE-2020-11023; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Insights Storage Workload Security Agent; MAX Data; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; OnCommand Insight; OnCommand System Manager 3.x; Snap Creator Framework; SnapCenter.

Open source
Advisory

May 2020 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200511-0001/

NetApp published this final advisory covering CVE-2020-12052, CVE-2020-12245; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

May 2020 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200511-0002/

NetApp published this final advisory covering CVE-2019-5614, CVE-2019-15874; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.

Open source
Advisory

May 2020 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200511-0004/

NetApp published this final advisory covering CVE-2020-11619, CVE-2020-11620; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-1752 GNU C Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200511-0005/

NetApp published this final advisory covering CVE-2020-1752; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-12243 OpenLDAP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200511-0003/

NetApp published this final advisory covering CVE-2020-12243; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-9488 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200504-0003/

NetApp published this final advisory covering CVE-2020-9488; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-7067 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200504-0001/

NetApp published this final advisory covering CVE-2020-7067; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-1751 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200430-0002/

NetApp published this final advisory covering CVE-2020-1751; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-11669 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200430-0001/

NetApp published this final advisory covering CVE-2020-11669; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-18276 GNU Bash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200430-0003/

NetApp published this final advisory covering CVE-2019-18276; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp SolidFire & HCI Management Node.

Open source
Advisory

April 2020 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200430-0005/

NetApp published this final advisory covering CVE-2020-5863, CVE-2020-5864, CVE-2020-5865, CVE-2020-5866, CVE-2020-5867; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

April 2020 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200430-0004/

NetApp published this final advisory covering CVE-2019-20636, CVE-2020-11494, CVE-2020-11608, CVE-2020-11609, CVE-2020-11668, CVE-2020-8832, CVE-2020-8835; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

April 2020 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200429-0001/

NetApp published this final advisory covering CVE-2020-10700, CVE-2020-10704; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-1967 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200424-0003/

NetApp published this final advisory covering CVE-2020-1967; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp E-Series Performance Analyzer; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-1730 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200424-0001/

NetApp published this final advisory covering CVE-2020-1730; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2020-11868 NTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200424-0002/

NetApp published this final advisory covering CVE-2020-11868; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP operating in 7-Mode; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP tools for VMware vSphere.

Open source
Advisory

CVE-2020-11501 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200416-0002/

NetApp published this final advisory covering CVE-2020-11501; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

April 2020 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200416-0001/

NetApp published this final advisory covering CVE-2020-11655, CVE-2020-11656; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

April 2020 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200416-0003/

NetApp published this final advisory covering CVE-2019-1547, CVE-2019-15601, CVE-2019-5482, CVE-2020-2752, CVE-2020-2759, CVE-2020-2760, CVE-2020-2761, CVE-2020-2762, CVE-2020-2763, CVE-2020-2765, CVE-2020-2768, CVE-2020-2770, CVE-2020-2774, CVE-2020-2779, CVE-2020-2780, CVE-2020-2790, CVE-2020-2804, CVE-2020-2806, CVE-2020-2812, CVE-2020-2814, CVE-2020-2853, CVE-2020-2892, CVE-2020-2893, CVE-2020-2895, CVE-2020-2896, CVE-2020-2897, CVE-2020-2898, CVE-2020-2901, CVE-2020-2903, CVE-2020-2904, CVE-2020-2921, CVE-2020-2922, CVE-2020-2923, CVE-2020-2924, CVE-2020-2925, CVE-2020-2926, CVE-2020-2928, CVE-2020-2930; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2020 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200416-0004/

NetApp published this final advisory covering CVE-2020-2803, CVE-2020-2805, CVE-2019-18197, CVE-2020-2816, CVE-2020-2754, CVE-2020-2755, CVE-2020-2756, CVE-2020-2757, CVE-2020-2764, CVE-2020-2767, CVE-2020-2773, CVE-2020-2778, CVE-2020-2781, CVE-2020-2800, CVE-2020-2830; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Secure Agent; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer; NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; OnCommand Insight; OnCommand Workflow Automation; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

March 2020 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200413-0001/

NetApp published this final advisory covering CVE-2019-15876, CVE-2019-15877, CVE-2020-7451, CVE-2020-7452, CVE-2020-7453; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode.

Open source
Advisory

April 2020 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200413-0003/

NetApp published this final advisory covering CVE-2020-8551, CVE-2020-8552, CVE-2019-11254; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2020 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200413-0002/

NetApp published this final advisory covering CVE-2020-1927, CVE-2020-1934; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; OnCommand Unified Manager Core Package.

Open source
Advisory

March 2020 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200403-0001/

NetApp published this final advisory covering CVE-2020-7064, CVE-2020-7065, CVE-2020-7066; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-7009 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200403-0004/

NetApp published this final advisory covering CVE-2020-7009; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10942 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200403-0003/

NetApp published this final advisory covering CVE-2020-10942; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

April 2020 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200403-0002/

NetApp published this final advisory covering CVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969, CVE-2020-11111, CVE-2020-11112, CVE-2020-11113; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2015-2992 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200330-0001/

NetApp published this final advisory covering CVE-2015-2992; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2020 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200327-0005/

NetApp published this final advisory covering CVE-2019-17569, CVE-2020-1935; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Data Availability Services; OnCommand System Manager 3.x.

Open source
Advisory

CVE-2020-9402 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200327-0004/

NetApp published this final advisory covering CVE-2020-9402; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-8840 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200327-0002/

NetApp published this final advisory covering CVE-2020-8840; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Service Level Manager; NetApp SteelStore Cloud Integrated Storage; OnCommand API Services; OnCommand Workflow Automation.

Open source
Advisory

CVE-2020-7919 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200327-0001/

NetApp published this final advisory covering CVE-2020-7919; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2020-10029 GNU C Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200327-0003/

NetApp published this final advisory covering CVE-2020-10029; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-14887 Wildfly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200327-0007/

NetApp published this final advisory covering CVE-2019-14887; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00334 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200320-0002/

NetApp published this final advisory covering CVE-2020-0551; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00330 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200320-0001/

NetApp published this final advisory covering CVE-2020-0550; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00315 Intel Graphics Drivers Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200320-0003/

NetApp published this final advisory covering CVE-2020-0504, CVE-2020-0516, CVE-2020-0519, CVE-2020-0520, CVE-2020-0505, CVE-2020-0501, CVE-2020-0565, CVE-2020-0514, CVE-2020-0515, CVE-2020-0508, CVE-2020-0511, CVE-2020-0503, CVE-2020-0567, CVE-2020-0502, CVE-2020-0507, CVE-2020-0517, CVE-2020-0506; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00260 Intel Graphics Drivers Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200320-0004/

NetApp published this final advisory covering CVE-2019-0154; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00242 Graphics Drivers Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200320-0005/

NetApp published this final advisory covering CVE-2019-0155, CVE-2019-11089, CVE-2019-11111, CVE-2019-11112, CVE-2019-11113, CVE-2019-14574, CVE-2019-14590, CVE-2019-14591; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

February 2020 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200313-0003/

NetApp published this final advisory covering CVE-2019-20422, CVE-2019-3016, CVE-2020-8428, CVE-2020-8992, CVE-2020-9383, CVE-2020-9391; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-9327 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200313-0002/

NetApp published this final advisory covering CVE-2020-9327; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2020-8597 PPP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200313-0004/

NetApp published this final advisory covering CVE-2020-8597; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-8441 JYaml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200313-0001/

NetApp published this final advisory covering CVE-2020-8441; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; SnapManager for Oracle.

Open source
Advisory

CVE-2020-1938 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200226-0002/

NetApp published this final advisory covering CVE-2020-1938; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Data Availability Services; OnCommand System Manager 3.x.

Open source
Advisory

Intel SA-00307 Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200221-0005/

NetApp published this final advisory covering CVE-2019-14598; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

February 2020 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200221-0002/

NetApp published this final advisory covering CVE-2020-7059, CVE-2020-7060; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2020 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200221-0004/

NetApp published this final advisory covering CVE-2019-15604, CVE-2019-15605, CVE-2019-15606; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8492 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200221-0001/

NetApp published this final advisory covering CVE-2020-8492; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-7471 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200221-0006/

NetApp published this final advisory covering CVE-2020-7471; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-9674 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200221-0003/

NetApp published this final advisory covering CVE-2019-9674; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

Intel SA-00329 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200210-0004/

NetApp published this final advisory covering CVE-2020-0548, CVE-2020-0549; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

February 2020 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200210-0003/

NetApp published this final advisory covering CVE-2020-7450, CVE-2019-5613, CVE-2019-15875; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-20386 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200210-0002/

NetApp published this final advisory covering CVE-2019-20386; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-18634 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200210-0001/

NetApp published this final advisory covering CVE-2019-18634; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

January 2020 NTP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200204-0003/

NetApp published this final advisory covering CVE-2015-8139, CVE-2015-8140; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

January 2020 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200204-0002/

NetApp published this final advisory covering CVE-2019-19966, CVE-2019-19965, CVE-2019-19947, CVE-2019-20054, CVE-2019-5108, CVE-2019-19922, CVE-2019-19927, CVE-2019-20095, CVE-2019-19332, CVE-2020-7053, CVE-2007-4774, CVE-2019-18282; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-19959 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200204-0001/

NetApp published this final advisory covering CVE-2019-19959; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2020-6750 GNOME GLib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200127-0001/

NetApp published this final advisory covering CVE-2020-6750; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2019-20372 NGINX vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200127-0003/

NetApp published this final advisory covering CVE-2019-20372; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2019-20330 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200127-0004/

NetApp published this final advisory covering CVE-2019-20330; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; NetApp Service Level Manager; NetApp SteelStore Cloud Integrated Storage; OnCommand API Services; SnapCenter.

Open source
Advisory

CVE-2019-15601 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200127-0002/

NetApp published this final advisory covering CVE-2019-15601; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

January 2020 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200122-0001/

NetApp published this final advisory covering CVE-2019-14902, CVE-2019-14907, CVE-2019-19344; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2020 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200122-0002/

NetApp published this final advisory covering CVE-2020-2579, CVE-2020-2686, CVE-2020-2627, CVE-2019-1547, CVE-2020-2572, CVE-2020-2573, CVE-2020-2574, CVE-2020-2577, CVE-2020-2580, CVE-2020-2584, CVE-2020-2588, CVE-2020-2589, CVE-2020-2660, CVE-2020-2679, CVE-2020-2694; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2020 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200122-0003/

NetApp published this final advisory covering CVE-2020-2604, CVE-2019-13117, CVE-2019-13118, CVE-2019-16168, CVE-2020-2583, CVE-2020-2585, CVE-2020-2590, CVE-2020-2593, CVE-2020-2601, CVE-2020-2654, CVE-2020-2655, CVE-2020-2659; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer; NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; OnCommand Insight; OnCommand Workflow Automation; SANtricity Unified Manager.

Open source
Advisory

October 2019 Tcpdump Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200120-0001/

NetApp published this final advisory covering CVE-2018-10103, CVE-2018-10105, CVE-2018-14461, CVE-2018-14462, CVE-2018-14463, CVE-2018-14464, CVE-2018-14465, CVE-2018-14466, CVE-2018-14467, CVE-2018-14468, CVE-2018-14469, CVE-2018-14470, CVE-2018-14879, CVE-2018-14880, CVE-2018-14881, CVE-2018-14882, CVE-2018-16227, CVE-2018-16228, CVE-2018-16229, CVE-2018-16230, CVE-2018-16300, CVE-2018-16451, CVE-2018-16452, CVE-2019-15166; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-5094 E2FSProgs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200115-0002/

NetApp published this final advisory covering CVE-2019-5094; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2019-18218 File Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200115-0001/

NetApp published this final advisory covering CVE-2019-18218; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above.

Open source
Advisory

January 2020 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200114-0003/

NetApp published this final advisory covering CVE-2019-19923, CVE-2019-19924, CVE-2019-19925, CVE-2019-19926; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2019-19956 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200114-0002/

NetApp published this final advisory covering CVE-2019-19956; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp Manageability SDK; NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-19880 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200114-0001/

NetApp published this final advisory covering CVE-2019-19880; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2019-19844 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200110-0003/

NetApp published this final advisory covering CVE-2019-19844; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-17571 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200110-0001/

NetApp published this final advisory covering CVE-2019-17571; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand System Manager 3.x; OnCommand Workflow Automation.

Open source
Advisory

December 2019 Sudo Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200103-0004/

NetApp published this final advisory covering CVE-2019-19232, CVE-2019-19234; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node.

Open source
Advisory

December 2019 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200103-0002/

NetApp published this final advisory covering CVE-2019-11044, CVE-2019-11045, CVE-2019-11046, CVE-2019-11047, CVE-2019-11049, CVE-2019-11050; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200103-0001/

NetApp published this final advisory covering CVE-2019-14815, CVE-2019-19227, CVE-2019-10220, CVE-2019-19318, CVE-2019-14896, CVE-2019-19252, CVE-2019-18660, CVE-2019-19319, CVE-2019-10207, CVE-2019-18675, CVE-2019-19602, CVE-2019-19378, CVE-2019-19377, CVE-2019-19447, CVE-2019-19448, CVE-2019-19449, CVE-2019-19768, CVE-2019-19769, CVE-2019-19770, CVE-2019-19767, CVE-2019-19807, CVE-2019-19241, CVE-2019-19815, CVE-2019-19814, CVE-2019-19816, CVE-2019-19813; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

December 2019 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191223-0001/

NetApp published this final advisory covering CVE-2019-19317, CVE-2019-19603, CVE-2019-19645, CVE-2019-19646; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-19118 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191217-0003/

NetApp published this final advisory covering CVE-2019-19118; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-14607 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191217-0002/

NetApp published this final advisory covering CVE-2019-14607; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-11157 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191217-0001/

NetApp published this final advisory covering CVE-2019-11157; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00241 CSME-SPS-TXE-AMT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191213-0001/

NetApp published this final advisory covering CVE-2019-0169, CVE-2019-11132, CVE-2019-11147, CVE-2019-11105, CVE-2019-11088, CVE-2019-11131, CVE-2019-11104, CVE-2019-11097, CVE-2019-11103, CVE-2019-0131, CVE-2019-11090, CVE-2019-0165, CVE-2019-0166, CVE-2019-0168, CVE-2019-11087, CVE-2019-11101, CVE-2019-11100, CVE-2019-11102, CVE-2019-11106, CVE-2019-11107, CVE-2019-11109, CVE-2019-11110, CVE-2019-11086, CVE-2019-11108; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

December 2019 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191210-0002/

NetApp published this final advisory covering CVE-2019-14861, CVE-2019-14870; the API labels exploitation information as **Not public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-1551 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191210-0001/

NetApp published this final advisory covering CVE-2019-1551; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp E-Series Performance Analyzer; NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

November 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191205-0001/

NetApp published this final advisory covering CVE-2019-18680, CVE-2019-18683, CVE-2019-18805, CVE-2019-18807, CVE-2019-18808, CVE-2019-18809, CVE-2019-18810, CVE-2019-18811, CVE-2019-18812, CVE-2019-18813, CVE-2019-18814, CVE-2019-18885, CVE-2019-19036, CVE-2019-19037, CVE-2019-19043, CVE-2019-19044, CVE-2019-19045, CVE-2019-19047, CVE-2019-19048, CVE-2019-19050, CVE-2019-19051, CVE-2019-19052, CVE-2019-19053, CVE-2019-19054, CVE-2019-19056, CVE-2019-19057, CVE-2019-19058, CVE-2019-19059, CVE-2019-19060, CVE-2019-19061, CVE-2019-19062, CVE-2019-19063, CVE-2019-19065, CVE-2019-19066, CVE-2019-19068, CVE-2019-19069, CVE-2019-19071, CVE-2019-19072, CVE-2019-19073, CVE-2019-19074, CVE-2019-19075, CVE-2019-19076, CVE-2019-19077, CVE-2019-19078, CVE-2019-19079, CVE-2019-19080, CVE-2019-19081, CVE-2019-19082, CVE-2019-19083; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

October 2019 PuTTY Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191127-0003/

NetApp published this final advisory covering CVE-2019-17067, CVE-2019-17068, CVE-2019-17069; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager Core Package.

Open source
Advisory

CVE-2019-17592 Nodejs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191127-0002/

NetApp published this final advisory covering CVE-2019-17592; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2019 Ruby Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191122-0003/

NetApp published this final advisory covering CVE-2018-8048, CVE-2019-15587, CVE-2019-15845, CVE-2019-16201, CVE-2019-16254, CVE-2019-16255; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-6477 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191122-0001/

NetApp published this final advisory covering CVE-2019-6477; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-17596 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191122-0005/

NetApp published this final advisory covering CVE-2019-17596; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-16276 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191122-0004/

NetApp published this final advisory covering CVE-2019-16276; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2018-21029 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191122-0002/

NetApp published this final advisory covering CVE-2018-21029; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00280 Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191113-0004/

NetApp published this final advisory covering CVE-2019-11136, CVE-2019-11137; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00255 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191113-0001/

NetApp published this final advisory covering CVE-2019-0139, CVE-2019-0140, CVE-2019-0142, CVE-2019-0143, CVE-2019-0144, CVE-2019-0145, CVE-2019-0146, CVE-2019-0147, CVE-2019-0148, CVE-2019-0149, CVE-2019-0150; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

Intel SA-00254 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191113-0008/

NetApp published this final advisory covering CVE-2019-0185; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00240 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191113-0002/

NetApp published this final advisory covering CVE-2019-0151, CVE-2019-0152; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00219 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191113-0006/

NetApp published this final advisory covering CVE-2019-0117; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00210 Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191113-0003/

NetApp published this final advisory covering CVE-2018-12207; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00164 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191113-0007/

NetApp published this final advisory covering CVE-2019-0184; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-18348 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191107-0004/

NetApp published this final advisory covering CVE-2019-18348; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-17514 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191107-0005/

NetApp published this final advisory covering CVE-2019-17514; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2007-2768 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191107-0002/

NetApp published this final advisory covering CVE-2007-2768; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2007-2243 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191107-0003/

NetApp published this interim advisory covering CVE-2007-2243; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2004-1653 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191107-0001/

NetApp published this final advisory covering CVE-2004-1653; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility.

Open source
Advisory

October 2019 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191031-0001/

NetApp published this final advisory covering CVE-2019-10218, CVE-2019-14833; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191031-0005/

NetApp published this final advisory covering CVE-2019-16714, CVE-2019-14814, CVE-2019-14816, CVE-2019-16746, CVE-2019-16994, CVE-2019-16995, CVE-2019-14835, CVE-2019-17133, CVE-2019-17351, CVE-2019-18198, CVE-2019-17666, CVE-2019-2215; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - A320/C190/A220/FAS2720/FAS2750/A800; NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; Service Processor.

Open source
Advisory

CVE-2019-18197 Libxslt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191031-0004/

NetApp published this final advisory covering CVE-2019-18197; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-14847 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191031-0002/

NetApp published this final advisory covering CVE-2019-14847; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-11253 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191031-0006/

NetApp published this final advisory covering CVE-2019-11253; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-11043 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191031-0003/

NetApp published this final advisory covering CVE-2019-11043; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2019 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191024-0004/

NetApp published this final advisory covering CVE-2019-6475, CVE-2019-6476; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

October 2019 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191024-0002/

NetApp published this final advisory covering CVE-2019-17450, CVE-2019-17451; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2019-17359 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191024-0006/

NetApp published this final advisory covering CVE-2019-17359; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; NetApp Service Level Manager; OnCommand API Services; OnCommand Workflow Automation.

Open source
Advisory

CVE-2019-16905 OpenSSH Pre-Auth Integer Overflow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191024-0003/

NetApp published this interim advisory covering CVE-2019-16905; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

October 2019 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191017-0002/

NetApp published this final advisory covering CVE-2019-5443, CVE-2019-2910, CVE-2019-2911, CVE-2019-2914, CVE-2019-2922, CVE-2019-2923, CVE-2019-2924, CVE-2019-2938, CVE-2019-2946, CVE-2019-2948, CVE-2019-2950, CVE-2019-2957, CVE-2019-2960, CVE-2019-2963, CVE-2019-2966, CVE-2019-2967, CVE-2019-2968, CVE-2019-2969, CVE-2019-2974, CVE-2019-2982, CVE-2019-2991, CVE-2019-2993, CVE-2019-2997, CVE-2019-2998, CVE-2019-3003, CVE-2019-3004, CVE-2019-3009, CVE-2019-3011, CVE-2019-3018; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2019 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191017-0001/

NetApp published this final advisory covering CVE-2019-2949, CVE-2019-11068, CVE-2019-2894, CVE-2019-2933, CVE-2019-2945, CVE-2019-2958, CVE-2019-2962, CVE-2019-2964, CVE-2019-2973, CVE-2019-2975, CVE-2019-2977, CVE-2019-2978, CVE-2019-2981, CVE-2019-2983, CVE-2019-2987, CVE-2019-2988, CVE-2019-2989, CVE-2019-2992, CVE-2019-2996, CVE-2019-2999; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; OnCommand Insight; OnCommand Workflow Automation; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

October 2019 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191017-0006/

NetApp published this final advisory covering CVE-2019-16942, CVE-2019-16943, CVE-2019-17267; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; NetApp SteelStore Cloud Integrated Storage; OnCommand API Services; OnCommand Workflow Automation.

Open source
Advisory

CVE-2019-16935 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191017-0004/

NetApp published this final advisory covering CVE-2019-16935; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2019-15138 Nodejs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191017-0005/

NetApp published this final advisory covering CVE-2019-15138; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-14287 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191017-0003/

NetApp published this final advisory covering CVE-2019-14287; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2019-15635 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191009-0002/

NetApp published this final advisory covering CVE-2019-15635; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2019 curl/libcurl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191004-0003/

NetApp published this final advisory covering CVE-2019-5481, CVE-2019-5482; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

September 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191004-0001/

NetApp published this final advisory covering CVE-2019-15666, CVE-2019-15538, CVE-2019-15807, CVE-2018-21008, CVE-2019-15921, CVE-2019-15922, CVE-2019-15923, CVE-2019-15924, CVE-2019-15902, CVE-2019-15916, CVE-2019-15917, CVE-2019-15918, CVE-2019-15919, CVE-2019-15920, CVE-2019-15925, CVE-2019-15926, CVE-2019-15927, CVE-2019-16089, CVE-2019-16229, CVE-2019-16230, CVE-2019-16231, CVE-2019-16232, CVE-2019-16233, CVE-2019-16234, CVE-2019-15031, CVE-2019-15030, CVE-2019-16413, CVE-2019-14821; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - A320/C190/A220/FAS2720/FAS2750/A800; NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

September 2019 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191004-0002/

NetApp published this final advisory covering CVE-2019-14540, CVE-2019-16335; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage; OnCommand API Services; OnCommand Workflow Automation.

Open source
Advisory

September 2019 Dropbear SSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191004-0006/

NetApp published this final advisory covering CVE-2017-9078, CVE-2017-9079; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2019-15043 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191004-0004/

NetApp published this final advisory covering CVE-2019-15043; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2019-10744 Lodash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191004-0005/

NetApp published this final advisory covering CVE-2019-10744; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager.

Open source
Advisory

Intel SA-00290 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190926-0001/

NetApp published this final advisory covering CVE-2019-11184; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-16168 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190926-0003/

NetApp published this final advisory covering CVE-2019-16168; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-16056 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190926-0005/

NetApp published this final advisory covering CVE-2019-16056; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-15903 Expat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190926-0004/

NetApp published this final advisory covering CVE-2019-15903; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for VMware vSphere; Clustered Data ONTAP; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; OnCommand Workflow Automation.

Open source
Advisory

CVE-2019-12401 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190926-0002/

NetApp published this final advisory covering CVE-2019-12401; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2019 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190919-0002/

NetApp published this final advisory covering CVE-2019-1547, CVE-2019-1549, CVE-2019-1563; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Data ONTAP operating in 7-Mode; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Service Processor - 8080/8060/8040/8020; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

September 2019 Lodash Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190919-0004/

NetApp published this final advisory covering CVE-2018-3721, CVE-2018-16487, CVE-2019-1010266; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; System Manager 9.x.

Open source
Advisory

September 2019 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190919-0003/

NetApp published this final advisory covering CVE-2019-11245, CVE-2019-11246, CVE-2019-11247, CVE-2019-11248, CVE-2019-11249, CVE-2019-11250; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-11358 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190919-0001/

NetApp published this final advisory covering CVE-2019-11358; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); OnCommand System Manager 3.x; SnapCenter.

Open source
Advisory

CVE-2013-4786 IPMI RAKP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190919-0005/

NetApp published this final advisory covering CVE-2013-4786; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire Baseboard Management Controller (BMC); StorageGRID Baseboard Management Controller (BMC).

Open source
Advisory

September 2019 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190910-0002/

NetApp published this final advisory covering CVE-2019-5608, CVE-2019-5609, CVE-2019-5610, CVE-2019-5611, CVE-2019-5612; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.

Open source
Advisory

CVE-2019-13139 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190910-0001/

NetApp published this final advisory covering CVE-2019-13139; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2019 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190905-0003/

NetApp published this final advisory covering CVE-2019-10092, CVE-2019-10098, CVE-2019-10082, CVE-2019-10081, CVE-2019-10097; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.

Open source
Advisory

CVE-2019-8460 OpenBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190905-0001/

NetApp published this final advisory covering CVE-2019-8460; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode.

Open source
Advisory

August 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190905-0002/

NetApp published this final advisory covering CVE-2019-14284, CVE-2019-14283, CVE-2018-20856, CVE-2018-20854, CVE-2018-20855, CVE-2018-20961, CVE-2019-15099, CVE-2019-15090, CVE-2019-15117, CVE-2019-15118, CVE-2019-15098, CVE-2019-10140, CVE-2019-15504, CVE-2019-15292, CVE-2019-15505, CVE-2018-20976, CVE-2019-15211, CVE-2019-15212, CVE-2019-15213, CVE-2019-15214, CVE-2019-15215, CVE-2019-15216, CVE-2019-15217, CVE-2019-15218, CVE-2019-15219, CVE-2019-15220, CVE-2019-15221, CVE-2019-15222, CVE-2019-15223, CVE-2019-15290, CVE-2019-15291, CVE-2018-20856; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-10197 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190903-0001/

NetApp published this final advisory covering CVE-2019-10197; the API labels exploitation information as **Not public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2019 IBM Informix Dynamic Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190903-0002/

NetApp published this final advisory covering CVE-2018-1630, CVE-2018-1631, CVE-2018-1632, CVE-2018-1633, CVE-2018-1634, CVE-2018-1635, CVE-2018-1636, CVE-2018-11796, CVE-2019-4253; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2017 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190830-0003/

NetApp published this final advisory covering CVE-2017-3142, CVE-2017-3143; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; OnCommand Balance.

Open source
Advisory

CVE-2018-5741 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190830-0001/

NetApp published this final advisory covering CVE-2018-5741; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2019 GNU patch Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190828-0001/

NetApp published this final advisory covering CVE-2019-13636, CVE-2019-13638; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above.

Open source
Advisory

August 2019 Docker Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190828-0003/

NetApp published this final advisory covering CVE-2019-14271, CVE-2019-13509; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2019 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190828-0002/

NetApp published this final advisory covering CVE-2019-14232, CVE-2019-14233, CVE-2019-14234, CVE-2019-14235; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

August 2019 Apache Tika Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190828-0004/

NetApp published this final advisory covering CVE-2019-10088, CVE-2019-10093, CVE-2019-10094; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-9517 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190823-0003/

NetApp published this final advisory covering CVE-2019-9517; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-1552 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190823-0006/

NetApp published this final advisory covering CVE-2019-1552; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Antivirus Connector; OnCommand Unified Manager Core Package; OnCommand Workflow Automation.

Open source
Advisory

August 2019 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190823-0005/

NetApp published this final advisory covering CVE-2019-9511, CVE-2019-9512, CVE-2019-9513, CVE-2019-9514, CVE-2019-9515, CVE-2019-9516, CVE-2019-9517, CVE-2019-9518; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapCenter.

Open source
Advisory

August 2019 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190823-0002/

NetApp published this final advisory covering CVE-2019-9511, CVE-2019-9513, CVE-2019-9516; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

August 2019 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190823-0001/

NetApp published this final advisory covering CVE-2019-9512, CVE-2019-9514; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2019 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190823-0004/

NetApp published this final advisory covering CVE-2019-9512, CVE-2019-9514; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent; Trident.

Open source
Advisory

CVE-2019-13057 OpenLDAP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190822-0004/

NetApp published this final advisory covering CVE-2019-13057; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2019 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190822-0003/

NetApp published this final advisory covering CVE-2019-11041, CVE-2019-11042; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2019 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190822-0002/

NetApp published this final advisory covering CVE-2019-14250, CVE-2019-14444; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

February 2019 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190814-0004/

NetApp published this final advisory covering CVE-2018-5744, CVE-2018-5745, CVE-2019-6465; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-13232 Info-ZIP UnZip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190814-0002/

NetApp published this final advisory covering CVE-2019-13232; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node.

Open source
Advisory

August 2019 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190814-0003/

NetApp published this final advisory covering CVE-2019-5603, CVE-2019-5604, CVE-2019-5605, CVE-2019-5606, CVE-2019-5607; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2019 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190814-0001/

NetApp published this final advisory covering CVE-2019-14379, CVE-2019-14439; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; NetApp Service Level Manager; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2019-1125 SWAPGS Speculative Execution Side Channel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190809-0002/

NetApp published this final advisory covering CVE-2019-1125; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility.

Open source
Advisory

July 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190806-0001/

NetApp published this final advisory covering CVE-2019-12984, CVE-2019-13233, CVE-2019-10638, CVE-2019-10639, CVE-2019-13631, CVE-2019-13272, CVE-2019-13648; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Service Processor - 8080/8060/8040/8020; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

July 2019 Libxslt Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190806-0004/

NetApp published this final advisory covering CVE-2019-13117, CVE-2019-13118; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-13115 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190806-0002/

NetApp published this final advisory covering CVE-2019-13115; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-13012 GNOME GLib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190806-0003/

NetApp published this final advisory covering CVE-2019-13012; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

August 2019 VxWorks TCP/IP Stack (IPNET) Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190802-0001/

NetApp published this final advisory covering CVE-2019-12256, CVE-2019-12257, CVE-2019-12255, CVE-2019-12260, CVE-2019-12261, CVE-2019-12263, CVE-2019-12258, CVE-2019-12259, CVE-2019-12262, CVE-2019-12264, CVE-2019-12265; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 8.x.

Open source
Advisory

December 2014 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190730-0002/

NetApp published this final advisory covering CVE-2014-8500, CVE-2014-8680; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190719-0003/

NetApp published this final advisory covering CVE-2018-20836, CVE-2019-11810, CVE-2019-11811, CVE-2019-11815; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Cluster Network Switch (NetApp CN1610); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 7.2 and above; Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

July 2019 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190719-0004/

NetApp published this final advisory covering CVE-2019-3822, CVE-2019-2822, CVE-2019-2800, CVE-2019-2795, CVE-2019-2746, CVE-2019-2812, CVE-2019-2834, CVE-2019-2805, CVE-2019-2740, CVE-2019-2758, CVE-2019-2819, CVE-2019-2731, CVE-2019-2778, CVE-2019-2741, CVE-2019-2743, CVE-2019-2739, CVE-2019-2785, CVE-2019-2798, CVE-2019-2879, CVE-2019-2737, CVE-2019-2780, CVE-2019-2784, CVE-2019-2801, CVE-2019-2747, CVE-2019-2757, CVE-2019-2774, CVE-2019-2796, CVE-2019-2802, CVE-2019-2803, CVE-2019-2808, CVE-2019-2810, CVE-2019-2815, CVE-2019-2830, CVE-2019-2752, CVE-2019-2755, CVE-2019-2811, CVE-2019-2826, CVE-2019-2797, CVE-2019-2791, CVE-2019-2738, CVE-2019-2730, CVE-2019-2789, CVE-2019-2814; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2019 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190719-0005/

NetApp published this final advisory covering CVE-2019-2745, CVE-2019-2762, CVE-2019-2766, CVE-2019-2769, CVE-2019-2786, CVE-2019-2816, CVE-2019-2818, CVE-2019-2821, CVE-2019-2842, CVE-2019-7317; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; OnCommand Insight; OnCommand Workflow Automation; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2018-14404 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190719-0002/

NetApp published this final advisory covering CVE-2018-14404; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility.

Open source
Advisory

April 2018 Libxml2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190719-0001/

NetApp published this final advisory covering CVE-2017-5130, CVE-2017-18258; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Data ONTAP Edge; NetApp Manageability SDK; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix.

Open source
Advisory

CVE-2018-20801 Highcharts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190715-0001/

NetApp published this final advisory covering CVE-2018-20801; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

June 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190710-0002/

NetApp published this final advisory covering CVE-2019-12380, CVE-2019-12379, CVE-2019-12455, CVE-2019-12614, CVE-2019-12615, CVE-2019-3846, CVE-2019-12819, CVE-2019-12818, CVE-2019-10126, CVE-2019-12881, CVE-2019-3896; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-13068 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190710-0001/

NetApp published this final advisory covering CVE-2019-13068; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

July 2019 Libvirt Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190705-0001/

NetApp published this final advisory covering CVE-2019-10161, CVE-2019-10166, CVE-2019-10167, CVE-2019-10168; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-12781 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190705-0002/

NetApp published this final advisory covering CVE-2019-12781; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-12384 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190703-0002/

NetApp published this final advisory covering CVE-2019-12384; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; NetApp SANtricity Cloud Connector; NetApp Service Level Manager; OnCommand Workflow Automation.

Open source
Advisory

CVE-2018-20843 Expat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190703-0001/

NetApp published this final advisory covering CVE-2018-20843; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand Workflow Automation; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

Linux Kernel TCP SACK Panic Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0001/

NetApp published this final advisory covering CVE-2019-11477, CVE-2019-11478, CVE-2019-11479; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A320/C190/A220/FAS2720/FAS2750/A800; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; Service Processor; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2019-6471 ISC Bind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0003/

NetApp published this final advisory covering CVE-2019-6471; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-5599 FreeBSD TCP SACK Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0004/

NetApp published this final advisory covering CVE-2019-5599; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-12875 Alpine Linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0005/

NetApp published this final advisory covering CVE-2019-12875; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-12814 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0006/

NetApp published this final advisory covering CVE-2019-12814; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; NetApp SteelStore Cloud Integrated Storage; SnapCenter.

Open source
Advisory

CVE-2019-10072 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0002/

NetApp published this final advisory covering CVE-2019-10072; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 Systemd Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0002/

NetApp published this final advisory covering CVE-2019-3843, CVE-2019-3844; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

June 2019 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0006/

NetApp published this final advisory covering CVE-2019-12435, CVE-2019-12436; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-9740 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0005/

NetApp published this final advisory covering CVE-2019-9740; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-3829 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0004/

NetApp published this final advisory covering CVE-2019-3829; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 7.2 and above.

Open source
Advisory

CVE-2019-0201 Apache ZooKeeper Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0001/

NetApp published this interim advisory covering CVE-2019-0201; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2018-11802 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0003/

NetApp published this final advisory covering CVE-2018-11802; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2019 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190617-0002/

NetApp published this final advisory covering CVE-2019-0196, CVE-2019-0197; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-10160 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190617-0003/

NetApp published this final advisory covering CVE-2019-10160; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Converged Systems Advisor Agent.

Open source
Advisory

CVE-2018-8029 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190617-0001/

NetApp published this final advisory covering CVE-2018-8029; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00247 Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190612-0001/

NetApp published this final advisory covering CVE-2019-0174; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190611-0001/

NetApp published this final advisory covering CVE-2019-5597, CVE-2019-5598; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-9628 XMLTooling Library Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190611-0003/

NetApp published this final advisory covering CVE-2019-9628; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 curl/libcurl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190606-0004/

NetApp published this final advisory covering CVE-2019-5435, CVE-2019-5436; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-8457 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190606-0002/

NetApp published this final advisory covering CVE-2019-8457; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2019-12450 GNOME GLib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190606-0003/

NetApp published this final advisory covering CVE-2019-12450; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190530-0003/

NetApp published this final advisory covering CVE-2018-11307, CVE-2018-12022, CVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-14720, CVE-2018-14721, CVE-2018-19360, CVE-2018-19361, CVE-2018-19362, CVE-2019-12086; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2018-20839 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190530-0002/

NetApp published this final advisory covering CVE-2018-20839; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2018-1000632 Dom4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190530-0001/

NetApp published this final advisory covering CVE-2018-1000632; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand System Manager 3.x; OnCommand Workflow Automation; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2019-5018 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190521-0001/

NetApp published this final advisory covering CVE-2019-5018; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 7th 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190517-0002/

NetApp published this final advisory covering CVE-2018-20509, CVE-2019-11599, CVE-2019-11683; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

May 2019 Wildfly Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190517-0004/

NetApp published this final advisory covering CVE-2019-3805, CVE-2019-3894; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190517-0005/

NetApp published this final advisory covering CVE-2019-11486, CVE-2019-11487, CVE-2019-3882, CVE-2019-3900, CVE-2019-3901; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2019-9636 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190517-0001/

NetApp published this final advisory covering CVE-2019-9636; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-11036 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190517-0003/

NetApp published this final advisory covering CVE-2019-11036; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00223 UEFI Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190516-0001/

NetApp published this final advisory covering CVE-2019-0119, CVE-2019-0120, CVE-2019-0126; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00233 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190515-0001/

NetApp published this final advisory covering CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SteelStore Cloud Integrated Storage; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

Intel SA-00213 Platform Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190515-0002/

NetApp published this final advisory covering CVE-2019-0089, CVE-2019-0090, CVE-2019-0086, CVE-2019-0091, CVE-2019-0092, CVE-2019-0093, CVE-2019-0094, CVE-2019-0096, CVE-2019-0097, CVE-2019-0098, CVE-2019-0099, CVE-2019-0153, CVE-2019-0170; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2018-16860 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190514-0001/

NetApp published this final advisory covering CVE-2018-16860; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190514-0002/

NetApp published this final advisory covering CVE-2018-5743, CVE-2019-6467, CVE-2019-6468; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-5021 Alpine Linux Docker Image Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190510-0001/

NetApp published this final advisory covering CVE-2019-5021; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Missing HTTP Security Headers in OnCommand Unified Manager for VMware vSphere, Linux and Windows 7.3 and above

Source: https://security.netapp.com/advisory/NTAP-20190509-0007/

NetApp published this final advisory covering CVE-2019-5495; the API labels exploitation information as **Not public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above.

Open source
Advisory

Missing HTTP Security Headers in OnCommand Insight

Source: https://security.netapp.com/advisory/NTAP-20190509-0005/

NetApp published this final advisory covering CVE-2019-5496; the API labels exploitation information as **Not public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2019-5953 GNU Wget Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190509-0001/

NetApp published this final advisory covering CVE-2019-5953; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

April 2019 Eclipse Jetty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190509-0003/

NetApp published this final advisory covering CVE-2019-10241, CVE-2019-10246, CVE-2019-10247; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand System Manager 3.x; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

March 2019 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0007/

NetApp published this final advisory covering CVE-2019-9637, CVE-2019-9638, CVE-2019-9639, CVE-2019-9640, CVE-2019-9641; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-9193 PostgreSQL in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0003/

NetApp published this final advisory covering CVE-2019-9193; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-3836 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0005/

NetApp published this final advisory covering CVE-2019-3836; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-0222 Apache ActiveMQ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0006/

NetApp published this final advisory covering CVE-2019-0222; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Web Services (REST API) for Web Services Proxy.

Open source
Advisory

CVE-2018-20449 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0002/

NetApp published this final advisory covering CVE-2018-20449; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2018-16984 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0009/

NetApp published this final advisory covering CVE-2018-16984; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

April 2019 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0004/

NetApp published this final advisory covering CVE-2018-20505, CVE-2018-20506; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0001/

NetApp published this final advisory covering CVE-2019-11034, CVE-2019-11035; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0008/

NetApp published this final advisory covering CVE-2019-5737, CVE-2019-5739; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190423-0002/

NetApp published this final advisory covering CVE-2019-2632, CVE-2019-2693, CVE-2019-2694, CVE-2019-2695, CVE-2019-2692, CVE-2019-1559, CVE-2019-1559, CVE-2018-3123, CVE-2019-2623, CVE-2018-0734, CVE-2019-2634, CVE-2019-2580, CVE-2019-2585, CVE-2019-2593, CVE-2019-2624, CVE-2019-2628, CVE-2019-2566, CVE-2019-2626, CVE-2019-2644, CVE-2019-2631, CVE-2019-2581, CVE-2019-2596, CVE-2019-2607, CVE-2019-2625, CVE-2019-2681, CVE-2019-2685, CVE-2019-2686, CVE-2019-2687, CVE-2019-2688, CVE-2019-2689, CVE-2019-2683, CVE-2019-2592, CVE-2019-2587, CVE-2019-2635, CVE-2019-2584, CVE-2019-2589, CVE-2019-2606, CVE-2019-2620, CVE-2019-2627, CVE-2019-2691, CVE-2019-2636, CVE-2019-2614, CVE-2019-2617, CVE-2019-2630, CVE-2019-1559; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2019 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190423-0003/

NetApp published this final advisory covering CVE-2019-2699, CVE-2019-2697, CVE-2019-2698, CVE-2019-2602, CVE-2019-2684; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Plug-in for Symantec NetBackup; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

April 2019 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190423-0001/

NetApp published this final advisory covering CVE-2019-0211, CVE-2019-0215, CVE-2019-0217; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager for 7-Mode (core package).

Open source
Advisory

April 2019 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190419-0001/

NetApp published this final advisory covering CVE-2019-0199, CVE-2019-0232; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2018 jQuery Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0007/

NetApp published this final advisory covering CVE-2007-2379, CVE-2010-5312, CVE-2011-4969, CVE-2016-7103; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); SnapCenter.

Open source
Advisory

March 2019 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0005/

NetApp published this final advisory covering CVE-2019-9936, CVE-2019-9937; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2018 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0004/

NetApp published this final advisory covering CVE-2018-12099, CVE-2018-19039; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID Webscale NAS Bridge.

Open source
Advisory

CVE-2018-20406 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0010/

NetApp published this final advisory covering CVE-2018-20406; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-20217 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0006/

NetApp published this final advisory covering CVE-2018-20217; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-18955 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0003/

NetApp published this final advisory covering CVE-2018-18955; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); SnapProtect.

Open source
Advisory

CVE-2018-11767 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0009/

NetApp published this final advisory covering CVE-2018-11767; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-1002101 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0008/

NetApp published this final advisory covering CVE-2018-1002101; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0002/

NetApp published this final advisory covering CVE-2019-9946, CVE-2019-1002100; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2019 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190411-0006/

NetApp published this final advisory covering CVE-2018-18849, CVE-2019-6501, CVE-2019-8934; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-9924 GNU Bash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190411-0001/

NetApp published this final advisory covering CVE-2019-9924; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2019-7612 Logstash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190411-0002/

NetApp published this final advisory covering CVE-2019-7612; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-3880 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190411-0004/

NetApp published this final advisory covering CVE-2019-3880; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190411-0003/

NetApp published this final advisory covering CVE-2019-10125, CVE-2019-3874; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2019-3870 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190408-0001/

NetApp published this final advisory covering CVE-2019-3870; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 27th 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190404-0002/

NetApp published this final advisory covering CVE-2019-9857, CVE-2018-19985, CVE-2018-20669, CVE-2019-7222, CVE-2019-7221; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

March 2019 Python Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190404-0004/

NetApp published this final advisory covering CVE-2019-9947, CVE-2019-9948; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2019 PuTTY Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190404-0001/

NetApp published this final advisory covering CVE-2019-9894, CVE-2019-9895, CVE-2019-9896, CVE-2019-9897; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2018 GNU C Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190404-0003/

NetApp published this final advisory covering CVE-2017-1000408, CVE-2017-1000409, CVE-2018-6485, CVE-2018-6551, CVE-2018-1000001; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

May 2018 GNU C Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190401-0001/

NetApp published this final advisory covering CVE-2017-18269, CVE-2018-11236, CVE-2018-11237; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

December 2018 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190401-0003/

NetApp published this final advisory covering CVE-2017-1427, CVE-2017-1428, CVE-2017-1779, CVE-2017-1783, CVE-2017-1784, CVE-2018-1413, CVE-2018-1842; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2019-9898 PuTTY Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190401-0002/

NetApp published this final advisory covering CVE-2019-9898; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager for 7-Mode (core package).

Open source
Advisory

October 2018 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0007/

NetApp published this final advisory covering CVE-2018-17794, CVE-2018-17985, CVE-2018-18309, CVE-2018-18483, CVE-2018-18484; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0002/

NetApp published this final advisory covering CVE-2019-9003, CVE-2019-9162; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

March 2019 Libssh2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0005/

NetApp published this final advisory covering CVE-2019-3855, CVE-2019-3856, CVE-2019-3857, CVE-2019-3858, CVE-2019-3859, CVE-2019-3860, CVE-2019-3861, CVE-2019-3862, CVE-2019-3863; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

Intel SA-00112 Active Management Technology Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0001/

NetApp published this final advisory covering CVE-2018-3628, CVE-2018-3629, CVE-2018-3632; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-6454 systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0004/

NetApp published this final advisory covering CVE-2019-6454; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); SnapProtect.

Open source
Advisory

CVE-2017-3164 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0003/

NetApp published this final advisory covering CVE-2017-3164, CVE-2019-0192; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2019 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190321-0001/

NetApp published this final advisory covering CVE-2019-9025, CVE-2019-9024, CVE-2019-9023, CVE-2019-9022, CVE-2019-9021, CVE-2019-9020; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-20483 GNU Wget Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190321-0002/

NetApp published this final advisory covering CVE-2018-20483; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2018-19591 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190321-0003/

NetApp published this final advisory covering CVE-2018-19591; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Cluster Network Switch (NetApp CN1610); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

Intel SA-00191 Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190318-0002/

NetApp published this final advisory covering CVE-2018-12201, CVE-2018-12202, CVE-2018-12203, CVE-2018-12204, CVE-2018-12205; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00185 CSME-SPS-TXE-AMT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190318-0001/

NetApp published this final advisory covering CVE-2018-12185, CVE-2018-12187, CVE-2018-12188, CVE-2018-12189, CVE-2018-12190, CVE-2018-12191, CVE-2018-12192, CVE-2018-12196, CVE-2018-12198, CVE-2018-12199, CVE-2018-12200, CVE-2018-12208; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

March 2019 GNU C Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190315-0002/

NetApp published this final advisory covering CVE-2009-5155, CVE-2018-20796, CVE-2019-9169; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Cluster Network Switch (NetApp CN1610); NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility; SnapProtect.

Open source
Advisory

CVE-2019-6977 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190315-0003/

NetApp published this final advisory covering CVE-2019-6977; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2019 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190314-0003/

NetApp published this final advisory covering CVE-2019-9070, CVE-2019-9071, CVE-2019-9072, CVE-2019-9073, CVE-2019-9074, CVE-2019-9075, CVE-2019-9076, CVE-2019-9077; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2019-6260 ASPEED BMC Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190314-0001/

NetApp published this final advisory covering CVE-2019-6260; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A320/C190/A220/FAS2720/FAS2750/A800; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-1543 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190314-0002/

NetApp published this final advisory covering CVE-2019-1543; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp Plug-in for Symantec NetBackup; SnapProtect.

Open source
Advisory

November 2018 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190307-0003/

NetApp published this final advisory covering CVE-2018-18605, CVE-2018-18606, CVE-2018-18607; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-5489 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190307-0001/

NetApp published this final advisory covering CVE-2019-5489; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2018-16888 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190307-0007/

NetApp published this final advisory covering CVE-2018-16888; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2015-2080 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190307-0005/

NetApp published this final advisory covering CVE-2015-2080; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Management Plug-ins (VMware vCenter); OnCommand System Manager 3.x; Snap Creator Framework.

Open source
Advisory

CVE-2011-4461 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190307-0004/

NetApp published this final advisory covering CVE-2011-4461; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand System Manager 3.x; Snap Creator Framework; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2019-1559 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190301-0001/

NetApp published this final advisory covering CVE-2019-1559; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Service Processor - 8080/8060/8040/8020; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS); NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2019-3824 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190226-0001/

NetApp published this final advisory covering CVE-2019-3824; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2018 Ruby Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190221-0002/

NetApp published this final advisory covering CVE-2018-16395, CVE-2018-16396; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID Webscale NAS Bridge.

Open source
Advisory

December 2018 PERL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190221-0003/

NetApp published this final advisory covering CVE-2018-18311, CVE-2018-18312, CVE-2018-18313, CVE-2018-18314; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; OnCommand Workflow Automation; Snap Creator Framework; SnapCenter.

Open source
Advisory

December 2018 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190221-0004/

NetApp published this final advisory covering CVE-2018-19931, CVE-2018-19932, CVE-2018-20002; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere.

Open source
Advisory

CVE-2018-1000656 Flask Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190221-0001/

NetApp published this final advisory covering CVE-2018-1000656; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2018-20685 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190215-0001/

NetApp published this final advisory covering CVE-2018-20685; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility.

Open source
Advisory

January 2019 OpenSSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190213-0001/

NetApp published this final advisory covering CVE-2019-6109, CVE-2019-6110, CVE-2019-6111; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility.

Open source
Advisory

November 2017 Apache Commons FileUpload Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190212-0001/

NetApp published this final advisory covering CVE-2016-3092, CVE-2016-1000031; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; E-Series SANtricity Web Services (REST API) for Web Services Proxy; Element Plug-in for vCenter Server; OnCommand Plug-in for Microsoft; Snap Creator Framework; SnapCenter.

Open source
Advisory

CVE-2016-6210 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190206-0001/

NetApp published this final advisory covering CVE-2016-6210; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP Edge; Data ONTAP operating in 7-Mode; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 6.x; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager Core Package; OnCommand Unified Manager for Clustered Data ONTAP; Service Processor; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

September 2018 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190204-0001/

NetApp published this final advisory covering CVE-2018-16597, CVE-2018-17182; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2018-11763 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190204-0004/

NetApp published this final advisory covering CVE-2018-11763; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2019 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190125-0001/

NetApp published this final advisory covering CVE-2019-0190, CVE-2018-17199, CVE-2018-17189; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-3462 APT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190125-0002/

NetApp published this final advisory covering CVE-2019-3462; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapProtect.

Open source
Advisory

January 2019 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190118-0002/

NetApp published this final advisory covering CVE-2018-10933, CVE-2019-2435, CVE-2018-0732, CVE-2019-2534, CVE-2019-2533, CVE-2019-2529, CVE-2019-2482, CVE-2019-2434, CVE-2019-2455, CVE-2019-2503, CVE-2019-2436, CVE-2018-0734, CVE-2019-2536, CVE-2019-2502, CVE-2019-2510, CVE-2019-2539, CVE-2019-2494, CVE-2019-2495, CVE-2019-2537, CVE-2019-2420, CVE-2019-2481, CVE-2019-2507, CVE-2019-2530, CVE-2019-2528, CVE-2019-2531, CVE-2019-2486, CVE-2019-2532, CVE-2019-2535, CVE-2019-2513, CVE-2018-0732; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2019 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190118-0001/

NetApp published this final advisory covering CVE-2019-2540, CVE-2018-11212, CVE-2019-2426, CVE-2019-2449, CVE-2019-2422; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Plug-in for Symantec NetBackup; OnCommand Insight; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

January 2019 Systemd-journald Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190117-0001/

NetApp published this final advisory covering CVE-2018-16864, CVE-2018-16865, CVE-2018-16866; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

November 2018 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181221-0005/

NetApp published this final advisory covering CVE-2018-19395, CVE-2018-19396; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-19935 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181221-0003/

NetApp published this final advisory covering CVE-2018-19935; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-19518 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181221-0004/

NetApp published this final advisory covering CVE-2018-19518; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-15919 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181221-0001/

NetApp published this final advisory covering CVE-2018-15919; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2018-14627 Wildfly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181221-0002/

NetApp published this final advisory covering CVE-2018-14627; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2007-6750 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181221-0006/

NetApp published this final advisory covering No CVE listed; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; OnCommand Unified Manager for 7-Mode (core package).

Open source
Advisory

November 2018 Samba Vulnerabilities in NetApp StorageGRID Products

Source: https://security.netapp.com/advisory/NTAP-20181127-0001/

NetApp published this final advisory covering CVE-2018-16857, CVE-2018-16851, CVE-2018-16852, CVE-2018-16853, CVE-2018-16841, CVE-2018-14629; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2018 Bouncy Castle Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181127-0004/

NetApp published this final advisory covering CVE-2016-1000339, CVE-2016-1000340, CVE-2016-1000341, CVE-2016-1000342, CVE-2016-1000343, CVE-2016-1000344, CVE-2016-1000345, CVE-2016-1000346, CVE-2016-1000352; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Service Level Manager; OnCommand API Services; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2016-7076 sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181127-0002/

NetApp published this final advisory covering CVE-2016-7076; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge.

Open source
Advisory

CVE-2018-5407 Simultaneous Multithreading Side-Channel Information Disclosure Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181126-0001/

NetApp published this final advisory covering CVE-2018-5407; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-16642 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181123-0001/

NetApp published this final advisory covering CVE-2017-16642; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.

Open source
Advisory

CVE-2018-12882 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181109-0001/

NetApp published this final advisory covering CVE-2018-12882; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2018 Net-SNMP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181107-0001/

NetApp published this final advisory covering CVE-2018-18065, CVE-2018-18066; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP operating in 7-Mode; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2017-5645 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181107-0002/

NetApp published this final advisory covering CVE-2017-5645; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Service Level Manager; OnCommand API Services.

Open source
Advisory

August 2018 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181107-0003/

NetApp published this final advisory covering CVE-2017-9118, CVE-2017-9120, CVE-2018-14851, CVE-2018-14883, CVE-2018-14884, CVE-2018-15132; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2018 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181105-0002/

NetApp published this final advisory covering CVE-2018-0734, CVE-2018-0735; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS); NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; ONTAP Antivirus Connector; SnapDrive for Unix; SnapDrive for Windows; SnapProtect.

Open source
Advisory

CVE-2018-0732 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181105-0001/

NetApp published this final advisory covering CVE-2018-0732; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); Data ONTAP Edge; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SteelStore Cloud Integrated Storage; NetApp Storage Encryption; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2018-15473 OpenSSH Username Enumeration Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181101-0001/

NetApp published this final advisory covering CVE-2018-15473; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP Edge; Data ONTAP operating in 7-Mode; FAS/AFF Baseboard Management Controller (BMC) - A320/C190/A220/FAS2720/FAS2750/A800; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; ONTAP Select Deploy administration utility; Service Processor; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2015-5352 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181023-0001/

NetApp published this final advisory covering CVE-2015-5352; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); OnCommand Balance; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

October 2018 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181018-0002/

NetApp published this final advisory covering CVE-2018-11776, CVE-2018-8014, CVE-2018-3258, CVE-2018-1258, CVE-2016-9843, CVE-2018-3155, CVE-2018-3143, CVE-2018-3156, CVE-2018-3251, CVE-2018-3182, CVE-2018-3137, CVE-2018-3203, CVE-2018-3133, CVE-2018-3145, CVE-2018-3144, CVE-2018-3185, CVE-2018-3195, CVE-2018-3247, CVE-2018-3187, CVE-2018-3174, CVE-2018-3171, CVE-2018-3277, CVE-2018-3162, CVE-2018-3173, CVE-2018-3200, CVE-2018-3170, CVE-2018-3212, CVE-2018-3280, CVE-2018-3276, CVE-2018-3186, CVE-2018-3161, CVE-2018-3278, CVE-2018-3279, CVE-2018-3282, CVE-2018-3285, CVE-2018-3284, CVE-2018-3283, CVE-2018-3286; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2018 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181018-0001/

NetApp published this final advisory covering CVE-2018-3183, CVE-2018-3209, CVE-2018-3169, CVE-2018-3149, CVE-2018-3211, CVE-2018-3180, CVE-2018-3214, CVE-2018-3157, CVE-2018-3150, CVE-2018-13785, CVE-2018-3136, CVE-2018-3139; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; OnCommand Insight; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; StorageGRID9 (9.x and prior).

Open source
Advisory

September 2018 Eclipse Jetty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181014-0001/

NetApp published this final advisory covering CVE-2017-7656, CVE-2017-7657, CVE-2017-7658, CVE-2018-12536, CVE-2018-12538; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp SANtricity Cloud Connector; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand System Manager 3.x; OnCommand Unified Manager Core Package; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2018-5391 Linux Kernel Denial of Service Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181003-0002/

NetApp published this final advisory covering CVE-2018-5391; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Data ONTAP Edge; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A320/C190/A220/FAS2720/FAS2750/A800; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2018-12015 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180927-0001/

NetApp published this final advisory covering CVE-2018-12015; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

May 2018 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180926-0004/

NetApp published this final advisory covering CVE-2018-5736, CVE-2018-5737; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

June 2017 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180926-0001/

NetApp published this final advisory covering CVE-2017-3140, CVE-2017-3141; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Balance.

Open source
Advisory

February 2018 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180926-0005/

NetApp published this final advisory covering CVE-2016-2848, CVE-2016-8864, CVE-2016-9131, CVE-2016-9147, CVE-2016-9444, CVE-2016-9778, CVE-2017-3135, CVE-2018-5734; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2018-5740 ISC Bind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180926-0003/

NetApp published this final advisory covering CVE-2018-5740; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2016-4975 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180926-0006/

NetApp published this final advisory covering CVE-2016-4975; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2016-2848 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180926-0002/

NetApp published this final advisory covering CVE-2016-2848; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp VASA Provider for Clustered Data ONTAP 6.x.

Open source
Advisory

September 2018 Intel Converged Security Management Engine Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180924-0003/

NetApp published this interim advisory covering CVE-2018-3655, CVE-2018-3657, CVE-2018-3658, CVE-2018-3659, CVE-2018-3616; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2018-17082 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180924-0001/

NetApp published this final advisory covering CVE-2018-17082; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-11776 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180822-0001/

NetApp published this final advisory covering CVE-2018-11776; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2018 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180817-0001/

NetApp published this final advisory covering CVE-2018-1336, CVE-2018-8034, CVE-2018-8037; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

Intel SA-00161 L1 Terminal Fault Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180815-0001/

NetApp published this final advisory covering CVE-2018-3615, CVE-2018-3620, CVE-2018-3646; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-5390 Linux Kernel Denial of Service (DoS) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180815-0003/

NetApp published this final advisory covering CVE-2018-5390; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; StorageGRID (formerly StorageGRID Webscale); Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

August 2018 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180814-0001/

NetApp published this final advisory covering CVE-2018-10919, CVE-2018-10918, CVE-2018-10858, CVE-2018-1140, CVE-2018-1139; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-3652 Intel Processor Information Disclosure and Privilege Escalation Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180802-0001/

NetApp published this final advisory covering CVE-2018-3652; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2017 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180802-0002/

NetApp published this final advisory covering CVE-2017-3136, CVE-2017-3137, CVE-2017-3138; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Balance.

Open source
Advisory

November 2017 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180731-0002/

NetApp published this final advisory covering CVE-2016-1240, CVE-2016-9774, CVE-2016-9775, CVE-2017-6056; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; OnCommand Balance; OnCommand Shift; Virtual Storage Console for VMware vSphere 6.x.

Open source
Advisory

July 2018 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180726-0002/

NetApp published this final advisory covering CVE-2017-5645, CVE-2017-0379, CVE-2018-3064, CVE-2018-0739, CVE-2018-0739, CVE-2018-3070, CVE-2018-3060, CVE-2018-3065, CVE-2018-0739, CVE-2018-3073, CVE-2018-0739, CVE-2018-3074, CVE-2018-3062, CVE-2018-3081, CVE-2018-3071, CVE-2018-3079, CVE-2018-3054, CVE-2018-3077, CVE-2018-3078, CVE-2018-3080, CVE-2018-3061, CVE-2018-3067, CVE-2018-3063, CVE-2018-3075, CVE-2018-3058, CVE-2018-3056, CVE-2018-2598, CVE-2018-3066, CVE-2018-2767, CVE-2018-3084, CVE-2018-3082; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2018 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180726-0001/

NetApp published this final advisory covering CVE-2018-2938, CVE-2018-2940, CVE-2018-2941, CVE-2018-2942, CVE-2018-2952, CVE-2018-2964, CVE-2018-2972, CVE-2018-2973; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand Insight; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2018-0737 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180726-0003/

NetApp published this final advisory covering CVE-2018-0737; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Data ONTAP Edge; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; ONTAP Antivirus Connector; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect.

Open source
Advisory

July 2017 Apache Struts Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180706-0002/

NetApp published this final advisory covering CVE-2017-7672, CVE-2017-9791, CVE-2017-9787; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance.

Open source
Advisory

April 2018 Apache Struts Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180629-0006/

NetApp published this final advisory covering CVE-2016-1182, CVE-2016-1181, CVE-2015-0899, CVE-2014-0114; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2015-8325 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180628-0001/

NetApp published this final advisory covering CVE-2015-8325; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); OnCommand Balance.

Open source
Advisory

March 2018 Network Time Protocol Daemon (ntpd) Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180626-0001/

NetApp published this final advisory covering CVE-2018-7170, CVE-2018-7182, CVE-2018-7183, CVE-2018-7184, CVE-2018-7185; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2015-8960 TLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180626-0002/

NetApp published this final advisory covering CVE-2015-8960; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; OnCommand Shift; Snap Creator Framework; SnapDrive for Unix; SnapDrive for Windows; SnapManager for Oracle; SnapManager for SAP; SnapProtect; System Setup.

Open source
Advisory

March 2017 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180614-0001/

NetApp published this final advisory covering CVE-2017-5651, CVE-2017-5648, CVE-2017-5647, CVE-2017-5650; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; OnCommand Shift; Snap Creator Framework.

Open source
Advisory

July 2017 Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180614-0003/

NetApp published this final advisory covering CVE-2017-7674, CVE-2017-7675; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Shift.

Open source
Advisory

November 2016 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180607-0001/

NetApp published this final advisory covering CVE-2016-8735, CVE-2016-6817, CVE-2016-6816; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; OnCommand Insight; OnCommand Shift; Snap Creator Framework.

Open source
Advisory

May 2018 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180607-0003/

NetApp published this final advisory covering CVE-2018-10545, CVE-2018-10546, CVE-2018-10547, CVE-2018-10548, CVE-2018-10549; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2016-8745 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180607-0002/

NetApp published this final advisory covering CVE-2016-8745; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight; OnCommand Shift; Snap Creator Framework.

Open source
Advisory

October 2016 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180605-0001/

NetApp published this final advisory covering CVE-2016-5018, CVE-2016-6796, CVE-2016-6797, CVE-2016-6794, CVE-2016-0762; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight; OnCommand Shift; Snap Creator Framework.

Open source
Advisory

March 2018 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180601-0004/

NetApp published this final advisory covering CVE-2017-15710, CVE-2017-15715, CVE-2018-1283, CVE-2018-1301, CVE-2018-1302, CVE-2018-1303, CVE-2018-1312; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

June 2017 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180601-0002/

NetApp published this final advisory covering CVE-2017-3167, CVE-2017-3169, CVE-2017-7659, CVE-2017-7668, CVE-2017-7679; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; OnCommand Unified Manager for 7-Mode (core package); StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2016-8612 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180601-0005/

NetApp published this final advisory covering CVE-2016-8612; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2016 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180531-0001/

NetApp published this final advisory covering CVE-2015-5345, CVE-2015-5351, CVE-2016-0706, CVE-2016-0714, CVE-2016-0763, CVE-2015-5174, CVE-2015-5346; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight; OnCommand Report; OnCommand Shift; Snap Creator Framework; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2018-5487 Unauthenticated Remote Code Execution Vulnerability in OnCommand Unified Manager for Linux and Windows 7.2 and above

Source: https://security.netapp.com/advisory/NTAP-20180523-0001/

NetApp published this final advisory covering CVE-2018-5487; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above.

Open source
Advisory

Speculative Execution Side Channel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180521-0001/

NetApp published this final advisory covering CVE-2018-3639, CVE-2018-3640; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2017 Perl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180426-0001/

NetApp published this final advisory covering CVE-2017-12883, CVE-2017-12837, CVE-2017-12814; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Workflow Automation.

Open source
Advisory

December 2016 Apache HTTP Server Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180423-0001/

NetApp published this final advisory covering CVE-2016-0736, CVE-2016-2161, CVE-2016-8740, CVE-2016-8743; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP; OnCommand Unified Manager for 7-Mode (core package).

Open source
Advisory

CVE-2018-5968 Jackson JSON Library Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180423-0002/

NetApp published this final advisory covering CVE-2018-5968; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Web Services (REST API) for Web Services Proxy; OnCommand Shift.

Open source
Advisory

CVE-2017-15906 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180423-0004/

NetApp published this final advisory covering CVE-2017-15906; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand Unified Manager Core Package; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2016-10708 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180423-0003/

NetApp published this final advisory covering CVE-2016-10708; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Clustered Data ONTAP; Data ONTAP Edge; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; Service Processor; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

April 2018 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180419-0002/

NetApp published this final advisory covering CVE-2018-2755, CVE-2018-2805, CVE-2018-2782, CVE-2018-2784, CVE-2018-2819, CVE-2018-2758, CVE-2018-2817, CVE-2018-2775, CVE-2018-2780, CVE-2017-3737, CVE-2018-2761, CVE-2018-2786, CVE-2018-2787, CVE-2018-2812, CVE-2018-2877, CVE-2018-2759, CVE-2018-2766, CVE-2018-2777, CVE-2018-2810, CVE-2018-2818, CVE-2018-2839, CVE-2018-2778, CVE-2018-2779, CVE-2018-2781, CVE-2018-2816, CVE-2018-2846, CVE-2018-2769, CVE-2018-2776, CVE-2018-2762, CVE-2018-2771, CVE-2018-2813, CVE-2018-2773, CVE-2016-9878; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2018 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180419-0001/

NetApp published this final advisory covering CVE-2018-2825, CVE-2018-2826, CVE-2018-2814, CVE-2018-2811, CVE-2018-2794, CVE-2018-2783, CVE-2018-2798, CVE-2018-2796, CVE-2018-2799, CVE-2018-2797, CVE-2018-2795, CVE-2018-2815, CVE-2018-2800, CVE-2018-2790; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SANtricity Cloud Connector; NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Insight; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 7.2 and above; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

March 2018 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180330-0002/

NetApp published this final advisory covering CVE-2018-0739, CVE-2018-0733; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp VASA Provider for Clustered Data ONTAP 9.6 and above; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.6 and above; Virtual Storage Console for VMware vSphere 9.6 and above.

Open source
Advisory

CVE-2018-1327 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180330-0001/

NetApp published this final advisory covering CVE-2018-1327; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-7489 Jackson JSON Library Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180328-0001/

NetApp published this final advisory covering CVE-2018-7489; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Service Level Manager; OnCommand API Services; OnCommand Cloud Manager; SnapCenter.

Open source
Advisory

March 2018 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180313-0001/

NetApp published this final advisory covering CVE-2018-1057, CVE-2018-1050; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2016-0793 Wildfly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180215-0001/

NetApp published this final advisory covering CVE-2016-0793; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above.

Open source
Advisory

SMBLoris Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180213-0001/

NetApp published this final advisory covering No CVE listed; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2017-17485 Jackson JSON Library vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180201-0003/

NetApp published this final advisory covering CVE-2017-17485; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Web Services (REST API) for Web Services Proxy; OnCommand Shift; SnapCenter.

Open source
Advisory

CVE-2016-8858 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180201-0001/

NetApp published this final advisory covering CVE-2016-8858; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2015-6563 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180201-0002/

NetApp published this final advisory covering CVE-2015-6563; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP Edge; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; ONTAP Select Deploy administration utility.

Open source
Advisory

January 2018 MySQL vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180117-0002/

NetApp published this final advisory covering CVE-2017-12617, CVE-2018-2585, CVE-2018-2696, CVE-2018-2562, CVE-2018-2583, CVE-2018-2612, CVE-2018-2703, CVE-2018-2622, CVE-2018-2573, CVE-2018-2640, CVE-2018-2665, CVE-2018-2668, CVE-2017-3736, CVE-2017-3736, CVE-2017-3737, CVE-2018-2647, CVE-2018-2591, CVE-2018-2576, CVE-2018-2586, CVE-2018-2646, CVE-2018-2565, CVE-2018-2600, CVE-2018-2667, CVE-2018-2590, CVE-2018-2645; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2018 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180117-0001/

NetApp published this final advisory covering CVE-2018-2638, CVE-2018-2639, CVE-2018-2633, CVE-2018-2627, CVE-2018-2637, CVE-2018-2634, CVE-2018-2582, CVE-2018-2641, CVE-2018-2618, CVE-2018-2629, CVE-2018-2603, CVE-2018-2657, CVE-2018-2599, CVE-2018-2581, CVE-2018-2602, CVE-2018-2677, CVE-2018-2678, CVE-2018-2588, CVE-2018-2663, CVE-2018-2675, CVE-2018-2579; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SANtricity Cloud Connector; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Insight; OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 7.2 and above; Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 6.x; Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

September 2017 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180112-0001/

NetApp published this final advisory covering CVE-2017-11628, CVE-2017-11362, CVE-2017-11142, CVE-2016-10397, CVE-2017-11143, CVE-2017-11144, CVE-2017-11145, CVE-2017-11147, CVE-2017-9119, CVE-2016-5399, CVE-2017-7272, CVE-2016-5873, CVE-2016-10160, CVE-2016-7479, CVE-2016-7480, CVE-2017-5340, CVE-2016-7478, CVE-2017-12932, CVE-2017-7890, CVE-2016-10158, CVE-2016-10159, CVE-2016-10161; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.

Open source
Advisory

CVE-2017-8779 rpcbind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180109-0001/

NetApp published this final advisory covering CVE-2017-8779; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP Edge; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand Balance; SnapProtect; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

Processor Speculated Execution Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180104-0001/

NetApp published this final advisory covering CVE-2017-5715, CVE-2017-5753, CVE-2017-5754; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2017-13098 Bouncy Castle TLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171222-0001/

NetApp published this final advisory covering CVE-2017-13098; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-7525 Jackson JSON Library Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171214-0002/

NetApp published this final advisory covering CVE-2017-7525; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Performance Manager for Linux; OnCommand Performance Manager for VMware vSphere; OnCommand Shift; SnapCenter.

Open source
Advisory

CVE-2017-15095 Jackson JSON Library vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171214-0003/

NetApp published this final advisory covering CVE-2017-15095; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Performance Manager for Linux; OnCommand Performance Manager for VMware vSphere; OnCommand Shift; SnapCenter.

Open source
Advisory

December 2017 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171208-0001/

NetApp published this final advisory covering CVE-2017-3737, CVE-2017-3738; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Storage Node (Element Software); NetApp Storage Encryption; NetApp VASA Provider for Clustered Data ONTAP 6.x; OnCommand Balance; OnCommand Performance Manager for VMware vSphere; OnCommand Unified Manager Core Package; OnCommand Unified Manager for VMware vSphere for 7.1 and below; OnCommand Workflow Automation; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

January 2017 OpenSSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171130-0002/

NetApp published this final advisory covering CVE-2016-10012, CVE-2016-10011, CVE-2016-10010, CVE-2016-10009; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP operating in 7-Mode; Management Network Switch (NetApp CN1601); NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager for 7-Mode (core package).

Open source
Advisory

CVE-2016-8610 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171130-0001/

NetApp published this final advisory covering CVE-2016-8610; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; E-Series SANtricity OS Controller Software 11.x; NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp VASA Provider for Clustered Data ONTAP 6.x; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; Service Processor; SnapCenter; SnapDrive for Unix; SnapProtect; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2016-6515 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171130-0003/

NetApp published this final advisory covering CVE-2016-6515: OpenSSH vulnerability; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager for Clustered Data ONTAP; Service Processor; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

Intel SA-00086 Management Engine Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171120-0001/

NetApp published this final advisory covering CVE-2017-5705, CVE-2017-5708, CVE-2017-5711, CVE-2017-5712, CVE-2017-5706, CVE-2017-5709, CVE-2017-5707, CVE-2017-5710; the API labels exploitation information as **Not public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-3736 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171107-0002/

NetApp published this final advisory covering CVE-2017-3736; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; E-Series SANtricity OS Controller Software 11.x; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp Storage Encryption; NetApp VASA Provider for Clustered Data ONTAP 6.x; OnCommand Balance; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

January 2016 Network Time Protocol Daemon (ntpd) Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171031-0001/

NetApp published this final advisory covering CVE-2015-7979, CVE-2015-7973, CVE-2015-7974, CVE-2015-8158, CVE-2015-8138, CVE-2015-7978, CVE-2015-7977, CVE-2015-7976, CVE-2015-7975; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; OnCommand Balance.

Open source
Advisory

CVE-2017-15361 Infineon RSA Library Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171024-0001/

NetApp published this final advisory covering CVE-2017-15361; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2017 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171019-0002/

NetApp published this final advisory covering CVE-2017-10155, CVE-2017-10165, CVE-2017-10167, CVE-2017-10203, CVE-2017-10227, CVE-2017-10268, CVE-2017-10276, CVE-2017-10277, CVE-2017-10279, CVE-2017-10283, CVE-2017-10284, CVE-2017-10286, CVE-2017-10294, CVE-2017-10296, CVE-2017-10311, CVE-2017-10313, CVE-2017-10314, CVE-2017-10320, CVE-2017-10365, CVE-2017-10378, CVE-2017-10379, CVE-2017-10384, CVE-2017-10424, CVE-2017-3731, CVE-2017-5664; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager for VMware vSphere; OnCommand Unified Manager for VMware vSphere for 7.1 and below; OnCommand Unified Manager for Windows for 7.1 and below; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2017 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171019-0001/

NetApp published this final advisory covering CVE-2017-10346, CVE-2017-10285, CVE-2017-10388, CVE-2017-10309, CVE-2017-10274, CVE-2017-10356, CVE-2017-10293, CVE-2017-10342, CVE-2017-10350, CVE-2017-10349, CVE-2017-10348, CVE-2017-10357, CVE-2016-9841, CVE-2016-10165, CVE-2017-10355, CVE-2017-10281, CVE-2017-10347, CVE-2017-10386, CVE-2017-10380, CVE-2017-10295, CVE-2017-10341, CVE-2017-10345; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager for VMware vSphere; OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for VMware vSphere for 7.1 and below; OnCommand Unified Manager for Windows for 7.1 and below; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 7.2 and above; Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above; Virtual Storage Console for VMware vSphere 6.x; Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

CVE-2017-12617 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171018-0002/

NetApp published this final advisory covering CVE-2017-12617; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; OnCommand Balance; OnCommand Shift.

Open source
Advisory

August 2017 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171018-0001/

NetApp published this final advisory covering CVE-2017-12615, CVE-2017-12616; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; OnCommand Balance; OnCommand Shift.

Open source
Advisory

October 2015 Network Time Protocol Daemon (ntpd) Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171004-0001/

NetApp published this final advisory covering CVE-2015-7871, CVE-2015-7855, CVE-2015-7854, CVE-2015-7853, CVE-2015-7852, CVE-2015-7851, CVE-2015-7850, CVE-2015-7849, CVE-2015-7848, CVE-2015-7701, CVE-2015-7703, CVE-2015-7704, CVE-2015-7705, CVE-2015-7691, CVE-2015-7692, CVE-2015-7702, CVE-2015-5300; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP.

Open source
Advisory

April 2016 Network Time Protocol Daemon (ntpd) Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171004-0002/

NetApp published this final advisory covering CVE-2015-7704, CVE-2016-1548, CVE-2015-8138, CVE-2016-1549, CVE-2016-2516, CVE-2016-2517, CVE-2016-2519, CVE-2016-1550, CVE-2016-1547, CVE-2016-1551, CVE-2016-2518; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP.

Open source
Advisory

CVE-2017-3735 OpenSSL Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170927-0001/

NetApp published this final advisory covering CVE-2017-3735; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; E-Series SANtricity OS Controller Software 11.x; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 6.x; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

September 2017 Samba Vulnerabilities in NetApp StorageGRID Products

Source: https://security.netapp.com/advisory/NTAP-20170921-0001/

NetApp published this final advisory covering CVE-2017-12150, CVE-2017-12151, CVE-2017-12163; the API labels exploitation information as **Not public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale); StorageGRID Webscale NAS Bridge; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-1999-0016 Denial of Service Vulnerability in Data ONTAP

Source: https://security.netapp.com/advisory/NTAP-20170815-0001/

NetApp published this final advisory covering CVE-1999-0016; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode.

Open source
Advisory

Linux Memory Management Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170808-0001/

NetApp published this final advisory covering CVE-2017-1000364, CVE-2017-1000365, CVE-2017-1000366; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Data ONTAP Edge; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Balance; SnapProtect.

Open source
Advisory

June 2017 sudo Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170803-0001/

NetApp published this final advisory covering CVE-2017-1000367, CVE-2017-1000368; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; Management Network Switch (NetApp CN1601); ONTAP Select Deploy administration utility; OnCommand Balance.

Open source
Advisory

July 2017 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170720-0002/

NetApp published this final advisory covering CVE-2016-4436, CVE-2017-5651, CVE-2017-5647, CVE-2017-3633, CVE-2017-3634, CVE-2017-3732, CVE-2017-3732, CVE-2017-3732, CVE-2017-3635, CVE-2017-3635, CVE-2017-3636, CVE-2017-3529, CVE-2017-3637, CVE-2017-3639, CVE-2017-3640, CVE-2017-3641, CVE-2017-3643, CVE-2017-3644, CVE-2017-3638, CVE-2017-3642, CVE-2017-3645, CVE-2017-3646, CVE-2014-1912, CVE-2017-3648, CVE-2017-3647, CVE-2017-3649, CVE-2017-3651, CVE-2017-3652, CVE-2017-3650, CVE-2017-3653; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager for VMware vSphere; OnCommand Unified Manager for VMware vSphere for 7.1 and below; OnCommand Unified Manager for Windows for 7.1 and below; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2017 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170720-0001/

NetApp published this final advisory covering CVE-2017-10110, CVE-2017-10089, CVE-2017-10086, CVE-2017-10096, CVE-2017-10101, CVE-2017-10087, CVE-2017-10090, CVE-2017-10111, CVE-2017-10107, CVE-2017-10102, CVE-2017-10114, CVE-2017-10074, CVE-2017-10116, CVE-2017-10078, CVE-2017-10067, CVE-2017-10115, CVE-2017-10118, CVE-2017-10176, CVE-2017-10104, CVE-2017-10145, CVE-2017-10125, CVE-2017-10198, CVE-2017-10243, CVE-2017-10121, CVE-2017-10135, CVE-2017-10117, CVE-2017-10053, CVE-2017-10108, CVE-2017-10109, CVE-2017-10105, CVE-2017-10081, CVE-2017-10193; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager for VMware vSphere; OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for VMware vSphere for 7.1 and below; OnCommand Unified Manager for Windows for 7.1 and below; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above; Virtual Storage Console for VMware vSphere 6.x; Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

March 2017 Network Time Protocol Daemon (ntpd) Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170526-0001/

NetApp published this final advisory covering CVE-2017-6464, CVE-2017-6462, CVE-2017-6463, CVE-2017-6455, CVE-2017-6452, CVE-2017-6459, CVE-2017-6458, CVE-2017-6451, CVE-2017-6460, CVE-2016-9042; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Balance.

Open source
Advisory

NetApp Product Security Notice for WannaCrypt and Petya Ransomware

Source: https://security.netapp.com/advisory/NTAP-20170515-0001/

NetApp published this final advisory covering CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, CVE-2017-0147, CVE-2017-0148; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-5689 Intel Management Engine Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170509-0001/

NetApp published this final advisory covering CVE-2017-5689; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2017 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170420-0002/

NetApp published this final advisory covering CVE-2017-3308, CVE-2017-3309, CVE-2017-3450, CVE-2017-3599, CVE-2017-3329, CVE-2017-3600, CVE-2017-3331, CVE-2017-3453, CVE-2017-3452, CVE-2017-3454, CVE-2017-3455, CVE-2017-3305, CVE-2017-3302, CVE-2017-3460, CVE-2017-3456, CVE-2017-3458, CVE-2017-3457, CVE-2017-3459, CVE-2017-3463, CVE-2017-3462, CVE-2017-3461, CVE-2017-3464, CVE-2017-3465, CVE-2017-3467, CVE-2017-3468; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2017 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170420-0001/

NetApp published this final advisory covering CVE-2017-3512, CVE-2017-3514, CVE-2017-3511, CVE-2017-3526, CVE-2017-3509, CVE-2017-3533, CVE-2017-3544, CVE-2017-3539; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Plug-in for Symantec NetBackup; NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

November 2016 Network Time Protocol Daemon (ntpd) Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170310-0002/

NetApp published this final advisory covering CVE-2016-7426, CVE-2016-7427, CVE-2016-7428, CVE-2016-7429, CVE-2016-7431, CVE-2016-7433, CVE-2016-7434, CVE-2016-9310, CVE-2016-9311, CVE-2016-9312; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

January 2017 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170127-0001/

NetApp published this final advisory covering CVE-2017-3732, CVE-2017-3731, CVE-2017-3730, CVE-2016-7055; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP operating in 7-Mode; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp SMI-S Provider; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); OnCommand Unified Manager Core Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

January 2017 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170119-0002/

NetApp published this final advisory covering CVE-2016-8318, CVE-2017-3312, CVE-2017-3258, CVE-2017-3273, CVE-2017-3244, CVE-2017-3257, CVE-2017-3238, CVE-2017-3256, CVE-2017-3291, CVE-2017-3265, CVE-2017-3251, CVE-2016-5541, CVE-2017-3313, CVE-2017-3243, CVE-2016-8327, CVE-2017-3317, CVE-2017-3318, CVE-2017-3321, CVE-2017-3323, CVE-2017-3322, CVE-2017-3319, CVE-2017-3320; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2017 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170119-0001/

NetApp published this final advisory covering CVE-2017-3289, CVE-2017-3272, CVE-2017-3241, CVE-2017-3260, CVE-2017-3253, CVE-2016-5546, CVE-2016-5549, CVE-2016-5548, CVE-2017-3252, CVE-2017-3262, CVE-2016-5547, CVE-2016-5552, CVE-2017-3231, CVE-2017-3261, CVE-2017-3259, CVE-2016-8328, CVE-2016-2183; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

December 2016 Samba Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20161219-0001/

NetApp published this final advisory covering CVE-2016-2123, CVE-2016-2125, CVE-2016-2126; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale); StorageGRID Webscale NAS Bridge; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2016-5195 Kernel Local Privilege Escalation Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20161025-0001/

NetApp published this final advisory covering CVE-2016-5195; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; SnapProtect.

Open source
Advisory

October 2016 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20161019-0002/

NetApp published this final advisory covering CVE-2016-6304, CVE-2016-6662, CVE-2016-5617, CVE-2016-5616, CVE-2016-5625, CVE-2016-5609, CVE-2016-5612, CVE-2016-5624, CVE-2016-5626, CVE-2016-5627, CVE-2016-3492, CVE-2016-7440, CVE-2016-5628, CVE-2016-5629, CVE-2016-3495, CVE-2016-5630, CVE-2016-5507, CVE-2016-5631, CVE-2016-5632, CVE-2016-5633, CVE-2016-5634, CVE-2016-5635, CVE-2016-8289, CVE-2016-8287, CVE-2016-8290, CVE-2016-5584, CVE-2016-8283, CVE-2016-8288, CVE-2016-8286, CVE-2016-8284; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapCenter; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

October 2016 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20161019-0001/

NetApp published this final advisory covering CVE-2016-5556, CVE-2016-5568, CVE-2016-5582, CVE-2016-5573, CVE-2016-5597, CVE-2016-5554, CVE-2016-5542; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Cloud Manager; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; SnapManager for Oracle; SnapManager for SAP; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2010-1871 JBoss Seam Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20161017-0001/

NetApp published this final advisory covering CVE-2010-1871; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Insight; OnCommand Unified Manager for Clustered Data ONTAP.

Open source
Advisory

CVE-2016-2776 ISC BIND Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160930-0001/

NetApp published this final advisory covering CVE-2016-2776; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 7.2 and above.

Open source
Advisory

September 2016 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160928-0001/

NetApp published this final advisory covering CVE-2016-6304, CVE-2016-2183, CVE-2016-6303, CVE-2016-6302, CVE-2016-2182, CVE-2016-2180, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2181, CVE-2016-6306, CVE-2016-6305, CVE-2016-6307, CVE-2016-6308; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP operating in 7-Mode; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Storage Node (Element Software); NetApp Storage Encryption; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID (formerly StorageGRID Webscale); StorageGRID Webscale NAS Bridge; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2016-2183 TLS Protocol 64-bit Cipher Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160915-0001/

NetApp published this final advisory covering CVE-2016-2183; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; AFF Baseboard Management Controller (BMC) - A700s; Brocade Fabric Operating System Firmware; Brocade Network Advisor Software; Data ONTAP operating in 7-Mode; E-Series SANtricity Storage Manager; FAS/AFF Service Processor - 8080/8060/8040/8020; NetApp Cloud Backup (formerly AltaVault); NetApp Console Agent; NetApp Host Agent; NetApp Manageability SDK; NetApp ONTAP PowerShell Toolkit (PSTK); NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; ONTAP 9; ONTAP Select Deploy administration utility; OnCommand Insight; OnCommand Shift; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; Perfstat; RBAC User Creator for Data ONTAP; Snap Creator Framework; SnapCenter; SnapCenter Plug-in for VMware vSphere; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior); System Setup; Virtual Storage Console for VMware vSphere 6.x; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

June 2016 Network Time Protocol Daemon (ntpd) Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160722-0001/

NetApp published this final advisory covering CVE-2016-4953, CVE-2016-4954, CVE-2016-4955, CVE-2016-4956, CVE-2016-4957; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP.

Open source
Advisory

CVE-2016-2775 ISC BIND Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160722-0002/

NetApp published this final advisory covering CVE-2016-2775; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2016 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160721-0002/

NetApp published this final advisory covering CVE-2016-3477, CVE-2016-3440, CVE-2016-2105, CVE-2016-3471, CVE-2016-3486, CVE-2016-3501, CVE-2016-3518, CVE-2016-3521, CVE-2016-3588, CVE-2016-3615, CVE-2016-3614, CVE-2016-5436, CVE-2016-3459, CVE-2016-5437, CVE-2016-3424, CVE-2016-5439, CVE-2016-5440, CVE-2016-5441, CVE-2016-5442, CVE-2016-5443, CVE-2016-5444, CVE-2016-3452; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation.

Open source
Advisory

July 2016 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160721-0001/

NetApp published this final advisory covering CVE-2016-3587, CVE-2016-3606, CVE-2016-3598, CVE-2016-3610, CVE-2016-3552, CVE-2016-3511, CVE-2016-3503, CVE-2016-3498, CVE-2016-3500, CVE-2016-3508, CVE-2016-3458, CVE-2016-3550, CVE-2016-3485; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

CVE-2016-2119 Samba SMB Client Required Signing Downgrade Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20160708-0001/

NetApp published this final advisory covering CVE-2016-2119; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2015-3253 Apache Groovy Vulnerability in OnCommand Insight

Source: https://security.netapp.com/advisory/NTAP-20160623-0001/

NetApp published this final advisory covering CVE-2015-3253; the API labels exploitation information as **Public**. The API currently lists affected products as: MetroCluster Plug-in for vSphere; OnCommand Insight; RapidData Migration Solution.

Open source
Advisory

May 2016 OpenSSH Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160519-0001/

NetApp published this final advisory covering CVE-2016-3115, CVE-2016-1907, CVE-2016-1908; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Unified Manager for Clustered Data ONTAP.

Open source
Advisory

May 2016 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160504-0001/

NetApp published this final advisory covering CVE-2016-2108, CVE-2016-2105, CVE-2016-2107, CVE-2016-2106, CVE-2016-2109, CVE-2016-2176; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp Storage Encryption; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

April 2016 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160421-0001/

NetApp published this final advisory covering CVE-2016-0705, CVE-2016-0639, CVE-2015-3194, CVE-2016-0640, CVE-2016-0641, CVE-2016-2047, CVE-2016-0642, CVE-2016-0643, CVE-2016-0644, CVE-2016-0646, CVE-2016-0647, CVE-2016-0648, CVE-2016-0649, CVE-2016-0650, CVE-2016-0652, CVE-2016-0653, CVE-2016-0654, CVE-2016-0655, CVE-2016-0656, CVE-2016-0657, CVE-2016-0658, CVE-2016-0651, CVE-2016-0659, CVE-2016-0661, CVE-2016-0662, CVE-2016-0663, CVE-2016-0665, CVE-2016-0666, CVE-2016-0667, CVE-2016-0668; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation.

Open source
Advisory

April 2016 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160420-0001/

NetApp published this final advisory covering CVE-2016-3443, CVE-2016-0687, CVE-2016-0686, CVE-2016-3427, CVE-2016-3449, CVE-2016-3422, CVE-2016-3425, CVE-2016-3426, CVE-2016-0695; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

SMB Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160412-0001/

NetApp published this final advisory covering CVE-2016-3400, CVE-2016-3997, CVE-2016-3998, CVE-2016-2118; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

August 2015 OpenSSH Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160330-0001/

NetApp published this final advisory covering CVE-2015-6564, CVE-2015-6565; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; FlashRay; NetApp VTL; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP.

Open source
Advisory

CVE-2016-0636 Java Platform Standard Edition Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160328-0001/

NetApp published this final advisory covering CVE-2016-0636; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Insight; OnCommand Report; OnCommand Unified Manager for 7-Mode (core package).

Open source
Advisory

March 2016 ISC BIND Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160322-0002/

NetApp published this final advisory covering CVE-2016-1285, CVE-2016-1286, CVE-2016-2088; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above.

Open source
Advisory

January 2016 ISC BIND Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160322-0001/

NetApp published this final advisory covering CVE-2015-8704, CVE-2015-8705; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above.

Open source
Advisory

CVE-2016-2842 OpenSSL Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160321-0001/

NetApp published this final advisory covering CVE-2016-2842; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp Host Agent; NetApp SMI-S Provider; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; Open Systems SnapVault Agent; SnapCenter; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

March 2016 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160303-0001/

NetApp published this final advisory covering CVE-2016-0703, CVE-2016-0704, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-0702, CVE-2016-0705; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp Host Agent; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp Storage Encryption; OnCommand Balance; OnCommand Report; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2016-0800 SSLv2 Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160301-0001/

NetApp published this final advisory covering CVE-2016-0800; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP operating in 7-Mode; MetroCluster Tiebreaker for clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); NetApp Host Agent; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Report; OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; Open Systems SnapVault Agent; Perfstat; RBAC User Creator for Data ONTAP; Snap Creator Framework; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 7.2 and above; Storage Replication Adapter for Data ONTAP operating in 7-Mode 2.1.

Open source
Advisory

CVE-2015-7575 TLS Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160225-0001/

NetApp published this final advisory covering CVE-2015-7575; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Brocade Fabric Operating System Firmware; Clustered Data ONTAP Antivirus Connector; Config Advisor; Data ONTAP PowerShell Toolkit; E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); NetApp Host Agent; NetApp Manageability SDK; NetApp Plug-in for Symantec NetBackup; OnCommand API Services; OnCommand Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Plug-in for Microsoft; OnCommand Report; OnCommand Shift; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; Open Systems SnapVault Agent; Perfstat; RBAC User Creator for Data ONTAP; Remote Support Diagnostics Tool; SnapCenter; SnapDrive for Windows; SnapProtect; Storage Services Connector; System Setup.

Open source
Advisory

CVE-2015-7547 GNU C Library (glibc) Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160217-0002/

NetApp published this final advisory covering CVE-2015-7547; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Storage Manager; NetApp Cloud Backup (formerly AltaVault); NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; SnapProtect; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

January 2016 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160201-0001/

NetApp published this final advisory covering CVE-2016-0701, CVE-2015-3197; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp Host Agent; NetApp Manageability SDK; NetApp SMI-S Provider; OnCommand Balance; OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapDrive for Unix; SnapDrive for Windows; SnapProtect.

Open source
Advisory

January 2016 OpenSSH Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160126-0001/

NetApp published this final advisory covering CVE-2016-0777, CVE-2016-0778; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Data ONTAP Edge; Data ONTAP operating in 7-Mode; ONTAP 9; OnCommand Balance; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

January 2016 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160121-0002/

NetApp published this final advisory covering CVE-2016-0546, CVE-2016-0504, CVE-2016-0505, CVE-2016-0594, CVE-2016-0595, CVE-2016-0503, CVE-2016-0596, CVE-2016-0502, CVE-2016-0597, CVE-2016-0611, CVE-2016-0616, CVE-2016-0598, CVE-2016-0600, CVE-2016-0610, CVE-2016-0599, CVE-2016-0601, CVE-2016-0606, CVE-2016-0608, CVE-2016-0607, CVE-2015-7744, CVE-2016-0605, CVE-2016-0609; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation.

Open source
Advisory

January 2016 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160121-0001/

NetApp published this final advisory covering CVE-2016-0494, CVE-2015-8126, CVE-2016-0483, CVE-2016-0475, CVE-2016-0402, CVE-2016-0466, CVE-2016-0448, CVE-2015-7575; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

December 2015 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20151207-0001/

NetApp published this final advisory covering CVE-2015-3193, CVE-2015-3194, CVE-2015-3195, CVE-2015-3196, CVE-2015-1794; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; FlashRay; NetApp Cloud Backup (formerly AltaVault); NetApp Host Agent; NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp Storage Encryption; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect.

Open source
Advisory

Apache Commons Collection Java Deserialization Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20151123-0001/

NetApp published this interim advisory covering CVE-2015-8545, CVE-2015-4852; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; FlashRay; MetroCluster Tiebreaker for clustered Data ONTAP; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); Snap Creator Framework; SnapManager for Oracle; SnapManager for SAP; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2015-5600 OpenSSH MaxAuthTries Bypass Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20151106-0001/

NetApp published this final advisory covering CVE-2015-5600; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; FlashRay; NetApp VTL; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

October 2015 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20151030-0001/

NetApp published this final advisory covering CVE-2015-4819, CVE-2015-1793, CVE-2015-4879, CVE-2015-4815, CVE-2015-4905, CVE-2015-4858, CVE-2015-4862, CVE-2015-4866, CVE-2015-4816, CVE-2015-4800, CVE-2015-4870, CVE-2015-4802, CVE-2015-4833, CVE-2015-4830, CVE-2015-4730, CVE-2015-4826, CVE-2015-4904, CVE-2015-4913, CVE-2015-4895, CVE-2015-4861, CVE-2015-4807, CVE-2015-4890, CVE-2015-4791, CVE-2015-4864, CVE-2015-4836, CVE-2015-4910, CVE-2015-4766, CVE-2015-4792; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation.

Open source
Advisory

October 2015 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20151028-0001/

NetApp published this final advisory covering CVE-2015-4835, CVE-2015-4881, CVE-2015-4843, CVE-2015-4883, CVE-2015-4860, CVE-2015-4805, CVE-2015-4844, CVE-2015-4901, CVE-2015-4868, CVE-2015-4810, CVE-2015-4806, CVE-2015-4871, CVE-2015-4902, CVE-2015-4840, CVE-2015-4882, CVE-2015-4842, CVE-2015-4734, CVE-2015-4903, CVE-2015-4803, CVE-2015-4893, CVE-2015-4911, CVE-2015-4872, CVE-2015-4906, CVE-2015-4916, CVE-2015-4908; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Cloud Manager; E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; MetroCluster Plug-in for vSphere; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Shift; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapCenter; SnapManager for Oracle; SnapManager for SAP; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

July 2015 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150716-0001/

NetApp published this final advisory covering CVE-2015-2617, CVE-2015-2648, CVE-2015-2611, CVE-2015-2582, CVE-2015-4752, CVE-2015-4756, CVE-2015-2643, CVE-2015-4772, CVE-2015-4761, CVE-2015-4757, CVE-2015-4737, CVE-2015-4771, CVE-2015-4769, CVE-2015-2639, CVE-2015-2620, CVE-2015-2641, CVE-2015-2661, CVE-2015-4767; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation.

Open source
Advisory

July 2015 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150715-0001/

NetApp published this final advisory covering CVE-2015-4760, CVE-2015-2628, CVE-2015-4731, CVE-2015-2590, CVE-2015-4732, CVE-2015-4733, CVE-2015-2638, CVE-2015-4736, CVE-2015-4748, CVE-2015-2597, CVE-2015-2664, CVE-2015-2632, CVE-2015-2601, CVE-2015-2613, CVE-2015-2621, CVE-2015-2659, CVE-2015-2619, CVE-2015-2637, CVE-2015-2596, CVE-2015-4749, CVE-2015-4729, CVE-2015-4000, CVE-2015-2808, CVE-2015-2627, CVE-2015-2625; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Cloud Manager; E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; MetroCluster Plug-in for vSphere; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Shift; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; RapidData Migration Solution; SnapManager for Oracle; SnapManager for SAP; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2015-1793 OpenSSL Vulnerability does not impact NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150709-0001/

NetApp published this final advisory covering CVE-2015-1793; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2015-4000 Diffie-Hellman Export Cipher Suite vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150619-0001/

NetApp published this final advisory covering CVE-2015-4000; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for Microsoft Windows; Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; FlashRay; NetApp Cloud Backup (formerly AltaVault); NetApp Host Agent; NetApp Manageability SDK; NetApp SMI-S Provider; ONTAP Tools for VMware vSphere; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; Snap Creator Framework; SnapDrive for Windows; SnapManager for SAP; SnapProtect; Storage Replication Adapter for Data ONTAP operating in 7-Mode 2.1; System Manager 9.x; System Setup; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

June 2015 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150616-0001/

NetApp published this final advisory covering CVE-2015-4000, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1792, CVE-2015-1791, CVE-2014-8176; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; FlashRay; NetApp Cloud Backup (formerly AltaVault); NetApp Host Agent; NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; OnCommand Balance; OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; Remote Support Diagnostics Tool; Service Processor; SnapDrive for Windows; SnapProtect.

Open source
Advisory

CVE-2015-2575 MySQL Connector/J Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150417-0003/

NetApp published this final advisory covering CVE-2015-2575; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation.

Open source
Advisory

April 2015 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150417-0002/

NetApp published this final advisory covering CVE-2014-3569, CVE-2015-0405, CVE-2015-0423, CVE-2015-0433, CVE-2015-0438, CVE-2015-0439, CVE-2015-0441, CVE-2015-0498, CVE-2015-0499, CVE-2015-0500, CVE-2015-0501, CVE-2015-0503, CVE-2015-0505, CVE-2015-0506, CVE-2015-0507, CVE-2015-0508, CVE-2015-0511, CVE-2015-2566, CVE-2015-2567, CVE-2015-2568, CVE-2015-2571, CVE-2015-2573; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

April 2015 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150417-0001/

NetApp published this final advisory covering CVE-2015-0469, CVE-2015-0459, CVE-2015-0491, CVE-2015-0460, CVE-2015-0492, CVE-2015-0458, CVE-2015-0484, CVE-2015-0480, CVE-2015-0486, CVE-2015-0488, CVE-2015-0477, CVE-2015-0470, CVE-2015-0478, CVE-2015-0204; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Cloud Manager; MetroCluster Plug-in for vSphere; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; NetApp VASA Provider for Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

March 2015 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150323-0002/

NetApp published this final advisory covering CVE-2015-0291, CVE-2015-0290, CVE-2015-0207, CVE-2015-0286, CVE-2015-0208, CVE-2015-0287, CVE-2015-0289, CVE-2015-0292, CVE-2015-0293, CVE-2015-1787, CVE-2015-0285, CVE-2015-0209, CVE-2015-0288; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; FlashRay; NetApp Host Agent; NetApp Manageability SDK; NetApp Storage Encryption; NetApp VTL; OnCommand Balance; OnCommand Report; OnCommand Unified Manager Host Package; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; Open Systems SnapVault Agent; SnapDrive for Unix; SnapDrive for Windows; SnapProtect.

Open source
Advisory

Potential SMB services disruption after installation of Microsoft patch KB3002657-v1 on Windows 2003 Domain Controllers

Source: https://security.netapp.com/advisory/NTAP-20150313-0001/

NetApp published this final advisory covering CVE-2015-0005; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2015 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150304-0001/

NetApp published this final advisory covering CVE-2014-6568, CVE-2015-0374, CVE-2015-0381, CVE-2015-0382, CVE-2015-0385, CVE-2015-0391, CVE-2015-0409, CVE-2015-0411, CVE-2015-0432; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

January 2015 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150205-0001/

NetApp published this final advisory covering CVE-2014-3571, CVE-2015-0206, CVE-2015-0205, CVE-2014-3570, CVE-2015-0204, CVE-2014-3572, CVE-2014-8275, CVE-2014-3569; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; NetApp Host Agent; NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp VTL; OnCommand Balance; OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2015-0235 GNU C Library (glibc) Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150127-0001/

NetApp published this final advisory covering CVE-2015-0235; the API labels exploitation information as **Public**. The API currently lists affected products as: FlashRay; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VTL; OnCommand Balance; RapidData Migration Solution; SnapDrive for Unix; SnapProtect; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

January 2015 Java Runtime Environment (JRE) Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150126-0001/

NetApp published this final advisory covering CVE-2014-3566, CVE-2014-6549, CVE-2014-6585, CVE-2014-6587, CVE-2014-6591, CVE-2014-6593, CVE-2014-6601, CVE-2015-0383, CVE-2015-0395, CVE-2015-0400, CVE-2015-0403, CVE-2015-0406, CVE-2015-0407, CVE-2015-0408, CVE-2015-0410, CVE-2015-0412, CVE-2015-0413, CVE-2015-0421, CVE-2015-0437; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Cloud Manager; E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; MetroCluster Plug-in for vSphere; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; NetApp VASA Provider for Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

RC4 Cipher Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150122-0001/

NetApp published this final advisory covering CVE-2013-2566, CVE-2015-2808; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager Core Package; OnCommand Unified Manager for Clustered Data ONTAP; Service Processor; SnapCenter.

Open source
Advisory

July 2014 Oracle MySQL vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141125-0001/

NetApp published this final advisory covering CVE-2014-2484, CVE-2014-2494, CVE-2014-4207, CVE-2014-4214, CVE-2014-4233, CVE-2014-4238, CVE-2014-4240, CVE-2014-4243, CVE-2014-4258, CVE-2014-4260; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Insight; OnCommand Report; OnCommand Workflow Automation.

Open source
Advisory

October 2014 Oracle MySQL vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141119-0001/

NetApp published this final advisory covering CVE-2014-6507, CVE-2014-6491, CVE-2014-6500, CVE-2014-6469, CVE-2014-0224, CVE-2014-6530, CVE-2014-6555, CVE-2014-6489, CVE-2012-5615, CVE-2014-6559, CVE-2014-6494, CVE-2014-6496, CVE-2014-6495, CVE-2014-6478, CVE-2014-4274, CVE-2014-4287, CVE-2014-6520, CVE-2014-6484, CVE-2014-6464, CVE-2014-6564, CVE-2014-6505, CVE-2014-6474, CVE-2014-6463, CVE-2014-6551; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

August 2014 OpenSSL CVE Bundle Security Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141030-0001/

NetApp published this final advisory covering CVE-2014-3505, CVE-2014-3506, CVE-2014-3507, CVE-2014-3508, CVE-2014-3509, CVE-2014-3510, CVE-2014-3511, CVE-2014-3512, CVE-2014-5139; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Config Advisor; FlashRay; NetApp Host Agent; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp VTL; OnCommand Balance; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapDrive for Unix; SnapDrive for Windows; SnapProtect.

Open source
Advisory

July 2014 Java Runtime Environment (JRE) vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141028-0001/

NetApp published this final advisory covering CVE-2013-1620, CVE-2013-1741, CVE-2013-5855, CVE-2014-2479, CVE-2014-2480, CVE-2014-2481, CVE-2014-2493, CVE-2014-4201, CVE-2014-4202, CVE-2014-4210, CVE-2014-4211, CVE-2014-4212, CVE-2014-4217, CVE-2014-4222, CVE-2014-4241, CVE-2014-4242, CVE-2014-4249, CVE-2014-4251, CVE-2014-4253, CVE-2014-4254, CVE-2014-4255, CVE-2014-4256, CVE-2014-4257, CVE-2014-4267; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; MetroCluster Plug-in for vSphere; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; NetApp VASA Provider for Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Insight; OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

GNUTLS Buffer Overflow vulnerabilities in Select NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141028-0002/

NetApp published this final advisory covering CVE-2014-3466; the API labels exploitation information as **Public**. The API currently lists affected products as: FlashRay; OnCommand Balance; Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

October 2014 Java Runtime Environment (JRE) Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141023-0001/

NetApp published this final advisory covering CVE-2014-6513, CVE-2014-6532, CVE-2014-6503, CVE-2014-6456, CVE-2014-6562, CVE-2014-6485, CVE-2014-6492, CVE-2014-6493, CVE-2014-4288, CVE-2014-6466, CVE-2014-6458, CVE-2014-6468, CVE-2014-6506, CVE-2014-6511, CVE-2014-6476, CVE-2014-6515, CVE-2014-6504, CVE-2014-6519, CVE-2014-6517, CVE-2014-6531, CVE-2014-6512, CVE-2014-6457, CVE-2014-6527, CVE-2014-6502, CVE-2014-6558; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Cloud Manager; MetroCluster Plug-in for vSphere; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; NetApp VASA Provider for Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Insight; OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

October 2014 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141015-0002/

NetApp published this final advisory covering CVE-2014-3513, CVE-2014-3567, CVE-2014-3568; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Data Center Fabric Manager Professional Software; Brocade Fabric Operating System Firmware; Brocade Network Advisor Software; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; NetApp Host Agent; NetApp SMI-S Provider; NetApp VTL; OnCommand Balance; OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; RapidData Migration Solution; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2014-3566 SSL v3.0 Nondeterministic CBC Padding Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141015-0001/

NetApp published this final advisory covering CVE-2014-3566; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Brocade Data Center Fabric Manager Professional Software; Brocade Fabric Operating System Firmware; Brocade Network Advisor Software; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP PowerShell Toolkit; Data ONTAP operating in 7-Mode; FlashRay; NetApp Host Agent; NetApp Manageability SDK; NetApp Plug-in for Symantec NetBackup; NetApp Recovery Manager for Citrix Sharefile; NetApp SMI-S Provider; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; NetApp VASA Provider for Data ONTAP operating in 7-Mode; NetApp VTL; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Plug-in for Microsoft; OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; Open Systems SnapVault Agent; RapidData Migration Solution; Service Processor; Snap Creator Framework; SnapDrive for Unix; SnapDrive for Windows; SnapManager for Oracle; SnapManager for SAP; SnapManager for Sharepoint; SnapProtect; Storage Replication Adapter for Data ONTAP operating in 7-Mode 2.1; System Manager 9.x; Virtual Storage Console for Citrix XenServer; Virtual Storage Console for Red Hat Enterprise Virtualization; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

Bash Code Injection Vulnerability in Select NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20140924-0001/

NetApp published this final advisory covering CVE-2014-6271, CVE-2014-7169, CVE-2014-6277, CVE-2014-6278, CVE-2014-7186, CVE-2014-7187; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP Edge; Data ONTAP operating in 7-Mode; FlashRay; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; RapidData Migration Solution; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

OpenSSL SSL_MODE_RELEASE_BUFFERS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20140609-0003/

NetApp published this final advisory covering CVE-2014-0198, CVE-2010-5298; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2014 OpenSSL TLS Handshake Vulnerability in Select NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20140609-0001/

NetApp published this final advisory covering CVE-2014-0224; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2014 OpenSSL Elliptic Curve Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20140609-0004/

NetApp published this final advisory covering CVE-2014-3470, CVE-2014-0076; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Config Advisor; Data ONTAP operating in 7-Mode; NetApp Host Agent; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp VTL; OnCommand Balance; OnCommand Unified Manager Host Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapDrive for Unix; SnapDrive for Windows; SnapProtect.

Open source
Advisory

June 2014 OpenSSL DTLS Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20140609-0002/

NetApp published this final advisory covering CVE-2014-0195, CVE-2014-0221; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

OpenSSL Heartbeat Extension Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20140410-0001/

NetApp published this final advisory covering CVE-2014-0160; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP Antivirus Connector; FlashRay; NetApp Cloud Backup; NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; SnapProtect.

Open source