Content Library · Advisory

Advisory 2014

Browse 19 2014 NetApp advisory records in the NetApp Black Box content library.

Library JSON API

Advisory

July 2014 Oracle MySQL vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141125-0001/

NetApp published this final advisory covering CVE-2014-2484, CVE-2014-2494, CVE-2014-4207, CVE-2014-4214, CVE-2014-4233, CVE-2014-4238, CVE-2014-4240, CVE-2014-4243, CVE-2014-4258, CVE-2014-4260; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Insight; OnCommand Report; OnCommand Workflow Automation.

Open source
Advisory

October 2014 Oracle MySQL vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141119-0001/

NetApp published this final advisory covering CVE-2014-6507, CVE-2014-6491, CVE-2014-6500, CVE-2014-6469, CVE-2014-0224, CVE-2014-6530, CVE-2014-6555, CVE-2014-6489, CVE-2012-5615, CVE-2014-6559, CVE-2014-6494, CVE-2014-6496, CVE-2014-6495, CVE-2014-6478, CVE-2014-4274, CVE-2014-4287, CVE-2014-6520, CVE-2014-6484, CVE-2014-6464, CVE-2014-6564, CVE-2014-6505, CVE-2014-6474, CVE-2014-6463, CVE-2014-6551; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

August 2014 OpenSSL CVE Bundle Security Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141030-0001/

NetApp published this final advisory covering CVE-2014-3505, CVE-2014-3506, CVE-2014-3507, CVE-2014-3508, CVE-2014-3509, CVE-2014-3510, CVE-2014-3511, CVE-2014-3512, CVE-2014-5139; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Config Advisor; FlashRay; NetApp Host Agent; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp VTL; OnCommand Balance; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapDrive for Unix; SnapDrive for Windows; SnapProtect.

Open source
Advisory

July 2014 Java Runtime Environment (JRE) vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141028-0001/

NetApp published this final advisory covering CVE-2013-1620, CVE-2013-1741, CVE-2013-5855, CVE-2014-2479, CVE-2014-2480, CVE-2014-2481, CVE-2014-2493, CVE-2014-4201, CVE-2014-4202, CVE-2014-4210, CVE-2014-4211, CVE-2014-4212, CVE-2014-4217, CVE-2014-4222, CVE-2014-4241, CVE-2014-4242, CVE-2014-4249, CVE-2014-4251, CVE-2014-4253, CVE-2014-4254, CVE-2014-4255, CVE-2014-4256, CVE-2014-4257, CVE-2014-4267; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; MetroCluster Plug-in for vSphere; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; NetApp VASA Provider for Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Insight; OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

GNUTLS Buffer Overflow vulnerabilities in Select NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141028-0002/

NetApp published this final advisory covering CVE-2014-3466; the API labels exploitation information as **Public**. The API currently lists affected products as: FlashRay; OnCommand Balance; Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

October 2014 Java Runtime Environment (JRE) Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141023-0001/

NetApp published this final advisory covering CVE-2014-6513, CVE-2014-6532, CVE-2014-6503, CVE-2014-6456, CVE-2014-6562, CVE-2014-6485, CVE-2014-6492, CVE-2014-6493, CVE-2014-4288, CVE-2014-6466, CVE-2014-6458, CVE-2014-6468, CVE-2014-6506, CVE-2014-6511, CVE-2014-6476, CVE-2014-6515, CVE-2014-6504, CVE-2014-6519, CVE-2014-6517, CVE-2014-6531, CVE-2014-6512, CVE-2014-6457, CVE-2014-6527, CVE-2014-6502, CVE-2014-6558; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Cloud Manager; MetroCluster Plug-in for vSphere; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; NetApp VASA Provider for Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Insight; OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

October 2014 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141015-0002/

NetApp published this final advisory covering CVE-2014-3513, CVE-2014-3567, CVE-2014-3568; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Data Center Fabric Manager Professional Software; Brocade Fabric Operating System Firmware; Brocade Network Advisor Software; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; NetApp Host Agent; NetApp SMI-S Provider; NetApp VTL; OnCommand Balance; OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; RapidData Migration Solution; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2014-3566 SSL v3.0 Nondeterministic CBC Padding Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20141015-0001/

NetApp published this final advisory covering CVE-2014-3566; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Brocade Data Center Fabric Manager Professional Software; Brocade Fabric Operating System Firmware; Brocade Network Advisor Software; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP PowerShell Toolkit; Data ONTAP operating in 7-Mode; FlashRay; NetApp Host Agent; NetApp Manageability SDK; NetApp Plug-in for Symantec NetBackup; NetApp Recovery Manager for Citrix Sharefile; NetApp SMI-S Provider; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; NetApp VASA Provider for Data ONTAP operating in 7-Mode; NetApp VTL; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Plug-in for Microsoft; OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; Open Systems SnapVault Agent; RapidData Migration Solution; Service Processor; Snap Creator Framework; SnapDrive for Unix; SnapDrive for Windows; SnapManager for Oracle; SnapManager for SAP; SnapManager for Sharepoint; SnapProtect; Storage Replication Adapter for Data ONTAP operating in 7-Mode 2.1; System Manager 9.x; Virtual Storage Console for Citrix XenServer; Virtual Storage Console for Red Hat Enterprise Virtualization; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

Bash Code Injection Vulnerability in Select NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20140924-0001/

NetApp published this final advisory covering CVE-2014-6271, CVE-2014-7169, CVE-2014-6277, CVE-2014-6278, CVE-2014-7186, CVE-2014-7187; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP Edge; Data ONTAP operating in 7-Mode; FlashRay; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; RapidData Migration Solution; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

OpenSSL SSL_MODE_RELEASE_BUFFERS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20140609-0003/

NetApp published this final advisory covering CVE-2014-0198, CVE-2010-5298; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2014 OpenSSL TLS Handshake Vulnerability in Select NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20140609-0001/

NetApp published this final advisory covering CVE-2014-0224; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2014 OpenSSL Elliptic Curve Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20140609-0004/

NetApp published this final advisory covering CVE-2014-3470, CVE-2014-0076; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Config Advisor; Data ONTAP operating in 7-Mode; NetApp Host Agent; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp VTL; OnCommand Balance; OnCommand Unified Manager Host Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapDrive for Unix; SnapDrive for Windows; SnapProtect.

Open source
Advisory

June 2014 OpenSSL DTLS Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20140609-0002/

NetApp published this final advisory covering CVE-2014-0195, CVE-2014-0221; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

OpenSSL Heartbeat Extension Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20140410-0001/

NetApp published this final advisory covering CVE-2014-0160; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP Antivirus Connector; FlashRay; NetApp Cloud Backup; NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; SnapProtect.

Open source