Content Library · Advisory

Advisory 2015

Browse 32 2015 NetApp advisory records in the NetApp Black Box content library.

Library JSON API

Advisory

December 2015 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20151207-0001/

NetApp published this final advisory covering CVE-2015-3193, CVE-2015-3194, CVE-2015-3195, CVE-2015-3196, CVE-2015-1794; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; FlashRay; NetApp Cloud Backup (formerly AltaVault); NetApp Host Agent; NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp Storage Encryption; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect.

Open source
Advisory

Apache Commons Collection Java Deserialization Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20151123-0001/

NetApp published this interim advisory covering CVE-2015-8545, CVE-2015-4852; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; FlashRay; MetroCluster Tiebreaker for clustered Data ONTAP; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); Snap Creator Framework; SnapManager for Oracle; SnapManager for SAP; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2015-5600 OpenSSH MaxAuthTries Bypass Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20151106-0001/

NetApp published this final advisory covering CVE-2015-5600; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; FlashRay; NetApp VTL; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

October 2015 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20151030-0001/

NetApp published this final advisory covering CVE-2015-4819, CVE-2015-1793, CVE-2015-4879, CVE-2015-4815, CVE-2015-4905, CVE-2015-4858, CVE-2015-4862, CVE-2015-4866, CVE-2015-4816, CVE-2015-4800, CVE-2015-4870, CVE-2015-4802, CVE-2015-4833, CVE-2015-4830, CVE-2015-4730, CVE-2015-4826, CVE-2015-4904, CVE-2015-4913, CVE-2015-4895, CVE-2015-4861, CVE-2015-4807, CVE-2015-4890, CVE-2015-4791, CVE-2015-4864, CVE-2015-4836, CVE-2015-4910, CVE-2015-4766, CVE-2015-4792; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation.

Open source
Advisory

October 2015 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20151028-0001/

NetApp published this final advisory covering CVE-2015-4835, CVE-2015-4881, CVE-2015-4843, CVE-2015-4883, CVE-2015-4860, CVE-2015-4805, CVE-2015-4844, CVE-2015-4901, CVE-2015-4868, CVE-2015-4810, CVE-2015-4806, CVE-2015-4871, CVE-2015-4902, CVE-2015-4840, CVE-2015-4882, CVE-2015-4842, CVE-2015-4734, CVE-2015-4903, CVE-2015-4803, CVE-2015-4893, CVE-2015-4911, CVE-2015-4872, CVE-2015-4906, CVE-2015-4916, CVE-2015-4908; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Cloud Manager; E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; MetroCluster Plug-in for vSphere; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Shift; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapCenter; SnapManager for Oracle; SnapManager for SAP; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

July 2015 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150716-0001/

NetApp published this final advisory covering CVE-2015-2617, CVE-2015-2648, CVE-2015-2611, CVE-2015-2582, CVE-2015-4752, CVE-2015-4756, CVE-2015-2643, CVE-2015-4772, CVE-2015-4761, CVE-2015-4757, CVE-2015-4737, CVE-2015-4771, CVE-2015-4769, CVE-2015-2639, CVE-2015-2620, CVE-2015-2641, CVE-2015-2661, CVE-2015-4767; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation.

Open source
Advisory

July 2015 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150715-0001/

NetApp published this final advisory covering CVE-2015-4760, CVE-2015-2628, CVE-2015-4731, CVE-2015-2590, CVE-2015-4732, CVE-2015-4733, CVE-2015-2638, CVE-2015-4736, CVE-2015-4748, CVE-2015-2597, CVE-2015-2664, CVE-2015-2632, CVE-2015-2601, CVE-2015-2613, CVE-2015-2621, CVE-2015-2659, CVE-2015-2619, CVE-2015-2637, CVE-2015-2596, CVE-2015-4749, CVE-2015-4729, CVE-2015-4000, CVE-2015-2808, CVE-2015-2627, CVE-2015-2625; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Cloud Manager; E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; MetroCluster Plug-in for vSphere; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Shift; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; RapidData Migration Solution; SnapManager for Oracle; SnapManager for SAP; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2015-1793 OpenSSL Vulnerability does not impact NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150709-0001/

NetApp published this final advisory covering CVE-2015-1793; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2015-4000 Diffie-Hellman Export Cipher Suite vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150619-0001/

NetApp published this final advisory covering CVE-2015-4000; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for Microsoft Windows; Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; FlashRay; NetApp Cloud Backup (formerly AltaVault); NetApp Host Agent; NetApp Manageability SDK; NetApp SMI-S Provider; ONTAP Tools for VMware vSphere; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; Snap Creator Framework; SnapDrive for Windows; SnapManager for SAP; SnapProtect; Storage Replication Adapter for Data ONTAP operating in 7-Mode 2.1; System Manager 9.x; System Setup; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

June 2015 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150616-0001/

NetApp published this final advisory covering CVE-2015-4000, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1792, CVE-2015-1791, CVE-2014-8176; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; FlashRay; NetApp Cloud Backup (formerly AltaVault); NetApp Host Agent; NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; OnCommand Balance; OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; Remote Support Diagnostics Tool; Service Processor; SnapDrive for Windows; SnapProtect.

Open source
Advisory

CVE-2015-2575 MySQL Connector/J Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150417-0003/

NetApp published this final advisory covering CVE-2015-2575; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation.

Open source
Advisory

April 2015 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150417-0002/

NetApp published this final advisory covering CVE-2014-3569, CVE-2015-0405, CVE-2015-0423, CVE-2015-0433, CVE-2015-0438, CVE-2015-0439, CVE-2015-0441, CVE-2015-0498, CVE-2015-0499, CVE-2015-0500, CVE-2015-0501, CVE-2015-0503, CVE-2015-0505, CVE-2015-0506, CVE-2015-0507, CVE-2015-0508, CVE-2015-0511, CVE-2015-2566, CVE-2015-2567, CVE-2015-2568, CVE-2015-2571, CVE-2015-2573; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

April 2015 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150417-0001/

NetApp published this final advisory covering CVE-2015-0469, CVE-2015-0459, CVE-2015-0491, CVE-2015-0460, CVE-2015-0492, CVE-2015-0458, CVE-2015-0484, CVE-2015-0480, CVE-2015-0486, CVE-2015-0488, CVE-2015-0477, CVE-2015-0470, CVE-2015-0478, CVE-2015-0204; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Cloud Manager; MetroCluster Plug-in for vSphere; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; NetApp VASA Provider for Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

March 2015 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150323-0002/

NetApp published this final advisory covering CVE-2015-0291, CVE-2015-0290, CVE-2015-0207, CVE-2015-0286, CVE-2015-0208, CVE-2015-0287, CVE-2015-0289, CVE-2015-0292, CVE-2015-0293, CVE-2015-1787, CVE-2015-0285, CVE-2015-0209, CVE-2015-0288; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; FlashRay; NetApp Host Agent; NetApp Manageability SDK; NetApp Storage Encryption; NetApp VTL; OnCommand Balance; OnCommand Report; OnCommand Unified Manager Host Package; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; Open Systems SnapVault Agent; SnapDrive for Unix; SnapDrive for Windows; SnapProtect.

Open source
Advisory

Potential SMB services disruption after installation of Microsoft patch KB3002657-v1 on Windows 2003 Domain Controllers

Source: https://security.netapp.com/advisory/NTAP-20150313-0001/

NetApp published this final advisory covering CVE-2015-0005; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2015 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150304-0001/

NetApp published this final advisory covering CVE-2014-6568, CVE-2015-0374, CVE-2015-0381, CVE-2015-0382, CVE-2015-0385, CVE-2015-0391, CVE-2015-0409, CVE-2015-0411, CVE-2015-0432; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

January 2015 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150205-0001/

NetApp published this final advisory covering CVE-2014-3571, CVE-2015-0206, CVE-2015-0205, CVE-2014-3570, CVE-2015-0204, CVE-2014-3572, CVE-2014-8275, CVE-2014-3569; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; NetApp Host Agent; NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp VTL; OnCommand Balance; OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2015-0235 GNU C Library (glibc) Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150127-0001/

NetApp published this final advisory covering CVE-2015-0235; the API labels exploitation information as **Public**. The API currently lists affected products as: FlashRay; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VTL; OnCommand Balance; RapidData Migration Solution; SnapDrive for Unix; SnapProtect; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

January 2015 Java Runtime Environment (JRE) Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150126-0001/

NetApp published this final advisory covering CVE-2014-3566, CVE-2014-6549, CVE-2014-6585, CVE-2014-6587, CVE-2014-6591, CVE-2014-6593, CVE-2014-6601, CVE-2015-0383, CVE-2015-0395, CVE-2015-0400, CVE-2015-0403, CVE-2015-0406, CVE-2015-0407, CVE-2015-0408, CVE-2015-0410, CVE-2015-0412, CVE-2015-0413, CVE-2015-0421, CVE-2015-0437; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Cloud Manager; E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; MetroCluster Plug-in for vSphere; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; NetApp VASA Provider for Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Unified Manager Host Package; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

RC4 Cipher Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20150122-0001/

NetApp published this final advisory covering CVE-2013-2566, CVE-2015-2808; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager Core Package; OnCommand Unified Manager for Clustered Data ONTAP; Service Processor; SnapCenter.

Open source