Content Library · Advisory

Advisory 2016

Browse 60 2016 NetApp advisory records in the NetApp Black Box content library.

Library JSON API

Advisory

December 2016 Samba Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20161219-0001/

NetApp published this final advisory covering CVE-2016-2123, CVE-2016-2125, CVE-2016-2126; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale); StorageGRID Webscale NAS Bridge; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2016-5195 Kernel Local Privilege Escalation Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20161025-0001/

NetApp published this final advisory covering CVE-2016-5195; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; SnapProtect.

Open source
Advisory

October 2016 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20161019-0002/

NetApp published this final advisory covering CVE-2016-6304, CVE-2016-6662, CVE-2016-5617, CVE-2016-5616, CVE-2016-5625, CVE-2016-5609, CVE-2016-5612, CVE-2016-5624, CVE-2016-5626, CVE-2016-5627, CVE-2016-3492, CVE-2016-7440, CVE-2016-5628, CVE-2016-5629, CVE-2016-3495, CVE-2016-5630, CVE-2016-5507, CVE-2016-5631, CVE-2016-5632, CVE-2016-5633, CVE-2016-5634, CVE-2016-5635, CVE-2016-8289, CVE-2016-8287, CVE-2016-8290, CVE-2016-5584, CVE-2016-8283, CVE-2016-8288, CVE-2016-8286, CVE-2016-8284; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapCenter; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

October 2016 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20161019-0001/

NetApp published this final advisory covering CVE-2016-5556, CVE-2016-5568, CVE-2016-5582, CVE-2016-5573, CVE-2016-5597, CVE-2016-5554, CVE-2016-5542; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Cloud Manager; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; SnapManager for Oracle; SnapManager for SAP; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2010-1871 JBoss Seam Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20161017-0001/

NetApp published this final advisory covering CVE-2010-1871; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Insight; OnCommand Unified Manager for Clustered Data ONTAP.

Open source
Advisory

CVE-2016-2776 ISC BIND Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160930-0001/

NetApp published this final advisory covering CVE-2016-2776; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 7.2 and above.

Open source
Advisory

September 2016 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160928-0001/

NetApp published this final advisory covering CVE-2016-6304, CVE-2016-2183, CVE-2016-6303, CVE-2016-6302, CVE-2016-2182, CVE-2016-2180, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2181, CVE-2016-6306, CVE-2016-6305, CVE-2016-6307, CVE-2016-6308; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP operating in 7-Mode; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Storage Node (Element Software); NetApp Storage Encryption; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID (formerly StorageGRID Webscale); StorageGRID Webscale NAS Bridge; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2016-2183 TLS Protocol 64-bit Cipher Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160915-0001/

NetApp published this final advisory covering CVE-2016-2183; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; AFF Baseboard Management Controller (BMC) - A700s; Brocade Fabric Operating System Firmware; Brocade Network Advisor Software; Data ONTAP operating in 7-Mode; E-Series SANtricity Storage Manager; FAS/AFF Service Processor - 8080/8060/8040/8020; NetApp Cloud Backup (formerly AltaVault); NetApp Console Agent; NetApp Host Agent; NetApp Manageability SDK; NetApp ONTAP PowerShell Toolkit (PSTK); NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; ONTAP 9; ONTAP Select Deploy administration utility; OnCommand Insight; OnCommand Shift; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; Perfstat; RBAC User Creator for Data ONTAP; Snap Creator Framework; SnapCenter; SnapCenter Plug-in for VMware vSphere; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior); System Setup; Virtual Storage Console for VMware vSphere 6.x; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

June 2016 Network Time Protocol Daemon (ntpd) Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160722-0001/

NetApp published this final advisory covering CVE-2016-4953, CVE-2016-4954, CVE-2016-4955, CVE-2016-4956, CVE-2016-4957; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP.

Open source
Advisory

CVE-2016-2775 ISC BIND Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160722-0002/

NetApp published this final advisory covering CVE-2016-2775; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2016 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160721-0002/

NetApp published this final advisory covering CVE-2016-3477, CVE-2016-3440, CVE-2016-2105, CVE-2016-3471, CVE-2016-3486, CVE-2016-3501, CVE-2016-3518, CVE-2016-3521, CVE-2016-3588, CVE-2016-3615, CVE-2016-3614, CVE-2016-5436, CVE-2016-3459, CVE-2016-5437, CVE-2016-3424, CVE-2016-5439, CVE-2016-5440, CVE-2016-5441, CVE-2016-5442, CVE-2016-5443, CVE-2016-5444, CVE-2016-3452; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation.

Open source
Advisory

July 2016 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160721-0001/

NetApp published this final advisory covering CVE-2016-3587, CVE-2016-3606, CVE-2016-3598, CVE-2016-3610, CVE-2016-3552, CVE-2016-3511, CVE-2016-3503, CVE-2016-3498, CVE-2016-3500, CVE-2016-3508, CVE-2016-3458, CVE-2016-3550, CVE-2016-3485; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

CVE-2016-2119 Samba SMB Client Required Signing Downgrade Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20160708-0001/

NetApp published this final advisory covering CVE-2016-2119; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2015-3253 Apache Groovy Vulnerability in OnCommand Insight

Source: https://security.netapp.com/advisory/NTAP-20160623-0001/

NetApp published this final advisory covering CVE-2015-3253; the API labels exploitation information as **Public**. The API currently lists affected products as: MetroCluster Plug-in for vSphere; OnCommand Insight; RapidData Migration Solution.

Open source
Advisory

May 2016 OpenSSH Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160519-0001/

NetApp published this final advisory covering CVE-2016-3115, CVE-2016-1907, CVE-2016-1908; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Unified Manager for Clustered Data ONTAP.

Open source
Advisory

May 2016 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160504-0001/

NetApp published this final advisory covering CVE-2016-2108, CVE-2016-2105, CVE-2016-2107, CVE-2016-2106, CVE-2016-2109, CVE-2016-2176; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp Storage Encryption; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

April 2016 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160421-0001/

NetApp published this final advisory covering CVE-2016-0705, CVE-2016-0639, CVE-2015-3194, CVE-2016-0640, CVE-2016-0641, CVE-2016-2047, CVE-2016-0642, CVE-2016-0643, CVE-2016-0644, CVE-2016-0646, CVE-2016-0647, CVE-2016-0648, CVE-2016-0649, CVE-2016-0650, CVE-2016-0652, CVE-2016-0653, CVE-2016-0654, CVE-2016-0655, CVE-2016-0656, CVE-2016-0657, CVE-2016-0658, CVE-2016-0651, CVE-2016-0659, CVE-2016-0661, CVE-2016-0662, CVE-2016-0663, CVE-2016-0665, CVE-2016-0666, CVE-2016-0667, CVE-2016-0668; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation.

Open source
Advisory

April 2016 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160420-0001/

NetApp published this final advisory covering CVE-2016-3443, CVE-2016-0687, CVE-2016-0686, CVE-2016-3427, CVE-2016-3449, CVE-2016-3422, CVE-2016-3425, CVE-2016-3426, CVE-2016-0695; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

SMB Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160412-0001/

NetApp published this final advisory covering CVE-2016-3400, CVE-2016-3997, CVE-2016-3998, CVE-2016-2118; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

August 2015 OpenSSH Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160330-0001/

NetApp published this final advisory covering CVE-2015-6564, CVE-2015-6565; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; FlashRay; NetApp VTL; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP.

Open source
Advisory

March 2016 ISC BIND Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160322-0002/

NetApp published this final advisory covering CVE-2016-1285, CVE-2016-1286, CVE-2016-2088; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above.

Open source
Advisory

January 2016 ISC BIND Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160322-0001/

NetApp published this final advisory covering CVE-2015-8704, CVE-2015-8705; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above.

Open source
Advisory

CVE-2016-2842 OpenSSL Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160321-0001/

NetApp published this final advisory covering CVE-2016-2842; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp Host Agent; NetApp SMI-S Provider; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; Open Systems SnapVault Agent; SnapCenter; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

March 2016 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160303-0001/

NetApp published this final advisory covering CVE-2016-0703, CVE-2016-0704, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-0702, CVE-2016-0705; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp Host Agent; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp Storage Encryption; OnCommand Balance; OnCommand Report; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2016-0800 SSLv2 Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160301-0001/

NetApp published this final advisory covering CVE-2016-0800; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP operating in 7-Mode; MetroCluster Tiebreaker for clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); NetApp Host Agent; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Report; OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; Open Systems SnapVault Agent; Perfstat; RBAC User Creator for Data ONTAP; Snap Creator Framework; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 7.2 and above; Storage Replication Adapter for Data ONTAP operating in 7-Mode 2.1.

Open source
Advisory

CVE-2015-7575 TLS Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160225-0001/

NetApp published this final advisory covering CVE-2015-7575; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Brocade Fabric Operating System Firmware; Clustered Data ONTAP Antivirus Connector; Config Advisor; Data ONTAP PowerShell Toolkit; E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); NetApp Host Agent; NetApp Manageability SDK; NetApp Plug-in for Symantec NetBackup; OnCommand API Services; OnCommand Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Plug-in for Microsoft; OnCommand Report; OnCommand Shift; OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; Open Systems SnapVault Agent; Perfstat; RBAC User Creator for Data ONTAP; Remote Support Diagnostics Tool; SnapCenter; SnapDrive for Windows; SnapProtect; Storage Services Connector; System Setup.

Open source
Advisory

CVE-2015-7547 GNU C Library (glibc) Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160217-0002/

NetApp published this final advisory covering CVE-2015-7547; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Storage Manager; NetApp Cloud Backup (formerly AltaVault); NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; SnapProtect; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

January 2016 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160201-0001/

NetApp published this final advisory covering CVE-2016-0701, CVE-2015-3197; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp Host Agent; NetApp Manageability SDK; NetApp SMI-S Provider; OnCommand Balance; OnCommand Report; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; Service Processor; SnapDrive for Unix; SnapDrive for Windows; SnapProtect.

Open source
Advisory

January 2016 OpenSSH Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160126-0001/

NetApp published this final advisory covering CVE-2016-0777, CVE-2016-0778; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Data ONTAP Edge; Data ONTAP operating in 7-Mode; ONTAP 9; OnCommand Balance; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

January 2016 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160121-0002/

NetApp published this final advisory covering CVE-2016-0546, CVE-2016-0504, CVE-2016-0505, CVE-2016-0594, CVE-2016-0595, CVE-2016-0503, CVE-2016-0596, CVE-2016-0502, CVE-2016-0597, CVE-2016-0611, CVE-2016-0616, CVE-2016-0598, CVE-2016-0600, CVE-2016-0610, CVE-2016-0599, CVE-2016-0601, CVE-2016-0606, CVE-2016-0608, CVE-2016-0607, CVE-2015-7744, CVE-2016-0605, CVE-2016-0609; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation.

Open source
Advisory

January 2016 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20160121-0001/

NetApp published this final advisory covering CVE-2016-0494, CVE-2015-8126, CVE-2016-0483, CVE-2016-0475, CVE-2016-0402, CVE-2016-0466, CVE-2016-0448, CVE-2015-7575; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Report; OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Virtual Storage Console for VMware vSphere 7.2 and above.

Open source