NetApp published this final advisory covering CVE-2017-13098; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2017-14583; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2017-7525; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Performance Manager for Linux; OnCommand Performance Manager for VMware vSphere; OnCommand Shift; SnapCenter.
NetApp published this final advisory covering CVE-2017-15707; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance.
NetApp published this final advisory covering CVE-2017-15095; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Performance Manager for Linux; OnCommand Performance Manager for VMware vSphere; OnCommand Shift; SnapCenter.
NetApp published this final advisory covering CVE-2017-3737, CVE-2017-3738; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Storage Node (Element Software); NetApp Storage Encryption; NetApp VASA Provider for Clustered Data ONTAP 6.x; OnCommand Balance; OnCommand Performance Manager for VMware vSphere; OnCommand Unified Manager Core Package; OnCommand Unified Manager for VMware vSphere for 7.1 and below; OnCommand Workflow Automation; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID9 (9.x and prior).
NetApp published this final advisory covering CVE-2016-6904; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 9.7 and above.
NetApp published this final advisory covering CVE-2016-10012, CVE-2016-10011, CVE-2016-10010, CVE-2016-10009; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP operating in 7-Mode; Management Network Switch (NetApp CN1601); NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager for 7-Mode (core package).
NetApp published this final advisory covering CVE-2016-8610; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; E-Series SANtricity OS Controller Software 11.x; NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp VASA Provider for Clustered Data ONTAP 6.x; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; Service Processor; SnapCenter; SnapDrive for Unix; SnapProtect; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).
NetApp published this final advisory covering CVE-2016-6515: OpenSSH vulnerability; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager for Clustered Data ONTAP; Service Processor; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).
NetApp published this final advisory covering CVE-2017-5705, CVE-2017-5708, CVE-2017-5711, CVE-2017-5712, CVE-2017-5706, CVE-2017-5709, CVE-2017-5707, CVE-2017-5710; the API labels exploitation information as **Not public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2017-15517; the API labels exploitation information as **Not public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).
NetApp published this final advisory covering CVE-2017-15516; the API labels exploitation information as **Not public**. The API currently lists affected products as: SnapCenter.
NetApp published this final advisory covering CVE-2017-3736; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; E-Series SANtricity OS Controller Software 11.x; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp Storage Encryption; NetApp VASA Provider for Clustered Data ONTAP 6.x; OnCommand Balance; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID9 (9.x and prior).
NetApp published this final advisory covering CVE-2017-11461; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager for 7-Mode (core package).
NetApp published this final advisory covering CVE-2015-7979, CVE-2015-7973, CVE-2015-7974, CVE-2015-8158, CVE-2015-8138, CVE-2015-7978, CVE-2015-7977, CVE-2015-7976, CVE-2015-7975; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; OnCommand Balance.
NetApp published this final advisory covering CVE-2017-15361; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2017-10155, CVE-2017-10165, CVE-2017-10167, CVE-2017-10203, CVE-2017-10227, CVE-2017-10268, CVE-2017-10276, CVE-2017-10277, CVE-2017-10279, CVE-2017-10283, CVE-2017-10284, CVE-2017-10286, CVE-2017-10294, CVE-2017-10296, CVE-2017-10311, CVE-2017-10313, CVE-2017-10314, CVE-2017-10320, CVE-2017-10365, CVE-2017-10378, CVE-2017-10379, CVE-2017-10384, CVE-2017-10424, CVE-2017-3731, CVE-2017-5664; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager for VMware vSphere; OnCommand Unified Manager for VMware vSphere for 7.1 and below; OnCommand Unified Manager for Windows for 7.1 and below; OnCommand Workflow Automation; SnapCenter.
NetApp published this final advisory covering CVE-2017-10346, CVE-2017-10285, CVE-2017-10388, CVE-2017-10309, CVE-2017-10274, CVE-2017-10356, CVE-2017-10293, CVE-2017-10342, CVE-2017-10350, CVE-2017-10349, CVE-2017-10348, CVE-2017-10357, CVE-2016-9841, CVE-2016-10165, CVE-2017-10355, CVE-2017-10281, CVE-2017-10347, CVE-2017-10386, CVE-2017-10380, CVE-2017-10295, CVE-2017-10341, CVE-2017-10345; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager for VMware vSphere; OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for VMware vSphere for 7.1 and below; OnCommand Unified Manager for Windows for 7.1 and below; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 7.2 and above; Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above; Virtual Storage Console for VMware vSphere 6.x; Virtual Storage Console for VMware vSphere 7.2 and above.
NetApp published this final advisory covering CVE-2017-12617; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; OnCommand Balance; OnCommand Shift.
NetApp published this final advisory covering CVE-2017-12615, CVE-2017-12616; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; OnCommand Balance; OnCommand Shift.
NetApp published this final advisory covering CVE-2015-7871, CVE-2015-7855, CVE-2015-7854, CVE-2015-7853, CVE-2015-7852, CVE-2015-7851, CVE-2015-7850, CVE-2015-7849, CVE-2015-7848, CVE-2015-7701, CVE-2015-7703, CVE-2015-7704, CVE-2015-7705, CVE-2015-7691, CVE-2015-7692, CVE-2015-7702, CVE-2015-5300; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2015-7704, CVE-2016-1548, CVE-2015-8138, CVE-2016-1549, CVE-2016-2516, CVE-2016-2517, CVE-2016-2519, CVE-2016-1550, CVE-2016-1547, CVE-2016-1551, CVE-2016-2518; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2017-12150, CVE-2017-12151, CVE-2017-12163; the API labels exploitation information as **Not public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale); StorageGRID Webscale NAS Bridge; StorageGRID9 (9.x and prior).
NetApp published this final advisory covering CVE-2017-9788, CVE-2017-9789; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager for 7-Mode (core package).
NetApp published this final advisory covering CVE-2017-12611; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance.
NetApp published this final advisory covering CVE-2017-9805; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance.
NetApp published this final advisory covering CVE-2017-12421, CVE-2017-12423; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2017-14053; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager for Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2016-1895; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode.
NetApp published this final advisory covering CVE-2017-12422; the API labels exploitation information as **Not public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).
NetApp published this final advisory covering CVE-2017-12859; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP operating in 7-Mode.
NetApp published this final advisory covering CVE-1999-0016; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode.
NetApp published this final advisory covering CVE-2017-12420; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2017-5201; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2017-1000364, CVE-2017-1000365, CVE-2017-1000366; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Data ONTAP Edge; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Balance; SnapProtect.
NetApp published this final advisory covering CVE-2017-1000367, CVE-2017-1000368; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; Management Network Switch (NetApp CN1601); ONTAP Select Deploy administration utility; OnCommand Balance.
NetApp published this final advisory covering CVE-2016-4436, CVE-2017-5651, CVE-2017-5647, CVE-2017-3633, CVE-2017-3634, CVE-2017-3732, CVE-2017-3732, CVE-2017-3732, CVE-2017-3635, CVE-2017-3635, CVE-2017-3636, CVE-2017-3529, CVE-2017-3637, CVE-2017-3639, CVE-2017-3640, CVE-2017-3641, CVE-2017-3643, CVE-2017-3644, CVE-2017-3638, CVE-2017-3642, CVE-2017-3645, CVE-2017-3646, CVE-2014-1912, CVE-2017-3648, CVE-2017-3647, CVE-2017-3649, CVE-2017-3651, CVE-2017-3652, CVE-2017-3650, CVE-2017-3653; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager for VMware vSphere; OnCommand Unified Manager for VMware vSphere for 7.1 and below; OnCommand Unified Manager for Windows for 7.1 and below; OnCommand Workflow Automation; SnapCenter.
NetApp published this final advisory covering CVE-2017-10110, CVE-2017-10089, CVE-2017-10086, CVE-2017-10096, CVE-2017-10101, CVE-2017-10087, CVE-2017-10090, CVE-2017-10111, CVE-2017-10107, CVE-2017-10102, CVE-2017-10114, CVE-2017-10074, CVE-2017-10116, CVE-2017-10078, CVE-2017-10067, CVE-2017-10115, CVE-2017-10118, CVE-2017-10176, CVE-2017-10104, CVE-2017-10145, CVE-2017-10125, CVE-2017-10198, CVE-2017-10243, CVE-2017-10121, CVE-2017-10135, CVE-2017-10117, CVE-2017-10053, CVE-2017-10108, CVE-2017-10109, CVE-2017-10105, CVE-2017-10081, CVE-2017-10193; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager for VMware vSphere; OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for VMware vSphere for 7.1 and below; OnCommand Unified Manager for Windows for 7.1 and below; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above; Virtual Storage Console for VMware vSphere 6.x; Virtual Storage Console for VMware vSphere 7.2 and above.
NetApp published this final advisory covering CVE-2017-8919; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand API Services.
NetApp published this final advisory covering CVE-2017-7947; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2017-6464, CVE-2017-6462, CVE-2017-6463, CVE-2017-6455, CVE-2017-6452, CVE-2017-6459, CVE-2017-6458, CVE-2017-6451, CVE-2017-6460, CVE-2016-9042; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Balance.
NetApp published this final advisory covering CVE-2017-7494; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID9 (9.x and prior).
NetApp published this final advisory covering CVE-2017-7439; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager for 7-Mode (core package).
NetApp published this final advisory covering CVE-2017-7236; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager for 7-Mode (core package).
NetApp published this final advisory covering CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, CVE-2017-0147, CVE-2017-0148; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2017-5689; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2017-3512, CVE-2017-3514, CVE-2017-3511, CVE-2017-3526, CVE-2017-3509, CVE-2017-3533, CVE-2017-3544, CVE-2017-3539; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Plug-in for Symantec NetBackup; NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 7.2 and above.
NetApp published this final advisory covering CVE-2017-7345; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2017-5988; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2016-5045; the API labels exploitation information as **Not public**. The API currently lists affected products as: OnCommand System Manager 9.x.
NetApp published this final advisory covering CVE-2016-7426, CVE-2016-7427, CVE-2016-7428, CVE-2016-7429, CVE-2016-7431, CVE-2016-7433, CVE-2016-7434, CVE-2016-9310, CVE-2016-9311, CVE-2016-9312; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp SolidFire & HCI Storage Node (Element Software).
NetApp published this final advisory covering CVE-2017-5638; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance.
NetApp published this final advisory covering CVE-2017-5995; the API labels exploitation information as **Not public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2016-5374; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2017-5600; the API labels exploitation information as **Not public**. The API currently lists affected products as: OnCommand Insight.