Content Library · Advisory

Advisory 2017

Browse 61 2017 NetApp advisory records in the NetApp Black Box content library.

Library JSON API

Advisory

CVE-2017-13098 Bouncy Castle TLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171222-0001/

NetApp published this final advisory covering CVE-2017-13098; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-7525 Jackson JSON Library Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171214-0002/

NetApp published this final advisory covering CVE-2017-7525; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Performance Manager for Linux; OnCommand Performance Manager for VMware vSphere; OnCommand Shift; SnapCenter.

Open source
Advisory

CVE-2017-15095 Jackson JSON Library vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171214-0003/

NetApp published this final advisory covering CVE-2017-15095; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Performance Manager for Linux; OnCommand Performance Manager for VMware vSphere; OnCommand Shift; SnapCenter.

Open source
Advisory

December 2017 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171208-0001/

NetApp published this final advisory covering CVE-2017-3737, CVE-2017-3738; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Storage Node (Element Software); NetApp Storage Encryption; NetApp VASA Provider for Clustered Data ONTAP 6.x; OnCommand Balance; OnCommand Performance Manager for VMware vSphere; OnCommand Unified Manager Core Package; OnCommand Unified Manager for VMware vSphere for 7.1 and below; OnCommand Workflow Automation; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

January 2017 OpenSSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171130-0002/

NetApp published this final advisory covering CVE-2016-10012, CVE-2016-10011, CVE-2016-10010, CVE-2016-10009; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP operating in 7-Mode; Management Network Switch (NetApp CN1601); NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager for 7-Mode (core package).

Open source
Advisory

CVE-2016-8610 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171130-0001/

NetApp published this final advisory covering CVE-2016-8610; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; E-Series SANtricity OS Controller Software 11.x; NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp VASA Provider for Clustered Data ONTAP 6.x; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; Service Processor; SnapCenter; SnapDrive for Unix; SnapProtect; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2016-6515 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171130-0003/

NetApp published this final advisory covering CVE-2016-6515: OpenSSH vulnerability; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager for Clustered Data ONTAP; Service Processor; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

Intel SA-00086 Management Engine Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171120-0001/

NetApp published this final advisory covering CVE-2017-5705, CVE-2017-5708, CVE-2017-5711, CVE-2017-5712, CVE-2017-5706, CVE-2017-5709, CVE-2017-5707, CVE-2017-5710; the API labels exploitation information as **Not public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-3736 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171107-0002/

NetApp published this final advisory covering CVE-2017-3736; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; E-Series SANtricity OS Controller Software 11.x; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp Storage Encryption; NetApp VASA Provider for Clustered Data ONTAP 6.x; OnCommand Balance; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

January 2016 Network Time Protocol Daemon (ntpd) Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171031-0001/

NetApp published this final advisory covering CVE-2015-7979, CVE-2015-7973, CVE-2015-7974, CVE-2015-8158, CVE-2015-8138, CVE-2015-7978, CVE-2015-7977, CVE-2015-7976, CVE-2015-7975; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; OnCommand Balance.

Open source
Advisory

CVE-2017-15361 Infineon RSA Library Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171024-0001/

NetApp published this final advisory covering CVE-2017-15361; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2017 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171019-0002/

NetApp published this final advisory covering CVE-2017-10155, CVE-2017-10165, CVE-2017-10167, CVE-2017-10203, CVE-2017-10227, CVE-2017-10268, CVE-2017-10276, CVE-2017-10277, CVE-2017-10279, CVE-2017-10283, CVE-2017-10284, CVE-2017-10286, CVE-2017-10294, CVE-2017-10296, CVE-2017-10311, CVE-2017-10313, CVE-2017-10314, CVE-2017-10320, CVE-2017-10365, CVE-2017-10378, CVE-2017-10379, CVE-2017-10384, CVE-2017-10424, CVE-2017-3731, CVE-2017-5664; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager for VMware vSphere; OnCommand Unified Manager for VMware vSphere for 7.1 and below; OnCommand Unified Manager for Windows for 7.1 and below; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2017 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171019-0001/

NetApp published this final advisory covering CVE-2017-10346, CVE-2017-10285, CVE-2017-10388, CVE-2017-10309, CVE-2017-10274, CVE-2017-10356, CVE-2017-10293, CVE-2017-10342, CVE-2017-10350, CVE-2017-10349, CVE-2017-10348, CVE-2017-10357, CVE-2016-9841, CVE-2016-10165, CVE-2017-10355, CVE-2017-10281, CVE-2017-10347, CVE-2017-10386, CVE-2017-10380, CVE-2017-10295, CVE-2017-10341, CVE-2017-10345; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager for VMware vSphere; OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for VMware vSphere for 7.1 and below; OnCommand Unified Manager for Windows for 7.1 and below; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 7.2 and above; Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above; Virtual Storage Console for VMware vSphere 6.x; Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

CVE-2017-12617 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171018-0002/

NetApp published this final advisory covering CVE-2017-12617; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; OnCommand Balance; OnCommand Shift.

Open source
Advisory

August 2017 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171018-0001/

NetApp published this final advisory covering CVE-2017-12615, CVE-2017-12616; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; OnCommand Balance; OnCommand Shift.

Open source
Advisory

October 2015 Network Time Protocol Daemon (ntpd) Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171004-0001/

NetApp published this final advisory covering CVE-2015-7871, CVE-2015-7855, CVE-2015-7854, CVE-2015-7853, CVE-2015-7852, CVE-2015-7851, CVE-2015-7850, CVE-2015-7849, CVE-2015-7848, CVE-2015-7701, CVE-2015-7703, CVE-2015-7704, CVE-2015-7705, CVE-2015-7691, CVE-2015-7692, CVE-2015-7702, CVE-2015-5300; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP.

Open source
Advisory

April 2016 Network Time Protocol Daemon (ntpd) Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20171004-0002/

NetApp published this final advisory covering CVE-2015-7704, CVE-2016-1548, CVE-2015-8138, CVE-2016-1549, CVE-2016-2516, CVE-2016-2517, CVE-2016-2519, CVE-2016-1550, CVE-2016-1547, CVE-2016-1551, CVE-2016-2518; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; OnCommand Balance; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP.

Open source
Advisory

CVE-2017-3735 OpenSSL Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170927-0001/

NetApp published this final advisory covering CVE-2017-3735; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; E-Series SANtricity OS Controller Software 11.x; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 6.x; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

September 2017 Samba Vulnerabilities in NetApp StorageGRID Products

Source: https://security.netapp.com/advisory/NTAP-20170921-0001/

NetApp published this final advisory covering CVE-2017-12150, CVE-2017-12151, CVE-2017-12163; the API labels exploitation information as **Not public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale); StorageGRID Webscale NAS Bridge; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-1999-0016 Denial of Service Vulnerability in Data ONTAP

Source: https://security.netapp.com/advisory/NTAP-20170815-0001/

NetApp published this final advisory covering CVE-1999-0016; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode.

Open source
Advisory

Linux Memory Management Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170808-0001/

NetApp published this final advisory covering CVE-2017-1000364, CVE-2017-1000365, CVE-2017-1000366; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Data ONTAP Edge; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Balance; SnapProtect.

Open source
Advisory

June 2017 sudo Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170803-0001/

NetApp published this final advisory covering CVE-2017-1000367, CVE-2017-1000368; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; Management Network Switch (NetApp CN1601); ONTAP Select Deploy administration utility; OnCommand Balance.

Open source
Advisory

July 2017 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170720-0002/

NetApp published this final advisory covering CVE-2016-4436, CVE-2017-5651, CVE-2017-5647, CVE-2017-3633, CVE-2017-3634, CVE-2017-3732, CVE-2017-3732, CVE-2017-3732, CVE-2017-3635, CVE-2017-3635, CVE-2017-3636, CVE-2017-3529, CVE-2017-3637, CVE-2017-3639, CVE-2017-3640, CVE-2017-3641, CVE-2017-3643, CVE-2017-3644, CVE-2017-3638, CVE-2017-3642, CVE-2017-3645, CVE-2017-3646, CVE-2014-1912, CVE-2017-3648, CVE-2017-3647, CVE-2017-3649, CVE-2017-3651, CVE-2017-3652, CVE-2017-3650, CVE-2017-3653; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager for VMware vSphere; OnCommand Unified Manager for VMware vSphere for 7.1 and below; OnCommand Unified Manager for Windows for 7.1 and below; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2017 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170720-0001/

NetApp published this final advisory covering CVE-2017-10110, CVE-2017-10089, CVE-2017-10086, CVE-2017-10096, CVE-2017-10101, CVE-2017-10087, CVE-2017-10090, CVE-2017-10111, CVE-2017-10107, CVE-2017-10102, CVE-2017-10114, CVE-2017-10074, CVE-2017-10116, CVE-2017-10078, CVE-2017-10067, CVE-2017-10115, CVE-2017-10118, CVE-2017-10176, CVE-2017-10104, CVE-2017-10145, CVE-2017-10125, CVE-2017-10198, CVE-2017-10243, CVE-2017-10121, CVE-2017-10135, CVE-2017-10117, CVE-2017-10053, CVE-2017-10108, CVE-2017-10109, CVE-2017-10105, CVE-2017-10081, CVE-2017-10193; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager for VMware vSphere; OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for VMware vSphere for 7.1 and below; OnCommand Unified Manager for Windows for 7.1 and below; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above; Virtual Storage Console for VMware vSphere 6.x; Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

March 2017 Network Time Protocol Daemon (ntpd) Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170526-0001/

NetApp published this final advisory covering CVE-2017-6464, CVE-2017-6462, CVE-2017-6463, CVE-2017-6455, CVE-2017-6452, CVE-2017-6459, CVE-2017-6458, CVE-2017-6451, CVE-2017-6460, CVE-2016-9042; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Balance.

Open source
Advisory

NetApp Product Security Notice for WannaCrypt and Petya Ransomware

Source: https://security.netapp.com/advisory/NTAP-20170515-0001/

NetApp published this final advisory covering CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, CVE-2017-0147, CVE-2017-0148; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-5689 Intel Management Engine Vulnerability in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170509-0001/

NetApp published this final advisory covering CVE-2017-5689; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2017 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170420-0002/

NetApp published this final advisory covering CVE-2017-3308, CVE-2017-3309, CVE-2017-3450, CVE-2017-3599, CVE-2017-3329, CVE-2017-3600, CVE-2017-3331, CVE-2017-3453, CVE-2017-3452, CVE-2017-3454, CVE-2017-3455, CVE-2017-3305, CVE-2017-3302, CVE-2017-3460, CVE-2017-3456, CVE-2017-3458, CVE-2017-3457, CVE-2017-3459, CVE-2017-3463, CVE-2017-3462, CVE-2017-3461, CVE-2017-3464, CVE-2017-3465, CVE-2017-3467, CVE-2017-3468; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2017 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170420-0001/

NetApp published this final advisory covering CVE-2017-3512, CVE-2017-3514, CVE-2017-3511, CVE-2017-3526, CVE-2017-3509, CVE-2017-3533, CVE-2017-3544, CVE-2017-3539; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Plug-in for Symantec NetBackup; NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

November 2016 Network Time Protocol Daemon (ntpd) Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170310-0002/

NetApp published this final advisory covering CVE-2016-7426, CVE-2016-7427, CVE-2016-7428, CVE-2016-7429, CVE-2016-7431, CVE-2016-7433, CVE-2016-7434, CVE-2016-9310, CVE-2016-9311, CVE-2016-9312; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

January 2017 OpenSSL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170127-0001/

NetApp published this final advisory covering CVE-2017-3732, CVE-2017-3731, CVE-2017-3730, CVE-2016-7055; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; Data ONTAP operating in 7-Mode; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp SMI-S Provider; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); OnCommand Unified Manager Core Package; OnCommand Workflow Automation; Open Systems SnapVault Agent; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID9 (9.x and prior).

Open source
Advisory

January 2017 MySQL Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170119-0002/

NetApp published this final advisory covering CVE-2016-8318, CVE-2017-3312, CVE-2017-3258, CVE-2017-3273, CVE-2017-3244, CVE-2017-3257, CVE-2017-3238, CVE-2017-3256, CVE-2017-3291, CVE-2017-3265, CVE-2017-3251, CVE-2016-5541, CVE-2017-3313, CVE-2017-3243, CVE-2016-8327, CVE-2017-3317, CVE-2017-3318, CVE-2017-3321, CVE-2017-3323, CVE-2017-3322, CVE-2017-3319, CVE-2017-3320; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2017 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20170119-0001/

NetApp published this final advisory covering CVE-2017-3289, CVE-2017-3272, CVE-2017-3241, CVE-2017-3260, CVE-2017-3253, CVE-2016-5546, CVE-2016-5549, CVE-2016-5548, CVE-2017-3252, CVE-2017-3262, CVE-2016-5547, CVE-2016-5552, CVE-2017-3231, CVE-2017-3261, CVE-2017-3259, CVE-2016-8328, CVE-2016-2183; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Balance; OnCommand Cloud Manager; OnCommand Insight; OnCommand Performance Manager (Unified Manager Performance Pkg); OnCommand Unified Manager for 7-Mode (core package); OnCommand Unified Manager for Clustered Data ONTAP; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 7.2 and above.

Open source