Content Library · Advisory

Advisory 2018

Browse 112 2018 NetApp advisory records in the NetApp Black Box content library.

Library JSON API

Advisory

November 2018 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181221-0005/

NetApp published this final advisory covering CVE-2018-19395, CVE-2018-19396; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-19935 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181221-0003/

NetApp published this final advisory covering CVE-2018-19935; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-19518 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181221-0004/

NetApp published this final advisory covering CVE-2018-19518; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-15919 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181221-0001/

NetApp published this final advisory covering CVE-2018-15919; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2018-14627 Wildfly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181221-0002/

NetApp published this final advisory covering CVE-2018-14627; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2018 Samba Vulnerabilities in NetApp StorageGRID Products

Source: https://security.netapp.com/advisory/NTAP-20181127-0001/

NetApp published this final advisory covering CVE-2018-16857, CVE-2018-16851, CVE-2018-16852, CVE-2018-16853, CVE-2018-16841, CVE-2018-14629; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2018 Bouncy Castle Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181127-0004/

NetApp published this final advisory covering CVE-2016-1000339, CVE-2016-1000340, CVE-2016-1000341, CVE-2016-1000342, CVE-2016-1000343, CVE-2016-1000344, CVE-2016-1000345, CVE-2016-1000346, CVE-2016-1000352; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Service Level Manager; OnCommand API Services; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2018-5407 Simultaneous Multithreading Side-Channel Information Disclosure Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181126-0001/

NetApp published this final advisory covering CVE-2018-5407; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-16642 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181123-0001/

NetApp published this final advisory covering CVE-2017-16642; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.

Open source
Advisory

CVE-2018-12882 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181109-0001/

NetApp published this final advisory covering CVE-2018-12882; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2018 Net-SNMP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181107-0001/

NetApp published this final advisory covering CVE-2018-18065, CVE-2018-18066; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP operating in 7-Mode; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2017-5645 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181107-0002/

NetApp published this final advisory covering CVE-2017-5645; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Service Level Manager; OnCommand API Services.

Open source
Advisory

August 2018 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181107-0003/

NetApp published this final advisory covering CVE-2017-9118, CVE-2017-9120, CVE-2018-14851, CVE-2018-14883, CVE-2018-14884, CVE-2018-15132; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2018 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181105-0002/

NetApp published this final advisory covering CVE-2018-0734, CVE-2018-0735; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS); NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; ONTAP Antivirus Connector; SnapDrive for Unix; SnapDrive for Windows; SnapProtect.

Open source
Advisory

CVE-2018-0732 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181105-0001/

NetApp published this final advisory covering CVE-2018-0732; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); Data ONTAP Edge; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SteelStore Cloud Integrated Storage; NetApp Storage Encryption; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2018-15473 OpenSSH Username Enumeration Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181101-0001/

NetApp published this final advisory covering CVE-2018-15473; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP Edge; Data ONTAP operating in 7-Mode; FAS/AFF Baseboard Management Controller (BMC) - A320/C190/A220/FAS2720/FAS2750/A800; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; ONTAP Select Deploy administration utility; Service Processor; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2015-5352 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181023-0001/

NetApp published this final advisory covering CVE-2015-5352; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); OnCommand Balance; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

October 2018 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181018-0002/

NetApp published this final advisory covering CVE-2018-11776, CVE-2018-8014, CVE-2018-3258, CVE-2018-1258, CVE-2016-9843, CVE-2018-3155, CVE-2018-3143, CVE-2018-3156, CVE-2018-3251, CVE-2018-3182, CVE-2018-3137, CVE-2018-3203, CVE-2018-3133, CVE-2018-3145, CVE-2018-3144, CVE-2018-3185, CVE-2018-3195, CVE-2018-3247, CVE-2018-3187, CVE-2018-3174, CVE-2018-3171, CVE-2018-3277, CVE-2018-3162, CVE-2018-3173, CVE-2018-3200, CVE-2018-3170, CVE-2018-3212, CVE-2018-3280, CVE-2018-3276, CVE-2018-3186, CVE-2018-3161, CVE-2018-3278, CVE-2018-3279, CVE-2018-3282, CVE-2018-3285, CVE-2018-3284, CVE-2018-3283, CVE-2018-3286; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2018 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181018-0001/

NetApp published this final advisory covering CVE-2018-3183, CVE-2018-3209, CVE-2018-3169, CVE-2018-3149, CVE-2018-3211, CVE-2018-3180, CVE-2018-3214, CVE-2018-3157, CVE-2018-3150, CVE-2018-13785, CVE-2018-3136, CVE-2018-3139; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; OnCommand Insight; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; StorageGRID9 (9.x and prior).

Open source
Advisory

September 2018 Eclipse Jetty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181014-0001/

NetApp published this final advisory covering CVE-2017-7656, CVE-2017-7657, CVE-2017-7658, CVE-2018-12536, CVE-2018-12538; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp SANtricity Cloud Connector; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand System Manager 3.x; OnCommand Unified Manager Core Package; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2018-5391 Linux Kernel Denial of Service Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20181003-0002/

NetApp published this final advisory covering CVE-2018-5391; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Data ONTAP Edge; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A320/C190/A220/FAS2720/FAS2750/A800; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2018-12015 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180927-0001/

NetApp published this final advisory covering CVE-2018-12015; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

May 2018 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180926-0004/

NetApp published this final advisory covering CVE-2018-5736, CVE-2018-5737; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

June 2017 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180926-0001/

NetApp published this final advisory covering CVE-2017-3140, CVE-2017-3141; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Balance.

Open source
Advisory

February 2018 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180926-0005/

NetApp published this final advisory covering CVE-2016-2848, CVE-2016-8864, CVE-2016-9131, CVE-2016-9147, CVE-2016-9444, CVE-2016-9778, CVE-2017-3135, CVE-2018-5734; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2018-5740 ISC Bind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180926-0003/

NetApp published this final advisory covering CVE-2018-5740; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2016-4975 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180926-0006/

NetApp published this final advisory covering CVE-2016-4975; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2016-2848 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180926-0002/

NetApp published this final advisory covering CVE-2016-2848; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp VASA Provider for Clustered Data ONTAP 6.x.

Open source
Advisory

CVE-2018-17082 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180924-0001/

NetApp published this final advisory covering CVE-2018-17082; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-11776 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180822-0001/

NetApp published this final advisory covering CVE-2018-11776; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2018 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180817-0001/

NetApp published this final advisory covering CVE-2018-1336, CVE-2018-8034, CVE-2018-8037; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

Intel SA-00161 L1 Terminal Fault Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180815-0001/

NetApp published this final advisory covering CVE-2018-3615, CVE-2018-3620, CVE-2018-3646; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-5390 Linux Kernel Denial of Service (DoS) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180815-0003/

NetApp published this final advisory covering CVE-2018-5390; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; StorageGRID (formerly StorageGRID Webscale); Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

August 2018 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180814-0001/

NetApp published this final advisory covering CVE-2018-10919, CVE-2018-10918, CVE-2018-10858, CVE-2018-1140, CVE-2018-1139; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-3652 Intel Processor Information Disclosure and Privilege Escalation Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180802-0001/

NetApp published this final advisory covering CVE-2018-3652; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2017 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180802-0002/

NetApp published this final advisory covering CVE-2017-3136, CVE-2017-3137, CVE-2017-3138; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Balance.

Open source
Advisory

November 2017 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180731-0002/

NetApp published this final advisory covering CVE-2016-1240, CVE-2016-9774, CVE-2016-9775, CVE-2017-6056; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; OnCommand Balance; OnCommand Shift; Virtual Storage Console for VMware vSphere 6.x.

Open source
Advisory

July 2018 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180726-0002/

NetApp published this final advisory covering CVE-2017-5645, CVE-2017-0379, CVE-2018-3064, CVE-2018-0739, CVE-2018-0739, CVE-2018-3070, CVE-2018-3060, CVE-2018-3065, CVE-2018-0739, CVE-2018-3073, CVE-2018-0739, CVE-2018-3074, CVE-2018-3062, CVE-2018-3081, CVE-2018-3071, CVE-2018-3079, CVE-2018-3054, CVE-2018-3077, CVE-2018-3078, CVE-2018-3080, CVE-2018-3061, CVE-2018-3067, CVE-2018-3063, CVE-2018-3075, CVE-2018-3058, CVE-2018-3056, CVE-2018-2598, CVE-2018-3066, CVE-2018-2767, CVE-2018-3084, CVE-2018-3082; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2018 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180726-0001/

NetApp published this final advisory covering CVE-2018-2938, CVE-2018-2940, CVE-2018-2941, CVE-2018-2942, CVE-2018-2952, CVE-2018-2964, CVE-2018-2972, CVE-2018-2973; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand Insight; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2018-0737 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180726-0003/

NetApp published this final advisory covering CVE-2018-0737; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Data ONTAP Edge; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; ONTAP Antivirus Connector; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect.

Open source
Advisory

July 2017 Apache Struts Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180706-0002/

NetApp published this final advisory covering CVE-2017-7672, CVE-2017-9791, CVE-2017-9787; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance.

Open source
Advisory

April 2018 Apache Struts Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180629-0006/

NetApp published this final advisory covering CVE-2016-1182, CVE-2016-1181, CVE-2015-0899, CVE-2014-0114; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2015-8325 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180628-0001/

NetApp published this final advisory covering CVE-2015-8325; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); OnCommand Balance.

Open source
Advisory

March 2018 Network Time Protocol Daemon (ntpd) Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180626-0001/

NetApp published this final advisory covering CVE-2018-7170, CVE-2018-7182, CVE-2018-7183, CVE-2018-7184, CVE-2018-7185; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2015-8960 TLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180626-0002/

NetApp published this final advisory covering CVE-2015-8960; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; OnCommand Shift; Snap Creator Framework; SnapDrive for Unix; SnapDrive for Windows; SnapManager for Oracle; SnapManager for SAP; SnapProtect; System Setup.

Open source
Advisory

March 2017 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180614-0001/

NetApp published this final advisory covering CVE-2017-5651, CVE-2017-5648, CVE-2017-5647, CVE-2017-5650; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; OnCommand Shift; Snap Creator Framework.

Open source
Advisory

July 2017 Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180614-0003/

NetApp published this final advisory covering CVE-2017-7674, CVE-2017-7675; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance; OnCommand Shift.

Open source
Advisory

November 2016 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180607-0001/

NetApp published this final advisory covering CVE-2016-8735, CVE-2016-6817, CVE-2016-6816; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; OnCommand Insight; OnCommand Shift; Snap Creator Framework.

Open source
Advisory

May 2018 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180607-0003/

NetApp published this final advisory covering CVE-2018-10545, CVE-2018-10546, CVE-2018-10547, CVE-2018-10548, CVE-2018-10549; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2016-8745 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180607-0002/

NetApp published this final advisory covering CVE-2016-8745; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight; OnCommand Shift; Snap Creator Framework.

Open source
Advisory

October 2016 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180605-0001/

NetApp published this final advisory covering CVE-2016-5018, CVE-2016-6796, CVE-2016-6797, CVE-2016-6794, CVE-2016-0762; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight; OnCommand Shift; Snap Creator Framework.

Open source
Advisory

March 2018 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180601-0004/

NetApp published this final advisory covering CVE-2017-15710, CVE-2017-15715, CVE-2018-1283, CVE-2018-1301, CVE-2018-1302, CVE-2018-1303, CVE-2018-1312; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

June 2017 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180601-0002/

NetApp published this final advisory covering CVE-2017-3167, CVE-2017-3169, CVE-2017-7659, CVE-2017-7668, CVE-2017-7679; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; OnCommand Unified Manager for 7-Mode (core package); StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2016-8612 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180601-0005/

NetApp published this final advisory covering CVE-2016-8612; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2016 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180531-0001/

NetApp published this final advisory covering CVE-2015-5345, CVE-2015-5351, CVE-2016-0706, CVE-2016-0714, CVE-2016-0763, CVE-2015-5174, CVE-2015-5346; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight; OnCommand Report; OnCommand Shift; Snap Creator Framework; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2018-5487 Unauthenticated Remote Code Execution Vulnerability in OnCommand Unified Manager for Linux and Windows 7.2 and above

Source: https://security.netapp.com/advisory/NTAP-20180523-0001/

NetApp published this final advisory covering CVE-2018-5487; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above.

Open source
Advisory

Speculative Execution Side Channel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180521-0001/

NetApp published this final advisory covering CVE-2018-3639, CVE-2018-3640; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2017 Perl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180426-0001/

NetApp published this final advisory covering CVE-2017-12883, CVE-2017-12837, CVE-2017-12814; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Workflow Automation.

Open source
Advisory

December 2016 Apache HTTP Server Vulnerabilities in Multiple NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180423-0001/

NetApp published this final advisory covering CVE-2016-0736, CVE-2016-2161, CVE-2016-8740, CVE-2016-8743; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP; OnCommand Unified Manager for 7-Mode (core package).

Open source
Advisory

CVE-2018-5968 Jackson JSON Library Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180423-0002/

NetApp published this final advisory covering CVE-2018-5968; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Web Services (REST API) for Web Services Proxy; OnCommand Shift.

Open source
Advisory

CVE-2017-15906 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180423-0004/

NetApp published this final advisory covering CVE-2017-15906; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand Unified Manager Core Package; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2016-10708 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180423-0003/

NetApp published this final advisory covering CVE-2016-10708; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Clustered Data ONTAP; Data ONTAP Edge; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; Service Processor; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

April 2018 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180419-0002/

NetApp published this final advisory covering CVE-2018-2755, CVE-2018-2805, CVE-2018-2782, CVE-2018-2784, CVE-2018-2819, CVE-2018-2758, CVE-2018-2817, CVE-2018-2775, CVE-2018-2780, CVE-2017-3737, CVE-2018-2761, CVE-2018-2786, CVE-2018-2787, CVE-2018-2812, CVE-2018-2877, CVE-2018-2759, CVE-2018-2766, CVE-2018-2777, CVE-2018-2810, CVE-2018-2818, CVE-2018-2839, CVE-2018-2778, CVE-2018-2779, CVE-2018-2781, CVE-2018-2816, CVE-2018-2846, CVE-2018-2769, CVE-2018-2776, CVE-2018-2762, CVE-2018-2771, CVE-2018-2813, CVE-2018-2773, CVE-2016-9878; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2018 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180419-0001/

NetApp published this final advisory covering CVE-2018-2825, CVE-2018-2826, CVE-2018-2814, CVE-2018-2811, CVE-2018-2794, CVE-2018-2783, CVE-2018-2798, CVE-2018-2796, CVE-2018-2799, CVE-2018-2797, CVE-2018-2795, CVE-2018-2815, CVE-2018-2800, CVE-2018-2790; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SANtricity Cloud Connector; NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Insight; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 7.2 and above; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

March 2018 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180330-0002/

NetApp published this final advisory covering CVE-2018-0739, CVE-2018-0733; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP Antivirus Connector; Data ONTAP Edge; Data ONTAP operating in 7-Mode; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Host Agent; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp VASA Provider for Clustered Data ONTAP 9.6 and above; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapCenter; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.6 and above; Virtual Storage Console for VMware vSphere 9.6 and above.

Open source
Advisory

CVE-2018-1327 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180330-0001/

NetApp published this final advisory covering CVE-2018-1327; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-7489 Jackson JSON Library Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180328-0001/

NetApp published this final advisory covering CVE-2018-7489; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Service Level Manager; OnCommand API Services; OnCommand Cloud Manager; SnapCenter.

Open source
Advisory

March 2018 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180313-0001/

NetApp published this final advisory covering CVE-2018-1057, CVE-2018-1050; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2016-0793 Wildfly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180215-0001/

NetApp published this final advisory covering CVE-2016-0793; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above.

Open source
Advisory

SMBLoris Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180213-0001/

NetApp published this final advisory covering No CVE listed; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2017-17485 Jackson JSON Library vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180201-0003/

NetApp published this final advisory covering CVE-2017-17485; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Web Services (REST API) for Web Services Proxy; OnCommand Shift; SnapCenter.

Open source
Advisory

CVE-2016-8858 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180201-0001/

NetApp published this final advisory covering CVE-2016-8858; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2015-6563 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180201-0002/

NetApp published this final advisory covering CVE-2015-6563; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP Edge; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; ONTAP Select Deploy administration utility.

Open source
Advisory

January 2018 MySQL vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180117-0002/

NetApp published this final advisory covering CVE-2017-12617, CVE-2018-2585, CVE-2018-2696, CVE-2018-2562, CVE-2018-2583, CVE-2018-2612, CVE-2018-2703, CVE-2018-2622, CVE-2018-2573, CVE-2018-2640, CVE-2018-2665, CVE-2018-2668, CVE-2017-3736, CVE-2017-3736, CVE-2017-3737, CVE-2018-2647, CVE-2018-2591, CVE-2018-2576, CVE-2018-2586, CVE-2018-2646, CVE-2018-2565, CVE-2018-2600, CVE-2018-2667, CVE-2018-2590, CVE-2018-2645; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2018 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180117-0001/

NetApp published this final advisory covering CVE-2018-2638, CVE-2018-2639, CVE-2018-2633, CVE-2018-2627, CVE-2018-2637, CVE-2018-2634, CVE-2018-2582, CVE-2018-2641, CVE-2018-2618, CVE-2018-2629, CVE-2018-2603, CVE-2018-2657, CVE-2018-2599, CVE-2018-2581, CVE-2018-2602, CVE-2018-2677, CVE-2018-2678, CVE-2018-2588, CVE-2018-2663, CVE-2018-2675, CVE-2018-2579; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; E-Series SANtricity Management Plug-ins (Microsoft System Center (SCOM)); E-Series SANtricity Management Plug-ins (VMware SRA); E-Series SANtricity Management Plug-ins (VMware VASA (Windows)); E-Series SANtricity Management Plug-ins (VMware vCenter (Linux)); E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SANtricity Cloud Connector; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; OnCommand Insight; OnCommand Shift; OnCommand Unified Manager for 7-Mode (core package); OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 7.2 and above; Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 6.x; Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

September 2017 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180112-0001/

NetApp published this final advisory covering CVE-2017-11628, CVE-2017-11362, CVE-2017-11142, CVE-2016-10397, CVE-2017-11143, CVE-2017-11144, CVE-2017-11145, CVE-2017-11147, CVE-2017-9119, CVE-2016-5399, CVE-2017-7272, CVE-2016-5873, CVE-2016-10160, CVE-2016-7479, CVE-2016-7480, CVE-2017-5340, CVE-2016-7478, CVE-2017-12932, CVE-2017-7890, CVE-2016-10158, CVE-2016-10159, CVE-2016-10161; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.

Open source
Advisory

CVE-2017-8779 rpcbind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180109-0001/

NetApp published this final advisory covering CVE-2017-8779; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP Edge; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand Balance; SnapProtect; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

Processor Speculated Execution Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20180104-0001/

NetApp published this final advisory covering CVE-2017-5715, CVE-2017-5753, CVE-2017-5754; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node.

Open source