NetApp published this final advisory covering CVE-2019-19317, CVE-2019-19603, CVE-2019-19645, CVE-2019-19646; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2019-19118; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.
NetApp published this final advisory covering CVE-2019-14607; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.
NetApp published this final advisory covering CVE-2019-11157; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.
NetApp published this final advisory covering CVE-2019-14861, CVE-2019-14870; the API labels exploitation information as **Not public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-17067, CVE-2019-17068, CVE-2019-17069; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager Core Package.
NetApp published this final advisory covering CVE-2018-1721, CVE-2019-4334, CVE-2019-4645; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2019-17592; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-8048, CVE-2019-15587, CVE-2019-15845, CVE-2019-16201, CVE-2019-16254, CVE-2019-16255; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-6477; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.
NetApp published this final advisory covering CVE-2019-17596; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-16276; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent.
NetApp published this final advisory covering CVE-2018-21029; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-5509; the API labels exploitation information as **Not public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2019-17272; the API labels exploitation information as **Not public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2019-11136, CVE-2019-11137; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-11139; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A320; FAS/AFF BIOS - A800.
NetApp published this final advisory covering CVE-2019-11135; the API labels exploitation information as **Not public**. The API currently lists affected products as: FAS/AFF BIOS.
NetApp published this final advisory covering CVE-2019-0139, CVE-2019-0140, CVE-2019-0142, CVE-2019-0143, CVE-2019-0144, CVE-2019-0145, CVE-2019-0146, CVE-2019-0147, CVE-2019-0148, CVE-2019-0149, CVE-2019-0150; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).
NetApp published this final advisory covering CVE-2019-0185; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-0151, CVE-2019-0152; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-0117; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-12207; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-0184; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-18348; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-17514; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2007-2768; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.
NetApp published this interim advisory covering CVE-2007-2243; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; StorageGRID9 (9.x and prior).
NetApp published this final advisory covering CVE-2019-10218, CVE-2019-14833; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-18197; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2019-14847; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-11253; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-11043; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-6475, CVE-2019-6476; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.
NetApp published this final advisory covering CVE-2019-17450, CVE-2019-17451; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).
NetApp published this final advisory covering CVE-2019-5508; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2019-17531; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage; OnCommand Workflow Automation.
NetApp published this final advisory covering CVE-2019-17359; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; NetApp Service Level Manager; OnCommand API Services; OnCommand Workflow Automation.
NetApp published this interim advisory covering CVE-2019-16905; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.
NetApp published this final advisory covering CVE-2019-5443, CVE-2019-2910, CVE-2019-2911, CVE-2019-2914, CVE-2019-2922, CVE-2019-2923, CVE-2019-2924, CVE-2019-2938, CVE-2019-2946, CVE-2019-2948, CVE-2019-2950, CVE-2019-2957, CVE-2019-2960, CVE-2019-2963, CVE-2019-2966, CVE-2019-2967, CVE-2019-2968, CVE-2019-2969, CVE-2019-2974, CVE-2019-2982, CVE-2019-2991, CVE-2019-2993, CVE-2019-2997, CVE-2019-2998, CVE-2019-3003, CVE-2019-3004, CVE-2019-3009, CVE-2019-3011, CVE-2019-3018; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.
NetApp published this final advisory covering CVE-2019-16942, CVE-2019-16943, CVE-2019-17267; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; NetApp SteelStore Cloud Integrated Storage; OnCommand API Services; OnCommand Workflow Automation.
NetApp published this final advisory covering CVE-2019-16935; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2019-15138; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-14287; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.
NetApp published this final advisory covering CVE-2019-4183, CVE-2019-4342; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering No CVE listed; the API labels exploitation information as **Not public**. The API currently lists affected products as: SnapManager for Oracle.
NetApp published this final advisory covering CVE-2019-5506; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2019-15635; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-5481, CVE-2019-5482; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.
NetApp published this final advisory covering CVE-2019-14540, CVE-2019-16335; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage; OnCommand API Services; OnCommand Workflow Automation.
NetApp published this final advisory covering CVE-2017-9078, CVE-2017-9079; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H410C.
NetApp published this final advisory covering CVE-2019-15043; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.
NetApp published this final advisory covering CVE-2019-10744; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager.
NetApp published this final advisory covering CVE-2019-11184; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.
NetApp published this final advisory covering CVE-2019-16168; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2019-16056; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-15903; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for VMware vSphere; Clustered Data ONTAP; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; OnCommand Workflow Automation.
NetApp published this final advisory covering CVE-2019-12401; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-5505; the API labels exploitation information as **Not public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2019-5504; the API labels exploitation information as **Not public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2018-3721, CVE-2018-16487, CVE-2019-1010266; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; System Manager 9.x.
NetApp published this final advisory covering CVE-2019-11245, CVE-2019-11246, CVE-2019-11247, CVE-2019-11248, CVE-2019-11249, CVE-2019-11250; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-11358; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); OnCommand System Manager 3.x; SnapCenter.
NetApp published this final advisory covering CVE-2019-5608, CVE-2019-5609, CVE-2019-5610, CVE-2019-5611, CVE-2019-5612; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2019-13139; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-12400; the API labels exploitation information as **Public**. The API currently lists affected products as: Snap Creator Framework.
NetApp published this final advisory covering CVE-2019-10071; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2019-5503; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Workflow Automation.
NetApp published this final advisory covering CVE-2019-10092, CVE-2019-10098, CVE-2019-10082, CVE-2019-10081, CVE-2019-10097; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2019-8460; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode.
NetApp published this final advisory covering CVE-2019-10197; the API labels exploitation information as **Not public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2015-4620; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance.
NetApp published this final advisory covering CVE-2018-1630, CVE-2018-1631, CVE-2018-1632, CVE-2018-1633, CVE-2018-1634, CVE-2018-1635, CVE-2018-1636, CVE-2018-11796, CVE-2019-4253; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2017-3142, CVE-2017-3143; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; OnCommand Balance.
NetApp published this final advisory covering CVE-2018-5741; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-5738; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge.
NetApp published this final advisory covering CVE-2019-13636, CVE-2019-13638; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above.
NetApp published this final advisory covering CVE-2019-14271, CVE-2019-13509; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-14232, CVE-2019-14233, CVE-2019-14234, CVE-2019-14235; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.
NetApp published this final advisory covering CVE-2019-10088, CVE-2019-10093, CVE-2019-10094; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-9517; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-9511, CVE-2019-9512, CVE-2019-9513, CVE-2019-9514, CVE-2019-9515, CVE-2019-9516, CVE-2019-9517, CVE-2019-9518; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapCenter.
NetApp published this final advisory covering CVE-2019-9511, CVE-2019-9513, CVE-2019-9516; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).
NetApp published this final advisory covering CVE-2019-9512, CVE-2019-9514; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-9512, CVE-2019-9514; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent; Trident.
NetApp published this final advisory covering CVE-2019-13057; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-1010204; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.
NetApp published this final advisory covering CVE-2019-11041, CVE-2019-11042; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-14250, CVE-2019-14444; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.
NetApp published this final advisory covering CVE-2018-5744, CVE-2018-5745, CVE-2019-6465; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-13232; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node.
NetApp published this final advisory covering CVE-2019-5603, CVE-2019-5604, CVE-2019-5605, CVE-2019-5606, CVE-2019-5607; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-14379, CVE-2019-14439; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; NetApp Service Level Manager; OnCommand Workflow Automation; SnapCenter.
NetApp published this final advisory covering CVE-2019-5498; the API labels exploitation information as **Not public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2019-1125; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2019-13117, CVE-2019-13118; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2019-13115; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2019-13012; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2019-5502; the API labels exploitation information as **Not public**. The API currently lists affected products as: Data ONTAP operating in 7-Mode.
NetApp published this final advisory covering CVE-2019-5500; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A320/C190/A220/FAS2720/FAS2750/A800; Service Processor.
NetApp published this final advisory covering CVE-2019-12256, CVE-2019-12257, CVE-2019-12255, CVE-2019-12260, CVE-2019-12261, CVE-2019-12263, CVE-2019-12258, CVE-2019-12259, CVE-2019-12262, CVE-2019-12264, CVE-2019-12265; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 8.x.
NetApp published this final advisory covering CVE-2019-5501; the API labels exploitation information as **Not public**. The API currently lists affected products as: Data ONTAP operating in 7-Mode.
NetApp published this final advisory covering CVE-2019-5493; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP operating in 7-Mode.
NetApp published this final advisory covering CVE-2016-8106; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2015-5722, CVE-2015-5986; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Balance.
NetApp published this final advisory covering CVE-2014-8500, CVE-2014-8680; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-20836, CVE-2019-11810, CVE-2019-11811, CVE-2019-11815; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Cluster Network Switch (NetApp CN1610); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 7.2 and above; Virtual Storage Console for VMware vSphere 7.2 and above.
NetApp published this final advisory covering CVE-2019-3822, CVE-2019-2822, CVE-2019-2800, CVE-2019-2795, CVE-2019-2746, CVE-2019-2812, CVE-2019-2834, CVE-2019-2805, CVE-2019-2740, CVE-2019-2758, CVE-2019-2819, CVE-2019-2731, CVE-2019-2778, CVE-2019-2741, CVE-2019-2743, CVE-2019-2739, CVE-2019-2785, CVE-2019-2798, CVE-2019-2879, CVE-2019-2737, CVE-2019-2780, CVE-2019-2784, CVE-2019-2801, CVE-2019-2747, CVE-2019-2757, CVE-2019-2774, CVE-2019-2796, CVE-2019-2802, CVE-2019-2803, CVE-2019-2808, CVE-2019-2810, CVE-2019-2815, CVE-2019-2830, CVE-2019-2752, CVE-2019-2755, CVE-2019-2811, CVE-2019-2826, CVE-2019-2797, CVE-2019-2791, CVE-2019-2738, CVE-2019-2730, CVE-2019-2789, CVE-2019-2814; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.
NetApp published this final advisory covering CVE-2019-2745, CVE-2019-2762, CVE-2019-2766, CVE-2019-2769, CVE-2019-2786, CVE-2019-2816, CVE-2019-2818, CVE-2019-2821, CVE-2019-2842, CVE-2019-7317; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; OnCommand Insight; OnCommand Workflow Automation; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP.
NetApp published this final advisory covering CVE-2018-14404; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2017-5130, CVE-2017-18258; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Data ONTAP Edge; NetApp Manageability SDK; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix.
NetApp published this final advisory covering CVE-2018-20801; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; OnCommand Insight; OnCommand Workflow Automation.
NetApp published this final advisory covering CVE-2019-13068; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.
NetApp published this final advisory covering CVE-2019-10161, CVE-2019-10166, CVE-2019-10167, CVE-2019-10168; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-12781; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-12384; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; NetApp SANtricity Cloud Connector; NetApp Service Level Manager; OnCommand Workflow Automation.
NetApp published this final advisory covering CVE-2018-20843; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand Workflow Automation; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.
NetApp published this final advisory covering CVE-2019-5497; the API labels exploitation information as **Not public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2019-6471; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-5599; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-12875; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-12814; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; NetApp SteelStore Cloud Integrated Storage; SnapCenter.
NetApp published this final advisory covering CVE-2019-10072; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-0220; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2019-3843, CVE-2019-3844; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.
NetApp published this final advisory covering CVE-2019-12435, CVE-2019-12436; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-9740; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-3829; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 7.2 and above.
NetApp published this interim advisory covering CVE-2019-0201; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).
NetApp published this final advisory covering CVE-2018-11802; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-0196, CVE-2019-0197; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-4139; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2019-10160; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Converged Systems Advisor Agent.
NetApp published this final advisory covering CVE-2018-8029; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-0174; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-5597, CVE-2019-5598; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-9628; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-10934; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-5435, CVE-2019-5436; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage.
NetApp published this final advisory covering CVE-2019-8457; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).
NetApp published this final advisory covering CVE-2019-12450; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-0221; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand System Manager 3.x.
NetApp published this final advisory covering CVE-2018-11307, CVE-2018-12022, CVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-14720, CVE-2018-14721, CVE-2018-19360, CVE-2018-19361, CVE-2018-19362, CVE-2019-12086; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage; OnCommand Workflow Automation; SnapCenter.
NetApp published this final advisory covering CVE-2018-20839; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.
NetApp published this final advisory covering CVE-2018-1000632; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand System Manager 3.x; OnCommand Workflow Automation; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP.
NetApp published this final advisory covering CVE-2019-5018; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-20509, CVE-2019-11599, CVE-2019-11683; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.
NetApp published this final advisory covering CVE-2019-3805, CVE-2019-3894; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-11486, CVE-2019-11487, CVE-2019-3882, CVE-2019-3900, CVE-2019-3901; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.
NetApp published this final advisory covering CVE-2019-9636; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-11036; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-0119, CVE-2019-0120, CVE-2019-0126; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SteelStore Cloud Integrated Storage; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).
NetApp published this final advisory covering CVE-2019-0089, CVE-2019-0090, CVE-2019-0086, CVE-2019-0091, CVE-2019-0092, CVE-2019-0093, CVE-2019-0094, CVE-2019-0096, CVE-2019-0097, CVE-2019-0098, CVE-2019-0099, CVE-2019-0153, CVE-2019-0170; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.
NetApp published this final advisory covering CVE-2018-16860; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-5743, CVE-2019-6467, CVE-2019-6468; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-5021; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-5495; the API labels exploitation information as **Not public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above.
NetApp published this final advisory covering CVE-2019-5494; the API labels exploitation information as **Not public**. The API currently lists affected products as: OnCommand Unified Manager for 7-Mode (core package).
NetApp published this final advisory covering CVE-2019-5496; the API labels exploitation information as **Not public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2019-11243, CVE-2019-11244; the API labels exploitation information as **Public**. The API currently lists affected products as: Trident.
NetApp published this final advisory covering CVE-2019-5953; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2019-4178; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2019-10241, CVE-2019-10246, CVE-2019-10247; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand System Manager 3.x; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.
NetApp published this final advisory covering CVE-2019-8936; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode.
NetApp published this final advisory covering CVE-2019-9637, CVE-2019-9638, CVE-2019-9639, CVE-2019-9640, CVE-2019-9641; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-9193; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-3836; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-0222; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Web Services (REST API) for Web Services Proxy.
NetApp published this final advisory covering CVE-2018-20449; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.
NetApp published this final advisory covering CVE-2018-16984; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.
NetApp published this final advisory covering CVE-2018-20505, CVE-2018-20506; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-11034, CVE-2019-11035; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-5737, CVE-2019-5739; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-5492; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; NetApp HCI Compute Node (Bootstrap OS).
NetApp published this final advisory covering CVE-2019-2632, CVE-2019-2693, CVE-2019-2694, CVE-2019-2695, CVE-2019-2692, CVE-2019-1559, CVE-2019-1559, CVE-2018-3123, CVE-2019-2623, CVE-2018-0734, CVE-2019-2634, CVE-2019-2580, CVE-2019-2585, CVE-2019-2593, CVE-2019-2624, CVE-2019-2628, CVE-2019-2566, CVE-2019-2626, CVE-2019-2644, CVE-2019-2631, CVE-2019-2581, CVE-2019-2596, CVE-2019-2607, CVE-2019-2625, CVE-2019-2681, CVE-2019-2685, CVE-2019-2686, CVE-2019-2687, CVE-2019-2688, CVE-2019-2689, CVE-2019-2683, CVE-2019-2592, CVE-2019-2587, CVE-2019-2635, CVE-2019-2584, CVE-2019-2589, CVE-2019-2606, CVE-2019-2620, CVE-2019-2627, CVE-2019-2691, CVE-2019-2636, CVE-2019-2614, CVE-2019-2617, CVE-2019-2630, CVE-2019-1559; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.
NetApp published this final advisory covering CVE-2019-2699, CVE-2019-2697, CVE-2019-2698, CVE-2019-2602, CVE-2019-2684; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Plug-in for Symantec NetBackup; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).
NetApp published this final advisory covering CVE-2019-0211, CVE-2019-0215, CVE-2019-0217; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager for 7-Mode (core package).
NetApp published this final advisory covering CVE-2019-0199, CVE-2019-0232; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2007-2379, CVE-2010-5312, CVE-2011-4969, CVE-2016-7103; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); SnapCenter.
NetApp published this final advisory covering CVE-2019-9936, CVE-2019-9937; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-12099, CVE-2018-19039; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID Webscale NAS Bridge.
NetApp published this final advisory covering CVE-2018-20406; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-20217; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-18955; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); SnapProtect.
NetApp published this final advisory covering CVE-2018-11767; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-1002105; the API labels exploitation information as **Public**. The API currently lists affected products as: Trident.
NetApp published this final advisory covering CVE-2018-1002101; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-9946, CVE-2019-1002100; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-18849, CVE-2019-6501, CVE-2019-8934; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-6443, CVE-2018-6444, CVE-2018-6445; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Network Advisor Software.
NetApp published this final advisory covering CVE-2019-9924; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.
NetApp published this final advisory covering CVE-2019-7612; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-3880; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-10125, CVE-2019-3874; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.
NetApp published this final advisory covering CVE-2019-3870; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-9857, CVE-2018-19985, CVE-2018-20669, CVE-2019-7222, CVE-2019-7221; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.
NetApp published this final advisory covering CVE-2019-9947, CVE-2019-9948; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-9894, CVE-2019-9895, CVE-2019-9896, CVE-2019-9897; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2017-1000408, CVE-2017-1000409, CVE-2018-6485, CVE-2018-6551, CVE-2018-1000001; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above; Virtual Storage Console for VMware vSphere 9.7 and above.
NetApp published this final advisory covering CVE-2017-18269, CVE-2018-11236, CVE-2018-11237; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; SnapProtect.
NetApp published this final advisory covering CVE-2017-1427, CVE-2017-1428, CVE-2017-1779, CVE-2017-1783, CVE-2017-1784, CVE-2018-1413, CVE-2018-1842; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2019-9898; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager for 7-Mode (core package).
NetApp published this final advisory covering CVE-2018-17794, CVE-2018-17985, CVE-2018-18309, CVE-2018-18483, CVE-2018-18484; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-9003, CVE-2019-9162; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.
NetApp published this final advisory covering CVE-2019-3855, CVE-2019-3856, CVE-2019-3857, CVE-2019-3858, CVE-2019-3859, CVE-2019-3860, CVE-2019-3861, CVE-2019-3862, CVE-2019-3863; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2018-3627; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-3628, CVE-2018-3629, CVE-2018-3632; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-6454; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); SnapProtect.
NetApp published this final advisory covering CVE-2017-3164, CVE-2019-0192; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-9025, CVE-2019-9024, CVE-2019-9023, CVE-2019-9022, CVE-2019-9021, CVE-2019-9020; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-20483; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.
NetApp published this final advisory covering CVE-2018-19591; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Cluster Network Switch (NetApp CN1610); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.
NetApp published this final advisory covering CVE-2018-12201, CVE-2018-12202, CVE-2018-12203, CVE-2018-12204, CVE-2018-12205; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-12185, CVE-2018-12187, CVE-2018-12188, CVE-2018-12189, CVE-2018-12190, CVE-2018-12191, CVE-2018-12192, CVE-2018-12196, CVE-2018-12198, CVE-2018-12199, CVE-2018-12200, CVE-2018-12208; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.
NetApp published this final advisory covering CVE-2018-16890, CVE-2019-3822, CVE-2019-3823; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2019-6977; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-9070, CVE-2019-9071, CVE-2019-9072, CVE-2019-9073, CVE-2019-9074, CVE-2019-9075, CVE-2019-9076, CVE-2019-9077; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.
NetApp published this final advisory covering CVE-2019-1543; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp Plug-in for Symantec NetBackup; SnapProtect.
NetApp published this final advisory covering CVE-2018-18605, CVE-2018-18606, CVE-2018-18607; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-5736; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.
NetApp published this final advisory covering CVE-2019-5489; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.
NetApp published this final advisory covering CVE-2018-8026; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapCenter.
NetApp published this final advisory covering CVE-2018-16888; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.
NetApp published this final advisory covering CVE-2016-4800; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand System Manager 3.x.
NetApp published this final advisory covering CVE-2015-2080; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Management Plug-ins (VMware vCenter); OnCommand System Manager 3.x; Snap Creator Framework.
NetApp published this final advisory covering CVE-2011-4461; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand System Manager 3.x; Snap Creator Framework; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above.
NetApp published this final advisory covering CVE-2019-5490; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; Service Processor.
NetApp published this final advisory covering CVE-2018-5482; the API labels exploitation information as **Not public**. The API currently lists affected products as: SnapCenter.
NetApp published this final advisory covering CVE-2017-15515; the API labels exploitation information as **Not public**. The API currently lists affected products as: SnapCenter.
NetApp published this final advisory covering CVE-2019-5491; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2019-3824; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-16395, CVE-2018-16396; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID Webscale NAS Bridge.
NetApp published this final advisory covering CVE-2018-18311, CVE-2018-18312, CVE-2018-18313, CVE-2018-18314; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; OnCommand Workflow Automation; Snap Creator Framework; SnapCenter.
NetApp published this final advisory covering CVE-2018-19931, CVE-2018-19932, CVE-2018-20002; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere.
NetApp published this final advisory covering CVE-2018-1000656; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2018-20685; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2019-6109, CVE-2019-6110, CVE-2019-6111; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2016-3092, CVE-2016-1000031; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; E-Series SANtricity Web Services (REST API) for Web Services Proxy; Element Plug-in for vCenter Server; OnCommand Plug-in for Microsoft; Snap Creator Framework; SnapCenter.
NetApp published this final advisory covering CVE-2018-16597, CVE-2018-17182; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; SnapProtect.
NetApp published this final advisory covering CVE-2018-1000180, CVE-2018-1000613; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Workflow Automation.
NetApp published this final advisory covering CVE-2018-14634; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapProtect.
NetApp published this final advisory covering CVE-2018-11763; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-0190, CVE-2018-17199, CVE-2018-17189; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-3462; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapProtect.
NetApp published this final advisory covering CVE-2018-5499; the API labels exploitation information as **Public**. The API currently lists affected products as: ATTO FibreBridge.
NetApp published this final advisory covering CVE-2018-10933, CVE-2019-2435, CVE-2018-0732, CVE-2019-2534, CVE-2019-2533, CVE-2019-2529, CVE-2019-2482, CVE-2019-2434, CVE-2019-2455, CVE-2019-2503, CVE-2019-2436, CVE-2018-0734, CVE-2019-2536, CVE-2019-2502, CVE-2019-2510, CVE-2019-2539, CVE-2019-2494, CVE-2019-2495, CVE-2019-2537, CVE-2019-2420, CVE-2019-2481, CVE-2019-2507, CVE-2019-2530, CVE-2019-2528, CVE-2019-2531, CVE-2019-2486, CVE-2019-2532, CVE-2019-2535, CVE-2019-2513, CVE-2018-0732; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.
NetApp published this final advisory covering CVE-2019-2540, CVE-2018-11212, CVE-2019-2426, CVE-2019-2449, CVE-2019-2422; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Plug-in for Symantec NetBackup; OnCommand Insight; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP.
NetApp published this final advisory covering CVE-2018-16864, CVE-2018-16865, CVE-2018-16866; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.
NetApp published this final advisory covering CVE-2018-5498; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2018-5497; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2018-5481; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager for 7-Mode (core package).