Content Library · Advisory

Advisory 2019

Browse 270 2019 NetApp advisory records in the NetApp Black Box content library.

Library JSON API

Advisory

December 2019 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191223-0001/

NetApp published this final advisory covering CVE-2019-19317, CVE-2019-19603, CVE-2019-19645, CVE-2019-19646; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-19118 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191217-0003/

NetApp published this final advisory covering CVE-2019-19118; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-14607 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191217-0002/

NetApp published this final advisory covering CVE-2019-14607; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-11157 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191217-0001/

NetApp published this final advisory covering CVE-2019-11157; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00241 CSME-SPS-TXE-AMT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191213-0001/

NetApp published this final advisory covering CVE-2019-0169, CVE-2019-11132, CVE-2019-11147, CVE-2019-11105, CVE-2019-11088, CVE-2019-11131, CVE-2019-11104, CVE-2019-11097, CVE-2019-11103, CVE-2019-0131, CVE-2019-11090, CVE-2019-0165, CVE-2019-0166, CVE-2019-0168, CVE-2019-11087, CVE-2019-11101, CVE-2019-11100, CVE-2019-11102, CVE-2019-11106, CVE-2019-11107, CVE-2019-11109, CVE-2019-11110, CVE-2019-11086, CVE-2019-11108; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

December 2019 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191210-0002/

NetApp published this final advisory covering CVE-2019-14861, CVE-2019-14870; the API labels exploitation information as **Not public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-1551 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191210-0001/

NetApp published this final advisory covering CVE-2019-1551; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp E-Series Performance Analyzer; NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

November 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191205-0001/

NetApp published this final advisory covering CVE-2019-18680, CVE-2019-18683, CVE-2019-18805, CVE-2019-18807, CVE-2019-18808, CVE-2019-18809, CVE-2019-18810, CVE-2019-18811, CVE-2019-18812, CVE-2019-18813, CVE-2019-18814, CVE-2019-18885, CVE-2019-19036, CVE-2019-19037, CVE-2019-19043, CVE-2019-19044, CVE-2019-19045, CVE-2019-19047, CVE-2019-19048, CVE-2019-19050, CVE-2019-19051, CVE-2019-19052, CVE-2019-19053, CVE-2019-19054, CVE-2019-19056, CVE-2019-19057, CVE-2019-19058, CVE-2019-19059, CVE-2019-19060, CVE-2019-19061, CVE-2019-19062, CVE-2019-19063, CVE-2019-19065, CVE-2019-19066, CVE-2019-19068, CVE-2019-19069, CVE-2019-19071, CVE-2019-19072, CVE-2019-19073, CVE-2019-19074, CVE-2019-19075, CVE-2019-19076, CVE-2019-19077, CVE-2019-19078, CVE-2019-19079, CVE-2019-19080, CVE-2019-19081, CVE-2019-19082, CVE-2019-19083; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

October 2019 PuTTY Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191127-0003/

NetApp published this final advisory covering CVE-2019-17067, CVE-2019-17068, CVE-2019-17069; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager Core Package.

Open source
Advisory

CVE-2019-17592 Nodejs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191127-0002/

NetApp published this final advisory covering CVE-2019-17592; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2019 Ruby Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191122-0003/

NetApp published this final advisory covering CVE-2018-8048, CVE-2019-15587, CVE-2019-15845, CVE-2019-16201, CVE-2019-16254, CVE-2019-16255; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-6477 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191122-0001/

NetApp published this final advisory covering CVE-2019-6477; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-17596 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191122-0005/

NetApp published this final advisory covering CVE-2019-17596; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-21029 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191122-0002/

NetApp published this final advisory covering CVE-2018-21029; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00280 Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191113-0004/

NetApp published this final advisory covering CVE-2019-11136, CVE-2019-11137; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00255 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191113-0001/

NetApp published this final advisory covering CVE-2019-0139, CVE-2019-0140, CVE-2019-0142, CVE-2019-0143, CVE-2019-0144, CVE-2019-0145, CVE-2019-0146, CVE-2019-0147, CVE-2019-0148, CVE-2019-0149, CVE-2019-0150; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

Intel SA-00254 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191113-0008/

NetApp published this final advisory covering CVE-2019-0185; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00240 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191113-0002/

NetApp published this final advisory covering CVE-2019-0151, CVE-2019-0152; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00219 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191113-0006/

NetApp published this final advisory covering CVE-2019-0117; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00210 Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191113-0003/

NetApp published this final advisory covering CVE-2018-12207; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00164 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191113-0007/

NetApp published this final advisory covering CVE-2019-0184; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-18348 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191107-0004/

NetApp published this final advisory covering CVE-2019-18348; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-17514 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191107-0005/

NetApp published this final advisory covering CVE-2019-17514; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2007-2768 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191107-0002/

NetApp published this final advisory covering CVE-2007-2768; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2007-2243 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191107-0003/

NetApp published this interim advisory covering CVE-2007-2243; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2004-1653 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191107-0001/

NetApp published this final advisory covering CVE-2004-1653; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility.

Open source
Advisory

October 2019 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191031-0001/

NetApp published this final advisory covering CVE-2019-10218, CVE-2019-14833; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191031-0005/

NetApp published this final advisory covering CVE-2019-16714, CVE-2019-14814, CVE-2019-14816, CVE-2019-16746, CVE-2019-16994, CVE-2019-16995, CVE-2019-14835, CVE-2019-17133, CVE-2019-17351, CVE-2019-18198, CVE-2019-17666, CVE-2019-2215; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - A320/C190/A220/FAS2720/FAS2750/A800; NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; Service Processor.

Open source
Advisory

CVE-2019-18197 Libxslt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191031-0004/

NetApp published this final advisory covering CVE-2019-18197; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-14847 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191031-0002/

NetApp published this final advisory covering CVE-2019-14847; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-11253 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191031-0006/

NetApp published this final advisory covering CVE-2019-11253; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-11043 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191031-0003/

NetApp published this final advisory covering CVE-2019-11043; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2019 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191024-0004/

NetApp published this final advisory covering CVE-2019-6475, CVE-2019-6476; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

October 2019 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191024-0002/

NetApp published this final advisory covering CVE-2019-17450, CVE-2019-17451; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2019-17359 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191024-0006/

NetApp published this final advisory covering CVE-2019-17359; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; NetApp Service Level Manager; OnCommand API Services; OnCommand Workflow Automation.

Open source
Advisory

CVE-2019-16905 OpenSSH Pre-Auth Integer Overflow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191024-0003/

NetApp published this interim advisory covering CVE-2019-16905; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

October 2019 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191017-0002/

NetApp published this final advisory covering CVE-2019-5443, CVE-2019-2910, CVE-2019-2911, CVE-2019-2914, CVE-2019-2922, CVE-2019-2923, CVE-2019-2924, CVE-2019-2938, CVE-2019-2946, CVE-2019-2948, CVE-2019-2950, CVE-2019-2957, CVE-2019-2960, CVE-2019-2963, CVE-2019-2966, CVE-2019-2967, CVE-2019-2968, CVE-2019-2969, CVE-2019-2974, CVE-2019-2982, CVE-2019-2991, CVE-2019-2993, CVE-2019-2997, CVE-2019-2998, CVE-2019-3003, CVE-2019-3004, CVE-2019-3009, CVE-2019-3011, CVE-2019-3018; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2019 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191017-0001/

NetApp published this final advisory covering CVE-2019-2949, CVE-2019-11068, CVE-2019-2894, CVE-2019-2933, CVE-2019-2945, CVE-2019-2958, CVE-2019-2962, CVE-2019-2964, CVE-2019-2973, CVE-2019-2975, CVE-2019-2977, CVE-2019-2978, CVE-2019-2981, CVE-2019-2983, CVE-2019-2987, CVE-2019-2988, CVE-2019-2989, CVE-2019-2992, CVE-2019-2996, CVE-2019-2999; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; OnCommand Insight; OnCommand Workflow Automation; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

October 2019 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191017-0006/

NetApp published this final advisory covering CVE-2019-16942, CVE-2019-16943, CVE-2019-17267; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; NetApp SteelStore Cloud Integrated Storage; OnCommand API Services; OnCommand Workflow Automation.

Open source
Advisory

CVE-2019-16935 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191017-0004/

NetApp published this final advisory covering CVE-2019-16935; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2019-15138 Nodejs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191017-0005/

NetApp published this final advisory covering CVE-2019-15138; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-14287 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191017-0003/

NetApp published this final advisory covering CVE-2019-14287; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2019-15635 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191009-0002/

NetApp published this final advisory covering CVE-2019-15635; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2019 curl/libcurl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191004-0003/

NetApp published this final advisory covering CVE-2019-5481, CVE-2019-5482; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

September 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191004-0001/

NetApp published this final advisory covering CVE-2019-15666, CVE-2019-15538, CVE-2019-15807, CVE-2018-21008, CVE-2019-15921, CVE-2019-15922, CVE-2019-15923, CVE-2019-15924, CVE-2019-15902, CVE-2019-15916, CVE-2019-15917, CVE-2019-15918, CVE-2019-15919, CVE-2019-15920, CVE-2019-15925, CVE-2019-15926, CVE-2019-15927, CVE-2019-16089, CVE-2019-16229, CVE-2019-16230, CVE-2019-16231, CVE-2019-16232, CVE-2019-16233, CVE-2019-16234, CVE-2019-15031, CVE-2019-15030, CVE-2019-16413, CVE-2019-14821; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - A320/C190/A220/FAS2720/FAS2750/A800; NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

September 2019 Dropbear SSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191004-0006/

NetApp published this final advisory covering CVE-2017-9078, CVE-2017-9079; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2019-15043 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191004-0004/

NetApp published this final advisory covering CVE-2019-15043; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2019-10744 Lodash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20191004-0005/

NetApp published this final advisory covering CVE-2019-10744; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager.

Open source
Advisory

Intel SA-00290 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190926-0001/

NetApp published this final advisory covering CVE-2019-11184; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-16168 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190926-0003/

NetApp published this final advisory covering CVE-2019-16168; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-16056 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190926-0005/

NetApp published this final advisory covering CVE-2019-16056; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-15903 Expat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190926-0004/

NetApp published this final advisory covering CVE-2019-15903; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for VMware vSphere; Clustered Data ONTAP; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; OnCommand Workflow Automation.

Open source
Advisory

CVE-2019-12401 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190926-0002/

NetApp published this final advisory covering CVE-2019-12401; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2019 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190919-0002/

NetApp published this final advisory covering CVE-2019-1547, CVE-2019-1549, CVE-2019-1563; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Data ONTAP operating in 7-Mode; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Service Processor - 8080/8060/8040/8020; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

September 2019 Lodash Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190919-0004/

NetApp published this final advisory covering CVE-2018-3721, CVE-2018-16487, CVE-2019-1010266; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; System Manager 9.x.

Open source
Advisory

September 2019 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190919-0003/

NetApp published this final advisory covering CVE-2019-11245, CVE-2019-11246, CVE-2019-11247, CVE-2019-11248, CVE-2019-11249, CVE-2019-11250; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-11358 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190919-0001/

NetApp published this final advisory covering CVE-2019-11358; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); OnCommand System Manager 3.x; SnapCenter.

Open source
Advisory

CVE-2013-4786 IPMI RAKP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190919-0005/

NetApp published this final advisory covering CVE-2013-4786; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire Baseboard Management Controller (BMC); StorageGRID Baseboard Management Controller (BMC).

Open source
Advisory

September 2019 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190910-0002/

NetApp published this final advisory covering CVE-2019-5608, CVE-2019-5609, CVE-2019-5610, CVE-2019-5611, CVE-2019-5612; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.

Open source
Advisory

CVE-2019-13139 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190910-0001/

NetApp published this final advisory covering CVE-2019-13139; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-8460 OpenBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190905-0001/

NetApp published this final advisory covering CVE-2019-8460; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode.

Open source
Advisory

August 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190905-0002/

NetApp published this final advisory covering CVE-2019-14284, CVE-2019-14283, CVE-2018-20856, CVE-2018-20854, CVE-2018-20855, CVE-2018-20961, CVE-2019-15099, CVE-2019-15090, CVE-2019-15117, CVE-2019-15118, CVE-2019-15098, CVE-2019-10140, CVE-2019-15504, CVE-2019-15292, CVE-2019-15505, CVE-2018-20976, CVE-2019-15211, CVE-2019-15212, CVE-2019-15213, CVE-2019-15214, CVE-2019-15215, CVE-2019-15216, CVE-2019-15217, CVE-2019-15218, CVE-2019-15219, CVE-2019-15220, CVE-2019-15221, CVE-2019-15222, CVE-2019-15223, CVE-2019-15290, CVE-2019-15291, CVE-2018-20856; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-10197 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190903-0001/

NetApp published this final advisory covering CVE-2019-10197; the API labels exploitation information as **Not public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2019 IBM Informix Dynamic Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190903-0002/

NetApp published this final advisory covering CVE-2018-1630, CVE-2018-1631, CVE-2018-1632, CVE-2018-1633, CVE-2018-1634, CVE-2018-1635, CVE-2018-1636, CVE-2018-11796, CVE-2019-4253; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2017 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190830-0003/

NetApp published this final advisory covering CVE-2017-3142, CVE-2017-3143; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; OnCommand Balance.

Open source
Advisory

CVE-2018-5741 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190830-0001/

NetApp published this final advisory covering CVE-2018-5741; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2019 GNU patch Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190828-0001/

NetApp published this final advisory covering CVE-2019-13636, CVE-2019-13638; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above.

Open source
Advisory

August 2019 Docker Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190828-0003/

NetApp published this final advisory covering CVE-2019-14271, CVE-2019-13509; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2019 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190828-0002/

NetApp published this final advisory covering CVE-2019-14232, CVE-2019-14233, CVE-2019-14234, CVE-2019-14235; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

August 2019 Apache Tika Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190828-0004/

NetApp published this final advisory covering CVE-2019-10088, CVE-2019-10093, CVE-2019-10094; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-9517 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190823-0003/

NetApp published this final advisory covering CVE-2019-9517; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-1552 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190823-0006/

NetApp published this final advisory covering CVE-2019-1552; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Antivirus Connector; OnCommand Unified Manager Core Package; OnCommand Workflow Automation.

Open source
Advisory

August 2019 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190823-0005/

NetApp published this final advisory covering CVE-2019-9511, CVE-2019-9512, CVE-2019-9513, CVE-2019-9514, CVE-2019-9515, CVE-2019-9516, CVE-2019-9517, CVE-2019-9518; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapCenter.

Open source
Advisory

August 2019 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190823-0002/

NetApp published this final advisory covering CVE-2019-9511, CVE-2019-9513, CVE-2019-9516; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

August 2019 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190823-0001/

NetApp published this final advisory covering CVE-2019-9512, CVE-2019-9514; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2019 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190823-0004/

NetApp published this final advisory covering CVE-2019-9512, CVE-2019-9514; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent; Trident.

Open source
Advisory

CVE-2019-13057 OpenLDAP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190822-0004/

NetApp published this final advisory covering CVE-2019-13057; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2019 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190822-0003/

NetApp published this final advisory covering CVE-2019-11041, CVE-2019-11042; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2019 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190822-0002/

NetApp published this final advisory covering CVE-2019-14250, CVE-2019-14444; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

February 2019 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190814-0004/

NetApp published this final advisory covering CVE-2018-5744, CVE-2018-5745, CVE-2019-6465; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-13232 Info-ZIP UnZip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190814-0002/

NetApp published this final advisory covering CVE-2019-13232; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node.

Open source
Advisory

August 2019 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190814-0003/

NetApp published this final advisory covering CVE-2019-5603, CVE-2019-5604, CVE-2019-5605, CVE-2019-5606, CVE-2019-5607; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2019 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190814-0001/

NetApp published this final advisory covering CVE-2019-14379, CVE-2019-14439; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; NetApp Service Level Manager; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2019-1125 SWAPGS Speculative Execution Side Channel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190809-0002/

NetApp published this final advisory covering CVE-2019-1125; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility.

Open source
Advisory

July 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190806-0001/

NetApp published this final advisory covering CVE-2019-12984, CVE-2019-13233, CVE-2019-10638, CVE-2019-10639, CVE-2019-13631, CVE-2019-13272, CVE-2019-13648; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Service Processor - 8080/8060/8040/8020; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

July 2019 Libxslt Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190806-0004/

NetApp published this final advisory covering CVE-2019-13117, CVE-2019-13118; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-13115 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190806-0002/

NetApp published this final advisory covering CVE-2019-13115; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

August 2019 VxWorks TCP/IP Stack (IPNET) Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190802-0001/

NetApp published this final advisory covering CVE-2019-12256, CVE-2019-12257, CVE-2019-12255, CVE-2019-12260, CVE-2019-12261, CVE-2019-12263, CVE-2019-12258, CVE-2019-12259, CVE-2019-12262, CVE-2019-12264, CVE-2019-12265; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 8.x.

Open source
Advisory

December 2014 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190730-0002/

NetApp published this final advisory covering CVE-2014-8500, CVE-2014-8680; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190719-0003/

NetApp published this final advisory covering CVE-2018-20836, CVE-2019-11810, CVE-2019-11811, CVE-2019-11815; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Cluster Network Switch (NetApp CN1610); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 7.2 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 7.2 and above; Virtual Storage Console for VMware vSphere 7.2 and above.

Open source
Advisory

July 2019 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190719-0004/

NetApp published this final advisory covering CVE-2019-3822, CVE-2019-2822, CVE-2019-2800, CVE-2019-2795, CVE-2019-2746, CVE-2019-2812, CVE-2019-2834, CVE-2019-2805, CVE-2019-2740, CVE-2019-2758, CVE-2019-2819, CVE-2019-2731, CVE-2019-2778, CVE-2019-2741, CVE-2019-2743, CVE-2019-2739, CVE-2019-2785, CVE-2019-2798, CVE-2019-2879, CVE-2019-2737, CVE-2019-2780, CVE-2019-2784, CVE-2019-2801, CVE-2019-2747, CVE-2019-2757, CVE-2019-2774, CVE-2019-2796, CVE-2019-2802, CVE-2019-2803, CVE-2019-2808, CVE-2019-2810, CVE-2019-2815, CVE-2019-2830, CVE-2019-2752, CVE-2019-2755, CVE-2019-2811, CVE-2019-2826, CVE-2019-2797, CVE-2019-2791, CVE-2019-2738, CVE-2019-2730, CVE-2019-2789, CVE-2019-2814; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2019 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190719-0005/

NetApp published this final advisory covering CVE-2019-2745, CVE-2019-2762, CVE-2019-2766, CVE-2019-2769, CVE-2019-2786, CVE-2019-2816, CVE-2019-2818, CVE-2019-2821, CVE-2019-2842, CVE-2019-7317; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; OnCommand Insight; OnCommand Workflow Automation; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2018-14404 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190719-0002/

NetApp published this final advisory covering CVE-2018-14404; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility.

Open source
Advisory

April 2018 Libxml2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190719-0001/

NetApp published this final advisory covering CVE-2017-5130, CVE-2017-18258; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Data ONTAP Edge; NetApp Manageability SDK; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix.

Open source
Advisory

CVE-2018-20801 Highcharts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190715-0001/

NetApp published this final advisory covering CVE-2018-20801; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

June 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190710-0002/

NetApp published this final advisory covering CVE-2019-12380, CVE-2019-12379, CVE-2019-12455, CVE-2019-12614, CVE-2019-12615, CVE-2019-3846, CVE-2019-12819, CVE-2019-12818, CVE-2019-10126, CVE-2019-12881, CVE-2019-3896; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-13068 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190710-0001/

NetApp published this final advisory covering CVE-2019-13068; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

July 2019 Libvirt Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190705-0001/

NetApp published this final advisory covering CVE-2019-10161, CVE-2019-10166, CVE-2019-10167, CVE-2019-10168; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-12781 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190705-0002/

NetApp published this final advisory covering CVE-2019-12781; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-12384 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190703-0002/

NetApp published this final advisory covering CVE-2019-12384; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; NetApp SANtricity Cloud Connector; NetApp Service Level Manager; OnCommand Workflow Automation.

Open source
Advisory

CVE-2018-20843 Expat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190703-0001/

NetApp published this final advisory covering CVE-2018-20843; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand Workflow Automation; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

Linux Kernel TCP SACK Panic Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0001/

NetApp published this final advisory covering CVE-2019-11477, CVE-2019-11478, CVE-2019-11479; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A320/C190/A220/FAS2720/FAS2750/A800; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; Service Processor; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2019-6471 ISC Bind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0003/

NetApp published this final advisory covering CVE-2019-6471; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-5599 FreeBSD TCP SACK Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0004/

NetApp published this final advisory covering CVE-2019-5599; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-12875 Alpine Linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0005/

NetApp published this final advisory covering CVE-2019-12875; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-12814 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0006/

NetApp published this final advisory covering CVE-2019-12814; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; NetApp SteelStore Cloud Integrated Storage; SnapCenter.

Open source
Advisory

CVE-2019-10072 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0002/

NetApp published this final advisory covering CVE-2019-10072; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 Systemd Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0002/

NetApp published this final advisory covering CVE-2019-3843, CVE-2019-3844; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

June 2019 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0006/

NetApp published this final advisory covering CVE-2019-12435, CVE-2019-12436; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-9740 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0005/

NetApp published this final advisory covering CVE-2019-9740; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-3829 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0004/

NetApp published this final advisory covering CVE-2019-3829; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 7.2 and above.

Open source
Advisory

CVE-2019-0201 Apache ZooKeeper Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0001/

NetApp published this interim advisory covering CVE-2019-0201; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2018-11802 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0003/

NetApp published this final advisory covering CVE-2018-11802; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2019 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190617-0002/

NetApp published this final advisory covering CVE-2019-0196, CVE-2019-0197; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-10160 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190617-0003/

NetApp published this final advisory covering CVE-2019-10160; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Converged Systems Advisor Agent.

Open source
Advisory

CVE-2018-8029 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190617-0001/

NetApp published this final advisory covering CVE-2018-8029; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00247 Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190612-0001/

NetApp published this final advisory covering CVE-2019-0174; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190611-0001/

NetApp published this final advisory covering CVE-2019-5597, CVE-2019-5598; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-9628 XMLTooling Library Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190611-0003/

NetApp published this final advisory covering CVE-2019-9628; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 curl/libcurl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190606-0004/

NetApp published this final advisory covering CVE-2019-5435, CVE-2019-5436; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-8457 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190606-0002/

NetApp published this final advisory covering CVE-2019-8457; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2019-12450 GNOME GLib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190606-0003/

NetApp published this final advisory covering CVE-2019-12450; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190530-0003/

NetApp published this final advisory covering CVE-2018-11307, CVE-2018-12022, CVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-14720, CVE-2018-14721, CVE-2018-19360, CVE-2018-19361, CVE-2018-19362, CVE-2019-12086; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2018-20839 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190530-0002/

NetApp published this final advisory covering CVE-2018-20839; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2018-1000632 Dom4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190530-0001/

NetApp published this final advisory covering CVE-2018-1000632; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand System Manager 3.x; OnCommand Workflow Automation; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2019-5018 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190521-0001/

NetApp published this final advisory covering CVE-2019-5018; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 7th 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190517-0002/

NetApp published this final advisory covering CVE-2018-20509, CVE-2019-11599, CVE-2019-11683; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

May 2019 Wildfly Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190517-0004/

NetApp published this final advisory covering CVE-2019-3805, CVE-2019-3894; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190517-0005/

NetApp published this final advisory covering CVE-2019-11486, CVE-2019-11487, CVE-2019-3882, CVE-2019-3900, CVE-2019-3901; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2019-9636 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190517-0001/

NetApp published this final advisory covering CVE-2019-9636; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-11036 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190517-0003/

NetApp published this final advisory covering CVE-2019-11036; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00223 UEFI Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190516-0001/

NetApp published this final advisory covering CVE-2019-0119, CVE-2019-0120, CVE-2019-0126; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00233 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190515-0001/

NetApp published this final advisory covering CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SteelStore Cloud Integrated Storage; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

Intel SA-00213 Platform Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190515-0002/

NetApp published this final advisory covering CVE-2019-0089, CVE-2019-0090, CVE-2019-0086, CVE-2019-0091, CVE-2019-0092, CVE-2019-0093, CVE-2019-0094, CVE-2019-0096, CVE-2019-0097, CVE-2019-0098, CVE-2019-0099, CVE-2019-0153, CVE-2019-0170; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2018-16860 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190514-0001/

NetApp published this final advisory covering CVE-2018-16860; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190514-0002/

NetApp published this final advisory covering CVE-2018-5743, CVE-2019-6467, CVE-2019-6468; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-5021 Alpine Linux Docker Image Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190510-0001/

NetApp published this final advisory covering CVE-2019-5021; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Missing HTTP Security Headers in OnCommand Unified Manager for VMware vSphere, Linux and Windows 7.3 and above

Source: https://security.netapp.com/advisory/NTAP-20190509-0007/

NetApp published this final advisory covering CVE-2019-5495; the API labels exploitation information as **Not public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above.

Open source
Advisory

Missing HTTP Security Headers in OnCommand Insight

Source: https://security.netapp.com/advisory/NTAP-20190509-0005/

NetApp published this final advisory covering CVE-2019-5496; the API labels exploitation information as **Not public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2019-5953 GNU Wget Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190509-0001/

NetApp published this final advisory covering CVE-2019-5953; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

April 2019 Eclipse Jetty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190509-0003/

NetApp published this final advisory covering CVE-2019-10241, CVE-2019-10246, CVE-2019-10247; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand System Manager 3.x; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

March 2019 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0007/

NetApp published this final advisory covering CVE-2019-9637, CVE-2019-9638, CVE-2019-9639, CVE-2019-9640, CVE-2019-9641; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-9193 PostgreSQL in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0003/

NetApp published this final advisory covering CVE-2019-9193; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-3836 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0005/

NetApp published this final advisory covering CVE-2019-3836; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-0222 Apache ActiveMQ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0006/

NetApp published this final advisory covering CVE-2019-0222; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Web Services (REST API) for Web Services Proxy.

Open source
Advisory

CVE-2018-20449 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0002/

NetApp published this final advisory covering CVE-2018-20449; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2018-16984 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0009/

NetApp published this final advisory covering CVE-2018-16984; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

April 2019 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0004/

NetApp published this final advisory covering CVE-2018-20505, CVE-2018-20506; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0001/

NetApp published this final advisory covering CVE-2019-11034, CVE-2019-11035; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0008/

NetApp published this final advisory covering CVE-2019-5737, CVE-2019-5739; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190423-0002/

NetApp published this final advisory covering CVE-2019-2632, CVE-2019-2693, CVE-2019-2694, CVE-2019-2695, CVE-2019-2692, CVE-2019-1559, CVE-2019-1559, CVE-2018-3123, CVE-2019-2623, CVE-2018-0734, CVE-2019-2634, CVE-2019-2580, CVE-2019-2585, CVE-2019-2593, CVE-2019-2624, CVE-2019-2628, CVE-2019-2566, CVE-2019-2626, CVE-2019-2644, CVE-2019-2631, CVE-2019-2581, CVE-2019-2596, CVE-2019-2607, CVE-2019-2625, CVE-2019-2681, CVE-2019-2685, CVE-2019-2686, CVE-2019-2687, CVE-2019-2688, CVE-2019-2689, CVE-2019-2683, CVE-2019-2592, CVE-2019-2587, CVE-2019-2635, CVE-2019-2584, CVE-2019-2589, CVE-2019-2606, CVE-2019-2620, CVE-2019-2627, CVE-2019-2691, CVE-2019-2636, CVE-2019-2614, CVE-2019-2617, CVE-2019-2630, CVE-2019-1559; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2019 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190423-0003/

NetApp published this final advisory covering CVE-2019-2699, CVE-2019-2697, CVE-2019-2698, CVE-2019-2602, CVE-2019-2684; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Plug-in for Symantec NetBackup; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

April 2019 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190423-0001/

NetApp published this final advisory covering CVE-2019-0211, CVE-2019-0215, CVE-2019-0217; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager for 7-Mode (core package).

Open source
Advisory

April 2019 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190419-0001/

NetApp published this final advisory covering CVE-2019-0199, CVE-2019-0232; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2018 jQuery Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0007/

NetApp published this final advisory covering CVE-2007-2379, CVE-2010-5312, CVE-2011-4969, CVE-2016-7103; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); SnapCenter.

Open source
Advisory

March 2019 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0005/

NetApp published this final advisory covering CVE-2019-9936, CVE-2019-9937; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2018 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0004/

NetApp published this final advisory covering CVE-2018-12099, CVE-2018-19039; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID Webscale NAS Bridge.

Open source
Advisory

CVE-2018-20406 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0010/

NetApp published this final advisory covering CVE-2018-20406; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-20217 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0006/

NetApp published this final advisory covering CVE-2018-20217; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-11767 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0009/

NetApp published this final advisory covering CVE-2018-11767; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-1002101 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0008/

NetApp published this final advisory covering CVE-2018-1002101; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0002/

NetApp published this final advisory covering CVE-2019-9946, CVE-2019-1002100; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2019 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190411-0006/

NetApp published this final advisory covering CVE-2018-18849, CVE-2019-6501, CVE-2019-8934; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-9924 GNU Bash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190411-0001/

NetApp published this final advisory covering CVE-2019-9924; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2019-7612 Logstash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190411-0002/

NetApp published this final advisory covering CVE-2019-7612; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-3880 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190411-0004/

NetApp published this final advisory covering CVE-2019-3880; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190411-0003/

NetApp published this final advisory covering CVE-2019-10125, CVE-2019-3874; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2019-3870 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190408-0001/

NetApp published this final advisory covering CVE-2019-3870; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 27th 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190404-0002/

NetApp published this final advisory covering CVE-2019-9857, CVE-2018-19985, CVE-2018-20669, CVE-2019-7222, CVE-2019-7221; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

March 2019 Python Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190404-0004/

NetApp published this final advisory covering CVE-2019-9947, CVE-2019-9948; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2019 PuTTY Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190404-0001/

NetApp published this final advisory covering CVE-2019-9894, CVE-2019-9895, CVE-2019-9896, CVE-2019-9897; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2018 GNU C Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190404-0003/

NetApp published this final advisory covering CVE-2017-1000408, CVE-2017-1000409, CVE-2018-6485, CVE-2018-6551, CVE-2018-1000001; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

May 2018 GNU C Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190401-0001/

NetApp published this final advisory covering CVE-2017-18269, CVE-2018-11236, CVE-2018-11237; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

December 2018 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190401-0003/

NetApp published this final advisory covering CVE-2017-1427, CVE-2017-1428, CVE-2017-1779, CVE-2017-1783, CVE-2017-1784, CVE-2018-1413, CVE-2018-1842; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2019-9898 PuTTY Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190401-0002/

NetApp published this final advisory covering CVE-2019-9898; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager for 7-Mode (core package).

Open source
Advisory

October 2018 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0007/

NetApp published this final advisory covering CVE-2018-17794, CVE-2018-17985, CVE-2018-18309, CVE-2018-18483, CVE-2018-18484; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0002/

NetApp published this final advisory covering CVE-2019-9003, CVE-2019-9162; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

March 2019 Libssh2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0005/

NetApp published this final advisory covering CVE-2019-3855, CVE-2019-3856, CVE-2019-3857, CVE-2019-3858, CVE-2019-3859, CVE-2019-3860, CVE-2019-3861, CVE-2019-3862, CVE-2019-3863; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

Intel SA-00112 Active Management Technology Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0001/

NetApp published this final advisory covering CVE-2018-3628, CVE-2018-3629, CVE-2018-3632; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-6454 systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0004/

NetApp published this final advisory covering CVE-2019-6454; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); SnapProtect.

Open source
Advisory

CVE-2017-3164 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0003/

NetApp published this final advisory covering CVE-2017-3164, CVE-2019-0192; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2019 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190321-0001/

NetApp published this final advisory covering CVE-2019-9025, CVE-2019-9024, CVE-2019-9023, CVE-2019-9022, CVE-2019-9021, CVE-2019-9020; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-20483 GNU Wget Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190321-0002/

NetApp published this final advisory covering CVE-2018-20483; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2018-19591 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190321-0003/

NetApp published this final advisory covering CVE-2018-19591; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Cluster Network Switch (NetApp CN1610); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

Intel SA-00191 Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190318-0002/

NetApp published this final advisory covering CVE-2018-12201, CVE-2018-12202, CVE-2018-12203, CVE-2018-12204, CVE-2018-12205; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00185 CSME-SPS-TXE-AMT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190318-0001/

NetApp published this final advisory covering CVE-2018-12185, CVE-2018-12187, CVE-2018-12188, CVE-2018-12189, CVE-2018-12190, CVE-2018-12191, CVE-2018-12192, CVE-2018-12196, CVE-2018-12198, CVE-2018-12199, CVE-2018-12200, CVE-2018-12208; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

March 2019 GNU C Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190315-0002/

NetApp published this final advisory covering CVE-2009-5155, CVE-2018-20796, CVE-2019-9169; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Cluster Network Switch (NetApp CN1610); NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility; SnapProtect.

Open source
Advisory

CVE-2019-6977 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190315-0003/

NetApp published this final advisory covering CVE-2019-6977; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2019 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190314-0003/

NetApp published this final advisory covering CVE-2019-9070, CVE-2019-9071, CVE-2019-9072, CVE-2019-9073, CVE-2019-9074, CVE-2019-9075, CVE-2019-9076, CVE-2019-9077; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2019-6260 ASPEED BMC Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190314-0001/

NetApp published this final advisory covering CVE-2019-6260; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A320/C190/A220/FAS2720/FAS2750/A800; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-1543 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190314-0002/

NetApp published this final advisory covering CVE-2019-1543; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp Plug-in for Symantec NetBackup; SnapProtect.

Open source
Advisory

November 2018 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190307-0003/

NetApp published this final advisory covering CVE-2018-18605, CVE-2018-18606, CVE-2018-18607; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-5489 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190307-0001/

NetApp published this final advisory covering CVE-2019-5489; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2018-16888 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190307-0007/

NetApp published this final advisory covering CVE-2018-16888; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2015-2080 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190307-0005/

NetApp published this final advisory covering CVE-2015-2080; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Management Plug-ins (VMware vCenter); OnCommand System Manager 3.x; Snap Creator Framework.

Open source
Advisory

CVE-2011-4461 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190307-0004/

NetApp published this final advisory covering CVE-2011-4461; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand System Manager 3.x; Snap Creator Framework; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2019-1559 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190301-0001/

NetApp published this final advisory covering CVE-2019-1559; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Service Processor - 8080/8060/8040/8020; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS); NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2019-3824 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190226-0001/

NetApp published this final advisory covering CVE-2019-3824; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2018 Ruby Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190221-0002/

NetApp published this final advisory covering CVE-2018-16395, CVE-2018-16396; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID Webscale NAS Bridge.

Open source
Advisory

December 2018 PERL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190221-0003/

NetApp published this final advisory covering CVE-2018-18311, CVE-2018-18312, CVE-2018-18313, CVE-2018-18314; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; OnCommand Workflow Automation; Snap Creator Framework; SnapCenter.

Open source
Advisory

December 2018 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190221-0004/

NetApp published this final advisory covering CVE-2018-19931, CVE-2018-19932, CVE-2018-20002; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere.

Open source
Advisory

CVE-2018-1000656 Flask Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190221-0001/

NetApp published this final advisory covering CVE-2018-1000656; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2018-20685 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190215-0001/

NetApp published this final advisory covering CVE-2018-20685; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility.

Open source
Advisory

January 2019 OpenSSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190213-0001/

NetApp published this final advisory covering CVE-2019-6109, CVE-2019-6110, CVE-2019-6111; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility.

Open source
Advisory

November 2017 Apache Commons FileUpload Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190212-0001/

NetApp published this final advisory covering CVE-2016-3092, CVE-2016-1000031; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; E-Series SANtricity Web Services (REST API) for Web Services Proxy; Element Plug-in for vCenter Server; OnCommand Plug-in for Microsoft; Snap Creator Framework; SnapCenter.

Open source
Advisory

CVE-2016-6210 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190206-0001/

NetApp published this final advisory covering CVE-2016-6210; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP Edge; Data ONTAP operating in 7-Mode; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 6.x; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager Core Package; OnCommand Unified Manager for Clustered Data ONTAP; Service Processor; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

September 2018 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190204-0001/

NetApp published this final advisory covering CVE-2018-16597, CVE-2018-17182; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2018-11763 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190204-0004/

NetApp published this final advisory covering CVE-2018-11763; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2019 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190125-0001/

NetApp published this final advisory covering CVE-2019-0190, CVE-2018-17199, CVE-2018-17189; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-3462 APT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190125-0002/

NetApp published this final advisory covering CVE-2019-3462; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapProtect.

Open source
Advisory

January 2019 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190118-0002/

NetApp published this final advisory covering CVE-2018-10933, CVE-2019-2435, CVE-2018-0732, CVE-2019-2534, CVE-2019-2533, CVE-2019-2529, CVE-2019-2482, CVE-2019-2434, CVE-2019-2455, CVE-2019-2503, CVE-2019-2436, CVE-2018-0734, CVE-2019-2536, CVE-2019-2502, CVE-2019-2510, CVE-2019-2539, CVE-2019-2494, CVE-2019-2495, CVE-2019-2537, CVE-2019-2420, CVE-2019-2481, CVE-2019-2507, CVE-2019-2530, CVE-2019-2528, CVE-2019-2531, CVE-2019-2486, CVE-2019-2532, CVE-2019-2535, CVE-2019-2513, CVE-2018-0732; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2019 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190118-0001/

NetApp published this final advisory covering CVE-2019-2540, CVE-2018-11212, CVE-2019-2426, CVE-2019-2449, CVE-2019-2422; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Plug-in for Symantec NetBackup; OnCommand Insight; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

January 2019 Systemd-journald Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190117-0001/

NetApp published this final advisory covering CVE-2018-16864, CVE-2018-16865, CVE-2018-16866; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source