Content Library · Advisory

Advisory 2019

Browse 270 2019 NetApp advisory records in the NetApp Black Box content library. Page 2 of 3.

Library JSON API

Showing all 120 items on this page

Advisory

July 2019 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190719-0005/

NetApp published this final advisory covering CVE-2019-2745, CVE-2019-2762, CVE-2019-2766, CVE-2019-2769, CVE-2019-2786, CVE-2019-2816, CVE-2019-2818, CVE-2019-2821, CVE-2019-2842, CVE-2019-7317; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; OnCommand Insight; OnCommand Workflow Automation; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2018-14404 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190719-0002/

NetApp published this final advisory covering CVE-2018-14404; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility.

Open source
Advisory

April 2018 Libxml2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190719-0001/

NetApp published this final advisory covering CVE-2017-5130, CVE-2017-18258; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Data ONTAP Edge; NetApp Manageability SDK; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix.

Open source
Advisory

CVE-2018-20801 Highcharts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190715-0001/

NetApp published this final advisory covering CVE-2018-20801; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

June 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190710-0002/

NetApp published this final advisory covering CVE-2019-12380, CVE-2019-12379, CVE-2019-12455, CVE-2019-12614, CVE-2019-12615, CVE-2019-3846, CVE-2019-12819, CVE-2019-12818, CVE-2019-10126, CVE-2019-12881, CVE-2019-3896; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-13068 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190710-0001/

NetApp published this final advisory covering CVE-2019-13068; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

July 2019 Libvirt Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190705-0001/

NetApp published this final advisory covering CVE-2019-10161, CVE-2019-10166, CVE-2019-10167, CVE-2019-10168; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-12781 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190705-0002/

NetApp published this final advisory covering CVE-2019-12781; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-12384 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190703-0002/

NetApp published this final advisory covering CVE-2019-12384; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; NetApp SANtricity Cloud Connector; NetApp Service Level Manager; OnCommand Workflow Automation.

Open source
Advisory

CVE-2018-20843 Expat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190703-0001/

NetApp published this final advisory covering CVE-2018-20843; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand Workflow Automation; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

Linux Kernel TCP SACK Panic Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0001/

NetApp published this final advisory covering CVE-2019-11477, CVE-2019-11478, CVE-2019-11479; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A320/C190/A220/FAS2720/FAS2750/A800; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; Service Processor; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior); Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2019-6471 ISC Bind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0003/

NetApp published this final advisory covering CVE-2019-6471; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-5599 FreeBSD TCP SACK Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0004/

NetApp published this final advisory covering CVE-2019-5599; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-12875 Alpine Linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0005/

NetApp published this final advisory covering CVE-2019-12875; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-12814 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0006/

NetApp published this final advisory covering CVE-2019-12814; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; NetApp SteelStore Cloud Integrated Storage; SnapCenter.

Open source
Advisory

CVE-2019-10072 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190625-0002/

NetApp published this final advisory covering CVE-2019-10072; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 Systemd Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0002/

NetApp published this final advisory covering CVE-2019-3843, CVE-2019-3844; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

June 2019 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0006/

NetApp published this final advisory covering CVE-2019-12435, CVE-2019-12436; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-9740 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0005/

NetApp published this final advisory covering CVE-2019-9740; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-3829 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0004/

NetApp published this final advisory covering CVE-2019-3829; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 7.2 and above.

Open source
Advisory

CVE-2019-0201 Apache ZooKeeper Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0001/

NetApp published this interim advisory covering CVE-2019-0201; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2018-11802 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190619-0003/

NetApp published this final advisory covering CVE-2018-11802; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2019 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190617-0002/

NetApp published this final advisory covering CVE-2019-0196, CVE-2019-0197; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-10160 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190617-0003/

NetApp published this final advisory covering CVE-2019-10160; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Converged Systems Advisor Agent.

Open source
Advisory

CVE-2018-8029 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190617-0001/

NetApp published this final advisory covering CVE-2018-8029; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00247 Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190612-0001/

NetApp published this final advisory covering CVE-2019-0174; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190611-0001/

NetApp published this final advisory covering CVE-2019-5597, CVE-2019-5598; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-9628 XMLTooling Library Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190611-0003/

NetApp published this final advisory covering CVE-2019-9628; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 curl/libcurl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190606-0004/

NetApp published this final advisory covering CVE-2019-5435, CVE-2019-5436; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-8457 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190606-0002/

NetApp published this final advisory covering CVE-2019-8457; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2019-12450 GNOME GLib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190606-0003/

NetApp published this final advisory covering CVE-2019-12450; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190530-0003/

NetApp published this final advisory covering CVE-2018-11307, CVE-2018-12022, CVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-14720, CVE-2018-14721, CVE-2018-19360, CVE-2018-19361, CVE-2018-19362, CVE-2019-12086; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2018-20839 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190530-0002/

NetApp published this final advisory covering CVE-2018-20839; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2018-1000632 Dom4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190530-0001/

NetApp published this final advisory covering CVE-2018-1000632; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand System Manager 3.x; OnCommand Workflow Automation; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2019-5018 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190521-0001/

NetApp published this final advisory covering CVE-2019-5018; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 7th 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190517-0002/

NetApp published this final advisory covering CVE-2018-20509, CVE-2019-11599, CVE-2019-11683; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

May 2019 Wildfly Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190517-0004/

NetApp published this final advisory covering CVE-2019-3805, CVE-2019-3894; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190517-0005/

NetApp published this final advisory covering CVE-2019-11486, CVE-2019-11487, CVE-2019-3882, CVE-2019-3900, CVE-2019-3901; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2019-9636 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190517-0001/

NetApp published this final advisory covering CVE-2019-9636; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-11036 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190517-0003/

NetApp published this final advisory covering CVE-2019-11036; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00223 UEFI Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190516-0001/

NetApp published this final advisory covering CVE-2019-0119, CVE-2019-0120, CVE-2019-0126; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00233 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190515-0001/

NetApp published this final advisory covering CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SteelStore Cloud Integrated Storage; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

Intel SA-00213 Platform Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190515-0002/

NetApp published this final advisory covering CVE-2019-0089, CVE-2019-0090, CVE-2019-0086, CVE-2019-0091, CVE-2019-0092, CVE-2019-0093, CVE-2019-0094, CVE-2019-0096, CVE-2019-0097, CVE-2019-0098, CVE-2019-0099, CVE-2019-0153, CVE-2019-0170; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2018-16860 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190514-0001/

NetApp published this final advisory covering CVE-2018-16860; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190514-0002/

NetApp published this final advisory covering CVE-2018-5743, CVE-2019-6467, CVE-2019-6468; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-5021 Alpine Linux Docker Image Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190510-0001/

NetApp published this final advisory covering CVE-2019-5021; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Missing HTTP Security Headers in OnCommand Unified Manager for VMware vSphere, Linux and Windows 7.3 and above

Source: https://security.netapp.com/advisory/NTAP-20190509-0007/

NetApp published this final advisory covering CVE-2019-5495; the API labels exploitation information as **Not public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above.

Open source
Advisory

Missing HTTP Security Headers in OnCommand Insight

Source: https://security.netapp.com/advisory/NTAP-20190509-0005/

NetApp published this final advisory covering CVE-2019-5496; the API labels exploitation information as **Not public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2019-5953 GNU Wget Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190509-0001/

NetApp published this final advisory covering CVE-2019-5953; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

April 2019 Eclipse Jetty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190509-0003/

NetApp published this final advisory covering CVE-2019-10241, CVE-2019-10246, CVE-2019-10247; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand System Manager 3.x; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

March 2019 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0007/

NetApp published this final advisory covering CVE-2019-9637, CVE-2019-9638, CVE-2019-9639, CVE-2019-9640, CVE-2019-9641; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-9193 PostgreSQL in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0003/

NetApp published this final advisory covering CVE-2019-9193; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-3836 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0005/

NetApp published this final advisory covering CVE-2019-3836; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-0222 Apache ActiveMQ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0006/

NetApp published this final advisory covering CVE-2019-0222; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Web Services (REST API) for Web Services Proxy.

Open source
Advisory

CVE-2018-20449 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0002/

NetApp published this final advisory covering CVE-2018-20449; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2018-16984 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0009/

NetApp published this final advisory covering CVE-2018-16984; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

April 2019 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0004/

NetApp published this final advisory covering CVE-2018-20505, CVE-2018-20506; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0001/

NetApp published this final advisory covering CVE-2019-11034, CVE-2019-11035; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190502-0008/

NetApp published this final advisory covering CVE-2019-5737, CVE-2019-5739; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190423-0002/

NetApp published this final advisory covering CVE-2019-2632, CVE-2019-2693, CVE-2019-2694, CVE-2019-2695, CVE-2019-2692, CVE-2019-1559, CVE-2019-1559, CVE-2018-3123, CVE-2019-2623, CVE-2018-0734, CVE-2019-2634, CVE-2019-2580, CVE-2019-2585, CVE-2019-2593, CVE-2019-2624, CVE-2019-2628, CVE-2019-2566, CVE-2019-2626, CVE-2019-2644, CVE-2019-2631, CVE-2019-2581, CVE-2019-2596, CVE-2019-2607, CVE-2019-2625, CVE-2019-2681, CVE-2019-2685, CVE-2019-2686, CVE-2019-2687, CVE-2019-2688, CVE-2019-2689, CVE-2019-2683, CVE-2019-2592, CVE-2019-2587, CVE-2019-2635, CVE-2019-2584, CVE-2019-2589, CVE-2019-2606, CVE-2019-2620, CVE-2019-2627, CVE-2019-2691, CVE-2019-2636, CVE-2019-2614, CVE-2019-2617, CVE-2019-2630, CVE-2019-1559; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2019 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190423-0003/

NetApp published this final advisory covering CVE-2019-2699, CVE-2019-2697, CVE-2019-2698, CVE-2019-2602, CVE-2019-2684; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Plug-in for Symantec NetBackup; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

April 2019 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190423-0001/

NetApp published this final advisory covering CVE-2019-0211, CVE-2019-0215, CVE-2019-0217; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager for 7-Mode (core package).

Open source
Advisory

April 2019 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190419-0001/

NetApp published this final advisory covering CVE-2019-0199, CVE-2019-0232; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2018 jQuery Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0007/

NetApp published this final advisory covering CVE-2007-2379, CVE-2010-5312, CVE-2011-4969, CVE-2016-7103; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); SnapCenter.

Open source
Advisory

March 2019 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0005/

NetApp published this final advisory covering CVE-2019-9936, CVE-2019-9937; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2018 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0004/

NetApp published this final advisory covering CVE-2018-12099, CVE-2018-19039; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID Webscale NAS Bridge.

Open source
Advisory

CVE-2018-20406 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0010/

NetApp published this final advisory covering CVE-2018-20406; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-20217 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0006/

NetApp published this final advisory covering CVE-2018-20217; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-11767 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0009/

NetApp published this final advisory covering CVE-2018-11767; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-1002101 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0008/

NetApp published this final advisory covering CVE-2018-1002101; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190416-0002/

NetApp published this final advisory covering CVE-2019-9946, CVE-2019-1002100; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2019 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190411-0006/

NetApp published this final advisory covering CVE-2018-18849, CVE-2019-6501, CVE-2019-8934; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-9924 GNU Bash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190411-0001/

NetApp published this final advisory covering CVE-2019-9924; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2019-7612 Logstash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190411-0002/

NetApp published this final advisory covering CVE-2019-7612; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-3880 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190411-0004/

NetApp published this final advisory covering CVE-2019-3880; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190411-0003/

NetApp published this final advisory covering CVE-2019-10125, CVE-2019-3874; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2019-3870 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190408-0001/

NetApp published this final advisory covering CVE-2019-3870; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 27th 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190404-0002/

NetApp published this final advisory covering CVE-2019-9857, CVE-2018-19985, CVE-2018-20669, CVE-2019-7222, CVE-2019-7221; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

March 2019 Python Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190404-0004/

NetApp published this final advisory covering CVE-2019-9947, CVE-2019-9948; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2019 PuTTY Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190404-0001/

NetApp published this final advisory covering CVE-2019-9894, CVE-2019-9895, CVE-2019-9896, CVE-2019-9897; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2018 GNU C Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190404-0003/

NetApp published this final advisory covering CVE-2017-1000408, CVE-2017-1000409, CVE-2018-6485, CVE-2018-6551, CVE-2018-1000001; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; NetApp VASA Provider for Clustered Data ONTAP 6.x; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

May 2018 GNU C Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190401-0001/

NetApp published this final advisory covering CVE-2017-18269, CVE-2018-11236, CVE-2018-11237; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

December 2018 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190401-0003/

NetApp published this final advisory covering CVE-2017-1427, CVE-2017-1428, CVE-2017-1779, CVE-2017-1783, CVE-2017-1784, CVE-2018-1413, CVE-2018-1842; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2019-9898 PuTTY Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190401-0002/

NetApp published this final advisory covering CVE-2019-9898; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager for 7-Mode (core package).

Open source
Advisory

October 2018 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0007/

NetApp published this final advisory covering CVE-2018-17794, CVE-2018-17985, CVE-2018-18309, CVE-2018-18483, CVE-2018-18484; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0002/

NetApp published this final advisory covering CVE-2019-9003, CVE-2019-9162; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

March 2019 Libssh2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0005/

NetApp published this final advisory covering CVE-2019-3855, CVE-2019-3856, CVE-2019-3857, CVE-2019-3858, CVE-2019-3859, CVE-2019-3860, CVE-2019-3861, CVE-2019-3862, CVE-2019-3863; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

Intel SA-00112 Active Management Technology Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0001/

NetApp published this final advisory covering CVE-2018-3628, CVE-2018-3629, CVE-2018-3632; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-6454 systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0004/

NetApp published this final advisory covering CVE-2019-6454; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); SnapProtect.

Open source
Advisory

CVE-2017-3164 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190327-0003/

NetApp published this final advisory covering CVE-2017-3164, CVE-2019-0192; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2019 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190321-0001/

NetApp published this final advisory covering CVE-2019-9025, CVE-2019-9024, CVE-2019-9023, CVE-2019-9022, CVE-2019-9021, CVE-2019-9020; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-20483 GNU Wget Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190321-0002/

NetApp published this final advisory covering CVE-2018-20483; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2018-19591 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190321-0003/

NetApp published this final advisory covering CVE-2018-19591; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Cluster Network Switch (NetApp CN1610); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; SnapProtect; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

Intel SA-00191 Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190318-0002/

NetApp published this final advisory covering CVE-2018-12201, CVE-2018-12202, CVE-2018-12203, CVE-2018-12204, CVE-2018-12205; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00185 CSME-SPS-TXE-AMT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190318-0001/

NetApp published this final advisory covering CVE-2018-12185, CVE-2018-12187, CVE-2018-12188, CVE-2018-12189, CVE-2018-12190, CVE-2018-12191, CVE-2018-12192, CVE-2018-12196, CVE-2018-12198, CVE-2018-12199, CVE-2018-12200, CVE-2018-12208; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

March 2019 GNU C Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190315-0002/

NetApp published this final advisory covering CVE-2009-5155, CVE-2018-20796, CVE-2019-9169; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Cluster Network Switch (NetApp CN1610); NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility; SnapProtect.

Open source
Advisory

CVE-2019-6977 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190315-0003/

NetApp published this final advisory covering CVE-2019-6977; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2019 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190314-0003/

NetApp published this final advisory covering CVE-2019-9070, CVE-2019-9071, CVE-2019-9072, CVE-2019-9073, CVE-2019-9074, CVE-2019-9075, CVE-2019-9076, CVE-2019-9077; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2019-6260 ASPEED BMC Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190314-0001/

NetApp published this final advisory covering CVE-2019-6260; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A320/C190/A220/FAS2720/FAS2750/A800; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-1543 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190314-0002/

NetApp published this final advisory covering CVE-2019-1543; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp Plug-in for Symantec NetBackup; SnapProtect.

Open source
Advisory

November 2018 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190307-0003/

NetApp published this final advisory covering CVE-2018-18605, CVE-2018-18606, CVE-2018-18607; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-5489 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190307-0001/

NetApp published this final advisory covering CVE-2019-5489; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2018-16888 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190307-0007/

NetApp published this final advisory covering CVE-2018-16888; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source