Content Library · Advisory

Advisory 2019

Browse 270 2019 NetApp advisory records in the NetApp Black Box content library. Page 3 of 3.

Library JSON API

Showing all 30 items on this page

Advisory

CVE-2015-2080 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190307-0005/

NetApp published this final advisory covering CVE-2015-2080; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Management Plug-ins (VMware vCenter); OnCommand System Manager 3.x; Snap Creator Framework.

Open source
Advisory

CVE-2011-4461 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190307-0004/

NetApp published this final advisory covering CVE-2011-4461; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand System Manager 3.x; Snap Creator Framework; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2019-1559 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190301-0001/

NetApp published this final advisory covering CVE-2019-1559; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cluster Network Switch (NetApp CN1610); FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Service Processor - 8080/8060/8040/8020; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS); NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapDrive for Unix; SnapDrive for Windows; SnapProtect; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

CVE-2019-3824 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190226-0001/

NetApp published this final advisory covering CVE-2019-3824; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2018 Ruby Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190221-0002/

NetApp published this final advisory covering CVE-2018-16395, CVE-2018-16396; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID Webscale NAS Bridge.

Open source
Advisory

December 2018 PERL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190221-0003/

NetApp published this final advisory covering CVE-2018-18311, CVE-2018-18312, CVE-2018-18313, CVE-2018-18314; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; OnCommand Workflow Automation; Snap Creator Framework; SnapCenter.

Open source
Advisory

December 2018 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190221-0004/

NetApp published this final advisory covering CVE-2018-19931, CVE-2018-19932, CVE-2018-20002; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere.

Open source
Advisory

CVE-2018-1000656 Flask Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190221-0001/

NetApp published this final advisory covering CVE-2018-1000656; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2018-20685 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190215-0001/

NetApp published this final advisory covering CVE-2018-20685; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility.

Open source
Advisory

January 2019 OpenSSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190213-0001/

NetApp published this final advisory covering CVE-2019-6109, CVE-2019-6110, CVE-2019-6111; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility.

Open source
Advisory

November 2017 Apache Commons FileUpload Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190212-0001/

NetApp published this final advisory covering CVE-2016-3092, CVE-2016-1000031; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; E-Series SANtricity Web Services (REST API) for Web Services Proxy; Element Plug-in for vCenter Server; OnCommand Plug-in for Microsoft; Snap Creator Framework; SnapCenter.

Open source
Advisory

CVE-2016-6210 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190206-0001/

NetApp published this final advisory covering CVE-2016-6210; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Cluster Network Switch (NetApp CN1610); Clustered Data ONTAP; Data ONTAP Edge; Data ONTAP operating in 7-Mode; Management Network Switch (NetApp CN1601); NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp VASA Provider for Clustered Data ONTAP 6.x; ONTAP Select Deploy administration utility; OnCommand Balance; OnCommand Unified Manager Core Package; OnCommand Unified Manager for Clustered Data ONTAP; Service Processor; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

September 2018 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190204-0001/

NetApp published this final advisory covering CVE-2018-16597, CVE-2018-17182; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; SnapProtect.

Open source
Advisory

CVE-2018-11763 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190204-0004/

NetApp published this final advisory covering CVE-2018-11763; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2019 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190125-0001/

NetApp published this final advisory covering CVE-2019-0190, CVE-2018-17199, CVE-2018-17189; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-3462 APT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190125-0002/

NetApp published this final advisory covering CVE-2019-3462; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapProtect.

Open source
Advisory

January 2019 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190118-0002/

NetApp published this final advisory covering CVE-2018-10933, CVE-2019-2435, CVE-2018-0732, CVE-2019-2534, CVE-2019-2533, CVE-2019-2529, CVE-2019-2482, CVE-2019-2434, CVE-2019-2455, CVE-2019-2503, CVE-2019-2436, CVE-2018-0734, CVE-2019-2536, CVE-2019-2502, CVE-2019-2510, CVE-2019-2539, CVE-2019-2494, CVE-2019-2495, CVE-2019-2537, CVE-2019-2420, CVE-2019-2481, CVE-2019-2507, CVE-2019-2530, CVE-2019-2528, CVE-2019-2531, CVE-2019-2486, CVE-2019-2532, CVE-2019-2535, CVE-2019-2513, CVE-2018-0732; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2019 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190118-0001/

NetApp published this final advisory covering CVE-2019-2540, CVE-2018-11212, CVE-2019-2426, CVE-2019-2449, CVE-2019-2422; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Plug-in for Symantec NetBackup; OnCommand Insight; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

January 2019 Systemd-journald Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20190117-0001/

NetApp published this final advisory covering CVE-2018-16864, CVE-2018-16865, CVE-2018-16866; the API labels exploitation information as **Public**. The API currently lists affected products as: Cluster Network Switch (NetApp CN1610); NetApp SolidFire & HCI Management Node; SnapProtect.

Open source