Content Library · Advisory

Advisory 2020

Browse 272 2020 NetApp advisory records in the NetApp Black Box content library.

Library JSON API

Advisory

CVE-2020-11612 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201223-0001/

NetApp published this final advisory covering CVE-2020-11612; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand API Services; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2020-1749 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201222-0001/

NetApp published this final advisory covering CVE-2020-1749; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-29370 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201218-0001/

NetApp published this final advisory covering CVE-2020-29370; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25723 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201218-0004/

NetApp published this final advisory covering CVE-2020-25723; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-1971 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201218-0005/

NetApp published this final advisory covering CVE-2020-1971; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Data ONTAP operating in 7-Mode; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Global File Cache; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp Plug-in for Symantec NetBackup; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Antivirus Connector; OnCommand Unified Manager Core Package; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

CVE-2020-15436 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201218-0002/

NetApp published this final advisory covering CVE-2020-15436; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25705 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201210-0002/

NetApp published this final advisory covering CVE-2020-25705; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25640 WildFly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201210-0001/

NetApp published this final advisory covering CVE-2020-25640; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager.

Open source
Advisory

CVE-2020-25624 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201210-0005/

NetApp published this final advisory covering CVE-2020-25624; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-17527 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201210-0003/

NetApp published this final advisory covering CVE-2020-17527; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; OnCommand System Manager 3.x.

Open source
Advisory

CVE-2020-14305 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201210-0004/

NetApp published this final advisory covering CVE-2020-14305; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

November 2020 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201202-0002/

NetApp published this final advisory covering CVE-2020-27616, CVE-2020-27617; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2020 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201202-0003/

NetApp published this final advisory covering CVE-2020-25694, CVE-2020-25695; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2020 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201202-0004/

NetApp published this final advisory covering CVE-2020-28362, CVE-2020-28366, CVE-2020-28367; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident; Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2020-7020 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201123-0001/

NetApp published this final advisory covering CVE-2020-7020; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-27619 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201123-0004/

NetApp published this final advisory covering CVE-2020-27619; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-27216 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201123-0005/

NetApp published this final advisory covering CVE-2020-27216; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; OnCommand System Manager 3.x; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above; Virtual Storage Console for VMware vSphere 9.7 and above.

Open source
Advisory

CVE-2020-25689 WildFly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201123-0006/

NetApp published this final advisory covering CVE-2020-25689; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; OnCommand Insight.

Open source
Advisory

CVE-2020-24352 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201123-0003/

NetApp published this final advisory covering CVE-2020-24352; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-24303 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201123-0002/

NetApp published this final advisory covering CVE-2020-24303; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00391 SPS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201113-0004/

NetApp published this final advisory covering CVE-2020-8705, CVE-2020-8744, CVE-2020-8755; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; FAS/AFF BIOS; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

Intel SA-00391 Intel TXE Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201113-0005/

NetApp published this final advisory covering CVE-2020-8705, CVE-2020-8744, CVE-2020-8745, CVE-2020-8750, CVE-2020-8751, CVE-2020-12297, CVE-2020-12303, CVE-2020-12355; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

Intel SA-00391 CSME Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201113-0002/

NetApp published this final advisory covering CVE-2020-8705, CVE-2020-8744, CVE-2020-8745, CVE-2020-8751, CVE-2020-8755, CVE-2020-8756, CVE-2020-8761, CVE-2020-12303, CVE-2020-12297; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

Intel SA-00391 AMT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201113-0003/

NetApp published this final advisory covering CVE-2020-8746, CVE-2020-8747, CVE-2020-8749, CVE-2020-8752, CVE-2020-8753, CVE-2020-8754, CVE-2020-8757, CVE-2020-8760, CVE-2020-12354, CVE-2020-12356; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

Intel SA-00381 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201113-0006/

NetApp published this final advisory covering CVE-2020-8696, CVE-2020-8698; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; FAS/AFF BIOS; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

Intel SA-00358 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201113-0001/

NetApp published this final advisory covering CVE-2020-0590, CVE-2020-0587, CVE-2020-0591, CVE-2020-0593, CVE-2020-0588, CVE-2020-0592; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; FAS/AFF BIOS; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

October 2020 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201103-0001/

NetApp published this final advisory covering CVE-2020-14318, CVE-2020-14323, CVE-2020-14383; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25645 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201103-0004/

NetApp published this final advisory covering CVE-2020-25645; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25643 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201103-0002/

NetApp published this final advisory covering CVE-2020-25643; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2018-11764 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201103-0003/

NetApp published this final advisory covering CVE-2018-11764; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2020 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201023-0003/

NetApp published this final advisory covering CVE-2020-8174, CVE-2020-14672, CVE-2020-14760, CVE-2020-14765, CVE-2020-14769, CVE-2020-14771, CVE-2020-14773, CVE-2020-14775, CVE-2020-14776, CVE-2020-14777, CVE-2020-14785, CVE-2020-14786, CVE-2020-14789, CVE-2020-14790, CVE-2020-14791, CVE-2020-14793, CVE-2020-14794, CVE-2020-14799, CVE-2020-14800, CVE-2020-14804, CVE-2020-14809, CVE-2020-14812, CVE-2020-14814, CVE-2020-14821, CVE-2020-14827, CVE-2020-14828, CVE-2020-14829, CVE-2020-14830, CVE-2020-14836, CVE-2020-14837, CVE-2020-14838, CVE-2020-14839, CVE-2020-14844, CVE-2020-14845, CVE-2020-14846, CVE-2020-14848, CVE-2020-14852, CVE-2020-14853, CVE-2020-14860, CVE-2020-14861, CVE-2020-14866, CVE-2020-14867, CVE-2020-14868, CVE-2020-14869, CVE-2020-14870, CVE-2020-14873, CVE-2020-14878, CVE-2020-14888, CVE-2020-14891, CVE-2020-14893, CVE-2020-4051; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2020 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201023-0004/

NetApp published this interim advisory covering CVE-2020-14779, CVE-2020-14781, CVE-2020-14782, CVE-2020-14792, CVE-2020-14796, CVE-2020-14797, CVE-2020-14798, CVE-2020-14803; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Insights Acquisition Unit; Cloud Secure Agent; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer; NetApp HCI Compute Node (Bootstrap OS); NetApp Plug-in for Symantec NetBackup; NetApp SANtricity Cloud Connector; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Unified Manager Core Package; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2020-26116 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201023-0001/

NetApp published this interim advisory covering CVE-2020-26116; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-13957 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201023-0002/

NetApp published this final advisory covering CVE-2020-13957; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2020 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201016-0001/

NetApp published this final advisory covering CVE-2020-7069, CVE-2020-7070; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2020 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201016-0002/

NetApp published this final advisory covering CVE-2020-7461, CVE-2020-7462, CVE-2020-7463, CVE-2020-7464, CVE-2020-7467, CVE-2020-7468, CVE-2020-24718; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.

Open source
Advisory

Intel SA-00435 BlueZ Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201016-0006/

NetApp published this final advisory covering CVE-2020-12351, CVE-2020-12352, CVE-2020-24490; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25644 WildFly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201016-0004/

NetApp published this final advisory covering CVE-2020-25644; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Service Level Manager; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2020-25626 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201016-0003/

NetApp published this final advisory covering CVE-2020-25626; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-11765 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201016-0005/

NetApp published this final advisory covering CVE-2018-11765; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2020 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201009-0005/

NetApp published this final advisory covering CVE-2020-25625, CVE-2020-25085, CVE-2020-25084, CVE-2020-25741; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2020 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201009-0004/

NetApp published this final advisory covering CVE-2020-8251, CVE-2020-8201, CVE-2020-8252; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25285 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201009-0002/

NetApp published this final advisory covering CVE-2020-25285; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25211 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201009-0001/

NetApp published this interim advisory covering CVE-2020-25211; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-24750 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201009-0003/

NetApp published this final advisory covering CVE-2020-24750; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8608 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201001-0002/

NetApp published this final advisory covering CVE-2020-8608; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25221 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201001-0003/

NetApp published this final advisory covering CVE-2020-25221; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25220 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201001-0004/

NetApp published this final advisory covering CVE-2020-25220; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-1748 WildFly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201001-0005/

NetApp published this final advisory covering CVE-2020-1748; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10756 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201001-0001/

NetApp published this final advisory covering CVE-2020-10756; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10733 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20201001-0006/

NetApp published this final advisory covering CVE-2020-10733; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8648 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200924-0004/

NetApp published this final advisory covering CVE-2020-8648; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-24977 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200924-0001/

NetApp published this final advisory covering CVE-2020-24977; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Clustered Data ONTAP; Clustered Data ONTAP Antivirus Connector; NetApp Cloud Backup (formerly AltaVault); NetApp Manageability SDK; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

CVE-2020-24553 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200924-0003/

NetApp published this final advisory covering CVE-2020-24553; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-16845 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200924-0002/

NetApp published this final advisory covering CVE-2020-16845; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-14364 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200924-0006/

NetApp published this final advisory covering CVE-2020-14364; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-19543 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200924-0005/

NetApp published this final advisory covering CVE-2019-19543; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

September 2020 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200918-0004/

NetApp published this final advisory covering CVE-2020-24583, CVE-2020-24584; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-7068 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200918-0005/

NetApp published this final advisory covering CVE-2020-7068; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-19499 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200918-0003/

NetApp published this final advisory covering CVE-2019-19499; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2020 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200918-0002/

NetApp published this final advisory covering CVE-2020-14349, CVE-2020-14350; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2020 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200918-0001/

NetApp published this final advisory covering CVE-2020-24346, CVE-2020-24347, CVE-2020-24348, CVE-2020-24349; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2020-8758 Intel AMT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200911-0005/

NetApp published this final advisory covering CVE-2020-8758; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-8231 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200911-0003/

NetApp published this final advisory covering CVE-2020-8231; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-8177 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200911-0001/

NetApp published this final advisory covering CVE-2020-8177; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-8169 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200911-0002/

NetApp published this final advisory covering CVE-2020-8169; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-24659 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200911-0006/

NetApp published this final advisory covering CVE-2020-24659; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2020-1968 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200911-0004/

NetApp published this final advisory covering CVE-2020-1968; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

CVE-2020-24394 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200904-0003/

NetApp published this final advisory covering CVE-2020-24394; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-14356 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200904-0002/

NetApp published this final advisory covering CVE-2020-14356; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-14892 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200904-0005/

NetApp published this final advisory covering CVE-2019-14892; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-1000873 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200904-0004/

NetApp published this final advisory covering CVE-2018-1000873; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

August 2020 Net-SNMP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200904-0001/

NetApp published this final advisory covering CVE-2020-15861, CVE-2020-15862; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node.

Open source
Advisory

August 2020 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200904-0006/

NetApp published this final advisory covering CVE-2020-9546, CVE-2020-9547, CVE-2020-9548, CVE-2020-24616; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2020-7019 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200827-0001/

NetApp published this final advisory covering CVE-2020-7019; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-11985 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200827-0002/

NetApp published this final advisory covering CVE-2020-11985; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-15173 Nmap Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200827-0004/

NetApp published this final advisory covering CVE-2018-15173; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2020 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200827-0003/

NetApp published this final advisory covering CVE-2020-8620, CVE-2020-8621, CVE-2020-8622, CVE-2020-8623, CVE-2020-8624; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-8558 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200821-0001/

NetApp published this final advisory covering CVE-2020-8558; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8557 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200821-0002/

NetApp published this final advisory covering CVE-2020-8557; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-16092 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200821-0006/

NetApp published this final advisory covering CVE-2020-16092; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2020 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200821-0005/

NetApp published this final advisory covering CVE-2020-7459, CVE-2020-7460; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2020 Apache Struts 2.x Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200821-0004/

NetApp published this final advisory covering CVE-2019-0230, CVE-2019-0233; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00386 Server Board Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200814-0003/

NetApp published this final advisory covering CVE-2020-8733, CVE-2020-8734; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00384 Server Boards, Systems and Compute Module Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200814-0002/

NetApp published this final advisory covering CVE-2020-8708, CVE-2020-8730, CVE-2020-8731, CVE-2020-8707, CVE-2020-8719, CVE-2020-8721, CVE-2020-8710, CVE-2020-8711, CVE-2020-8712, CVE-2020-8718, CVE-2020-8722, CVE-2020-8732, CVE-2020-8709, CVE-2020-8723, CVE-2020-8713, CVE-2020-8706, CVE-2020-8729, CVE-2020-8715, CVE-2020-8716, CVE-2020-8714, CVE-2020-8717, CVE-2020-8720; the API labels exploitation information as **Not public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00367 Server Board Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200814-0001/

NetApp published this final advisory covering CVE-2020-12299, CVE-2020-12300, CVE-2020-12301; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-16166 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200814-0004/

NetApp published this interim advisory covering CVE-2020-16166; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; StorageGRID9 (9.x and prior).

Open source
Advisory

August 2020 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200814-0005/

NetApp published this final advisory covering CVE-2020-9490, CVE-2020-11984, CVE-2020-11993; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8559 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200810-0004/

NetApp published this final advisory covering CVE-2020-8559; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-15852 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200810-0001/

NetApp published this final advisory covering CVE-2020-15852; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-11110 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200810-0002/

NetApp published this final advisory covering CVE-2020-11110; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2019-11255 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200810-0003/

NetApp published this final advisory covering CVE-2019-11255; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8575 Denial of Service Vulnerability in Active IQ Unified Manager for VMware vSphere and Windows

Source: https://security.netapp.com/advisory/NTAP-20200803-0002/

NetApp published this final advisory covering CVE-2020-8575; the API labels exploitation information as **Not public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above.

Open source
Advisory

July 2020 Grub2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200731-0008/

NetApp published this final advisory covering CVE-2020-10713, CVE-2020-14308, CVE-2020-14309, CVE-2020-14310, CVE-2020-14311, CVE-2020-15705, CVE-2020-15706, CVE-2020-15707; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

July 2020 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200731-0005/

NetApp published this final advisory covering CVE-2020-15586, CVE-2020-14039; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-15778 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200731-0007/

NetApp published this final advisory covering CVE-2020-15778; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-14725 MySQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200731-0006/

NetApp published this final advisory covering CVE-2020-14725; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2020-14001 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200731-0004/

NetApp published this final advisory covering CVE-2020-14001; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10761 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200731-0001/

NetApp published this final advisory covering CVE-2020-10761; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-20907 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200731-0002/

NetApp published this final advisory covering CVE-2019-20907; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; MAX Data.

Open source
Advisory

June 2020 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200724-0001/

NetApp published this final advisory covering CVE-2020-14966, CVE-2020-14967, CVE-2020-14968; the API labels exploitation information as **Public**. The API currently lists affected products as: MAX Data.

Open source
Advisory

July 2020 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200724-0002/

NetApp published this final advisory covering CVE-2020-7457, CVE-2020-7458; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8555 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200724-0005/

NetApp published this final advisory covering CVE-2020-8555; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8203 Lodash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200724-0006/

NetApp published this final advisory covering CVE-2020-8203; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager.

Open source
Advisory

CVE-2020-14422 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200724-0004/

NetApp published this final advisory covering CVE-2020-14422; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; MAX Data.

Open source
Advisory

CVE-2020-10702 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200724-0007/

NetApp published this final advisory covering CVE-2020-10702; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2020 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200717-0001/

NetApp published this final advisory covering CVE-2020-13800, CVE-2020-13791; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2020 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200717-0004/

NetApp published this final advisory covering CVE-2020-1967, CVE-2020-14663, CVE-2020-14678, CVE-2020-14697, CVE-2020-14539, CVE-2020-14540, CVE-2020-14547, CVE-2020-14553, CVE-2020-14559, CVE-2020-14567, CVE-2020-14568, CVE-2020-14575, CVE-2020-14576, CVE-2020-14586, CVE-2020-14591, CVE-2020-14597, CVE-2020-14614, CVE-2020-14619, CVE-2020-14620, CVE-2020-14623, CVE-2020-14624, CVE-2020-14631, CVE-2020-14632, CVE-2020-14633, CVE-2020-14634, CVE-2020-14641, CVE-2020-14643, CVE-2020-14651, CVE-2020-14654, CVE-2020-14656, CVE-2020-14680, CVE-2020-14702; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2020 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200717-0005/

NetApp published this final advisory covering CVE-2020-14664, CVE-2020-14583, CVE-2020-14593, CVE-2020-14556, CVE-2020-14562, CVE-2020-14573, CVE-2020-14577, CVE-2020-14578, CVE-2020-14579, CVE-2020-14581, CVE-2020-14621; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Secure Agent; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer; NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; OnCommand Insight; OnCommand Unified Manager Core Package; OnCommand Workflow Automation; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2020-14002 PuTTY Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200717-0003/

NetApp published this final advisory covering CVE-2020-14002; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager Core Package.

Open source
Advisory

CVE-2020-13401 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200717-0002/

NetApp published this final advisory covering CVE-2020-13401; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2020-15358 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200709-0001/

NetApp published this final advisory covering CVE-2020-15358; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2020-14303 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200709-0003/

NetApp published this final advisory covering CVE-2020-14303; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-14145 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200709-0004/

NetApp published this interim advisory covering CVE-2020-14145; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; ONTAP Select Deploy administration utility.

Open source
Advisory

June 2020 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200702-0001/

NetApp published this final advisory covering CVE-2020-10730, CVE-2020-10745, CVE-2020-10760; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2020 Libxml2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200702-0005/

NetApp published this final advisory covering CVE-2019-20388, CVE-2020-7595; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp SteelStore Cloud Integrated Storage; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility; SnapDrive for Windows.

Open source
Advisory

June 2020 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200702-0003/

NetApp published this final advisory covering CVE-2020-14060, CVE-2020-14061, CVE-2020-14062, CVE-2020-14195; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-15025 Network Time Protocol Daemon (ntpd) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200702-0002/

NetApp published this final advisory covering CVE-2020-15025; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-12662 Unbound Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200702-0006/

NetApp published this final advisory covering CVE-2020-12662; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10757 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200702-0004/

NetApp published this final advisory covering CVE-2020-10757; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-8573 Default Account Vulnerability in the NetApp HCI Baseboard Management Controller (BMC) - H610C, H615C and H610S

Source: https://security.netapp.com/advisory/NTAP-20200626-0001/

NetApp published this final advisory covering CVE-2020-8573; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

June 2020 Treck TCP/IP Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200625-0006/

NetApp published this final advisory covering CVE-2020-11908, CVE-2020-11903, CVE-2020-11900, CVE-2020-11896, CVE-2020-11898, CVE-2020-11899, CVE-2020-11902, CVE-2020-11904, CVE-2020-11905, CVE-2020-11906, CVE-2020-11907, CVE-2020-11909, CVE-2020-11910, CVE-2020-11911, CVE-2020-11912, CVE-2020-11913, CVE-2020-11914; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2020 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200625-0003/

NetApp published this final advisory covering CVE-2020-8618, CVE-2020-8619; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-13817 NTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200625-0004/

NetApp published this final advisory covering CVE-2020-13817; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); NetApp SteelStore Cloud Integrated Storage; ONTAP tools for VMware vSphere.

Open source
Advisory

CVE-2020-10933 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200625-0001/

NetApp published this final advisory covering CVE-2020-10933; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-7014 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200619-0003/

NetApp published this final advisory covering CVE-2020-7014; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-13871 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200619-0002/

NetApp published this final advisory covering CVE-2020-13871; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-13777 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200619-0004/

NetApp published this final advisory covering CVE-2020-13777; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-13765 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200619-0006/

NetApp published this final advisory covering CVE-2020-13765; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-20806 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200619-0001/

NetApp published this final advisory covering CVE-2019-20806; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

June 2020 Perl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200611-0001/

NetApp published this final advisory covering CVE-2020-10878, CVE-2020-12723, CVE-2020-10543; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

June 2020 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200611-0002/

NetApp published this final advisory covering CVE-2020-13254, CVE-2020-13596; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage; SRA Plugin for Linux.

Open source
Advisory

Intel SA-00295 TXE Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200611-0005/

NetApp published this final advisory covering CVE-2020-0566; the API labels exploitation information as **Not public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00295 SPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200611-0004/

NetApp published this final advisory covering CVE-2020-0586; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00295 CSME Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200611-0006/

NetApp published this final advisory covering CVE-2020-0533, CVE-2020-0534, CVE-2020-0536, CVE-2020-0539, CVE-2020-0541, CVE-2020-0542, CVE-2020-0545; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00295 AMT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200611-0007/

NetApp published this final advisory covering CVE-2020-0594, CVE-2020-0538, CVE-2020-0532, CVE-2020-0597, CVE-2020-0535, CVE-2020-0540, CVE-2020-0537, CVE-2020-8674, CVE-2020-0531, CVE-2020-0595, CVE-2020-0596; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-13776 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200611-0003/

NetApp published this final advisory covering CVE-2020-13776; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

May 2020 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200608-0001/

NetApp published this final advisory covering CVE-2020-10711, CVE-2020-13143, CVE-2020-12888, CVE-2020-12826, CVE-2020-12771, CVE-2020-12770, CVE-2020-12769, CVE-2019-20794, CVE-2019-14898, CVE-2020-12659, CVE-2020-12657, CVE-2020-12655, CVE-2020-12653, CVE-2020-12654, CVE-2020-12652, CVE-2020-12114, CVE-2020-12465, CVE-2020-12464, CVE-2020-11884, CVE-2019-11599, CVE-2020-10690; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

June 2020 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200608-0002/

NetApp published this final advisory covering CVE-2020-13630, CVE-2020-13631, CVE-2020-13632; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

June 2020 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200608-0003/

NetApp published this final advisory covering CVE-2020-13361, CVE-2020-13362; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2020 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200608-0007/

NetApp published this final advisory covering CVE-2020-13754, CVE-2020-13659; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2020 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200608-0008/

NetApp published this final advisory covering CVE-2018-18623, CVE-2018-18624, CVE-2018-18625; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-13379 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200608-0006/

NetApp published this final advisory covering CVE-2020-13379; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2020-10703 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200608-0005/

NetApp published this final advisory covering CVE-2020-10703; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2020 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200528-0004/

NetApp published this final advisory covering CVE-2020-13435, CVE-2020-13434; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-7656 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200528-0001/

NetApp published this final advisory covering CVE-2020-7656; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); OnCommand System Manager 3.x; Snap Creator Framework.

Open source
Advisory

CVE-2020-13430 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200528-0003/

NetApp published this final advisory covering CVE-2020-13430; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-13388 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200528-0002/

NetApp published this final advisory covering CVE-2020-13388; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-11048 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200528-0006/

NetApp published this final advisory covering CVE-2019-11048; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2020 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200522-0002/

NetApp published this final advisory covering CVE-2020-8616, CVE-2020-8617; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SteelStore Cloud Integrated Storage; Storage Replication Adapter for Clustered Data ONTAP for Windows 7.2 and above.

Open source
Advisory

CVE-2020-5895 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200522-0001/

NetApp published this final advisory covering CVE-2020-5895; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

May 2020 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0005/

NetApp published this final advisory covering CVE-2019-15879, CVE-2020-7454, CVE-2020-7455; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-12459 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0004/

NetApp published this final advisory covering CVE-2020-12459; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-12458 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0001/

NetApp published this final advisory covering CVE-2020-12458; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-12430 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0003/

NetApp published this final advisory covering CVE-2020-12430; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10683 Dom4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0002/

NetApp published this final advisory covering CVE-2020-10683; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Service Level Manager; OnCommand API Services; OnCommand System Manager 3.x; OnCommand Workflow Automation; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2019-15880 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0008/

NetApp published this final advisory covering CVE-2019-15880; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-15878 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0007/

NetApp published this final advisory covering CVE-2019-15878; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-8956 Network Time Protocol Daemon (ntpd) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200518-0006/

NetApp published this final advisory covering CVE-2018-8956; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

May 2020 jQuery Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200511-0006/

NetApp published this final advisory covering CVE-2020-11022, CVE-2020-11023; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Insights Storage Workload Security Agent; MAX Data; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; OnCommand Insight; OnCommand System Manager 3.x; Snap Creator Framework; SnapCenter.

Open source
Advisory

May 2020 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200511-0001/

NetApp published this final advisory covering CVE-2020-12052, CVE-2020-12245; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

May 2020 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200511-0002/

NetApp published this final advisory covering CVE-2019-5614, CVE-2019-15874; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.

Open source
Advisory

May 2020 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200511-0004/

NetApp published this final advisory covering CVE-2020-11619, CVE-2020-11620; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-1752 GNU C Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200511-0005/

NetApp published this final advisory covering CVE-2020-1752; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-12243 OpenLDAP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200511-0003/

NetApp published this final advisory covering CVE-2020-12243; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-9488 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200504-0003/

NetApp published this final advisory covering CVE-2020-9488; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-7067 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200504-0001/

NetApp published this final advisory covering CVE-2020-7067; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-1751 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200430-0002/

NetApp published this final advisory covering CVE-2020-1751; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-11669 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200430-0001/

NetApp published this final advisory covering CVE-2020-11669; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-18276 GNU Bash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200430-0003/

NetApp published this final advisory covering CVE-2019-18276; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp SolidFire & HCI Management Node.

Open source
Advisory

April 2020 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200430-0005/

NetApp published this final advisory covering CVE-2020-5863, CVE-2020-5864, CVE-2020-5865, CVE-2020-5866, CVE-2020-5867; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

April 2020 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200430-0004/

NetApp published this final advisory covering CVE-2019-20636, CVE-2020-11494, CVE-2020-11608, CVE-2020-11609, CVE-2020-11668, CVE-2020-8832, CVE-2020-8835; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

April 2020 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200429-0001/

NetApp published this final advisory covering CVE-2020-10700, CVE-2020-10704; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-1967 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200424-0003/

NetApp published this final advisory covering CVE-2020-1967; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp E-Series Performance Analyzer; NetApp Plug-in for Symantec NetBackup; NetApp SMI-S Provider; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-1730 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200424-0001/

NetApp published this final advisory covering CVE-2020-1730; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2020-11868 NTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200424-0002/

NetApp published this final advisory covering CVE-2020-11868; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP operating in 7-Mode; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP tools for VMware vSphere.

Open source
Advisory

CVE-2020-11501 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200416-0002/

NetApp published this final advisory covering CVE-2020-11501; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

April 2020 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200416-0001/

NetApp published this final advisory covering CVE-2020-11655, CVE-2020-11656; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

April 2020 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200416-0003/

NetApp published this final advisory covering CVE-2019-1547, CVE-2019-15601, CVE-2019-5482, CVE-2020-2752, CVE-2020-2759, CVE-2020-2760, CVE-2020-2761, CVE-2020-2762, CVE-2020-2763, CVE-2020-2765, CVE-2020-2768, CVE-2020-2770, CVE-2020-2774, CVE-2020-2779, CVE-2020-2780, CVE-2020-2790, CVE-2020-2804, CVE-2020-2806, CVE-2020-2812, CVE-2020-2814, CVE-2020-2853, CVE-2020-2892, CVE-2020-2893, CVE-2020-2895, CVE-2020-2896, CVE-2020-2897, CVE-2020-2898, CVE-2020-2901, CVE-2020-2903, CVE-2020-2904, CVE-2020-2921, CVE-2020-2922, CVE-2020-2923, CVE-2020-2924, CVE-2020-2925, CVE-2020-2926, CVE-2020-2928, CVE-2020-2930; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2020 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200416-0004/

NetApp published this final advisory covering CVE-2020-2803, CVE-2020-2805, CVE-2019-18197, CVE-2020-2816, CVE-2020-2754, CVE-2020-2755, CVE-2020-2756, CVE-2020-2757, CVE-2020-2764, CVE-2020-2767, CVE-2020-2773, CVE-2020-2778, CVE-2020-2781, CVE-2020-2800, CVE-2020-2830; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Secure Agent; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer; NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; OnCommand Insight; OnCommand Workflow Automation; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP; StorageGRID (formerly StorageGRID Webscale); StorageGRID9 (9.x and prior).

Open source
Advisory

March 2020 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200413-0001/

NetApp published this final advisory covering CVE-2019-15876, CVE-2019-15877, CVE-2020-7451, CVE-2020-7452, CVE-2020-7453; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; Data ONTAP operating in 7-Mode.

Open source
Advisory

April 2020 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200413-0003/

NetApp published this final advisory covering CVE-2020-8551, CVE-2020-8552, CVE-2019-11254; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2020 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200413-0002/

NetApp published this final advisory covering CVE-2020-1927, CVE-2020-1934; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; OnCommand Unified Manager Core Package.

Open source
Advisory

March 2020 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200403-0001/

NetApp published this final advisory covering CVE-2020-7064, CVE-2020-7065, CVE-2020-7066; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-7009 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200403-0004/

NetApp published this final advisory covering CVE-2020-7009; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10942 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200403-0003/

NetApp published this final advisory covering CVE-2020-10942; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

April 2020 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200403-0002/

NetApp published this final advisory covering CVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969, CVE-2020-11111, CVE-2020-11112, CVE-2020-11113; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2015-2992 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200330-0001/

NetApp published this final advisory covering CVE-2015-2992; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2020 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200327-0005/

NetApp published this final advisory covering CVE-2019-17569, CVE-2020-1935; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Data Availability Services; OnCommand System Manager 3.x.

Open source
Advisory

CVE-2020-9402 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200327-0004/

NetApp published this final advisory covering CVE-2020-9402; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-8840 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200327-0002/

NetApp published this final advisory covering CVE-2020-8840; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Service Level Manager; NetApp SteelStore Cloud Integrated Storage; OnCommand API Services; OnCommand Workflow Automation.

Open source
Advisory

CVE-2020-7919 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200327-0001/

NetApp published this final advisory covering CVE-2020-7919; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2020-10029 GNU C Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200327-0003/

NetApp published this final advisory covering CVE-2020-10029; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-14887 Wildfly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200327-0007/

NetApp published this final advisory covering CVE-2019-14887; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00334 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200320-0002/

NetApp published this final advisory covering CVE-2020-0551; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00330 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200320-0001/

NetApp published this final advisory covering CVE-2020-0550; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00315 Intel Graphics Drivers Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200320-0003/

NetApp published this final advisory covering CVE-2020-0504, CVE-2020-0516, CVE-2020-0519, CVE-2020-0520, CVE-2020-0505, CVE-2020-0501, CVE-2020-0565, CVE-2020-0514, CVE-2020-0515, CVE-2020-0508, CVE-2020-0511, CVE-2020-0503, CVE-2020-0567, CVE-2020-0502, CVE-2020-0507, CVE-2020-0517, CVE-2020-0506; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00260 Intel Graphics Drivers Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200320-0004/

NetApp published this final advisory covering CVE-2019-0154; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

Intel SA-00242 Graphics Drivers Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200320-0005/

NetApp published this final advisory covering CVE-2019-0155, CVE-2019-11089, CVE-2019-11111, CVE-2019-11112, CVE-2019-11113, CVE-2019-14574, CVE-2019-14590, CVE-2019-14591; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

February 2020 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200313-0003/

NetApp published this final advisory covering CVE-2019-20422, CVE-2019-3016, CVE-2020-8428, CVE-2020-8992, CVE-2020-9383, CVE-2020-9391; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-9327 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200313-0002/

NetApp published this final advisory covering CVE-2020-9327; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2020-8597 PPP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200313-0004/

NetApp published this final advisory covering CVE-2020-8597; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2020-8441 JYaml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200313-0001/

NetApp published this final advisory covering CVE-2020-8441; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; SnapManager for Oracle.

Open source
Advisory

CVE-2020-1938 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200226-0002/

NetApp published this final advisory covering CVE-2020-1938; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Data Availability Services; OnCommand System Manager 3.x.

Open source
Advisory

Intel SA-00307 Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200221-0005/

NetApp published this final advisory covering CVE-2019-14598; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

February 2020 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200221-0002/

NetApp published this final advisory covering CVE-2020-7059, CVE-2020-7060; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2020 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200221-0004/

NetApp published this final advisory covering CVE-2019-15604, CVE-2019-15605, CVE-2019-15606; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8492 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200221-0001/

NetApp published this final advisory covering CVE-2020-8492; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-7471 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200221-0006/

NetApp published this final advisory covering CVE-2020-7471; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-9674 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200221-0003/

NetApp published this final advisory covering CVE-2019-9674; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

Intel SA-00329 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200210-0004/

NetApp published this final advisory covering CVE-2020-0548, CVE-2020-0549; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

February 2020 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200210-0003/

NetApp published this final advisory covering CVE-2020-7450, CVE-2019-5613, CVE-2019-15875; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-20386 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200210-0002/

NetApp published this final advisory covering CVE-2019-20386; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-18634 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200210-0001/

NetApp published this final advisory covering CVE-2019-18634; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

January 2020 NTP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200204-0003/

NetApp published this final advisory covering CVE-2015-8139, CVE-2015-8140; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

January 2020 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200204-0002/

NetApp published this final advisory covering CVE-2019-19966, CVE-2019-19965, CVE-2019-19947, CVE-2019-20054, CVE-2019-5108, CVE-2019-19922, CVE-2019-19927, CVE-2019-20095, CVE-2019-19332, CVE-2020-7053, CVE-2007-4774, CVE-2019-18282; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-19959 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200204-0001/

NetApp published this final advisory covering CVE-2019-19959; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2019-20372 NGINX vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200127-0003/

NetApp published this final advisory covering CVE-2019-20372; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2019-20330 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200127-0004/

NetApp published this final advisory covering CVE-2019-20330; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; NetApp Service Level Manager; NetApp SteelStore Cloud Integrated Storage; OnCommand API Services; SnapCenter.

Open source
Advisory

CVE-2019-15601 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200127-0002/

NetApp published this final advisory covering CVE-2019-15601; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

January 2020 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200122-0001/

NetApp published this final advisory covering CVE-2019-14902, CVE-2019-14907, CVE-2019-19344; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2020 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200122-0002/

NetApp published this final advisory covering CVE-2020-2579, CVE-2020-2686, CVE-2020-2627, CVE-2019-1547, CVE-2020-2572, CVE-2020-2573, CVE-2020-2574, CVE-2020-2577, CVE-2020-2580, CVE-2020-2584, CVE-2020-2588, CVE-2020-2589, CVE-2020-2660, CVE-2020-2679, CVE-2020-2694; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2020 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200122-0003/

NetApp published this final advisory covering CVE-2020-2604, CVE-2019-13117, CVE-2019-13118, CVE-2019-16168, CVE-2020-2583, CVE-2020-2585, CVE-2020-2590, CVE-2020-2593, CVE-2020-2601, CVE-2020-2654, CVE-2020-2655, CVE-2020-2659; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer; NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; OnCommand Insight; OnCommand Workflow Automation; SANtricity Unified Manager.

Open source
Advisory

October 2019 Tcpdump Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200120-0001/

NetApp published this final advisory covering CVE-2018-10103, CVE-2018-10105, CVE-2018-14461, CVE-2018-14462, CVE-2018-14463, CVE-2018-14464, CVE-2018-14465, CVE-2018-14466, CVE-2018-14467, CVE-2018-14468, CVE-2018-14469, CVE-2018-14470, CVE-2018-14879, CVE-2018-14880, CVE-2018-14881, CVE-2018-14882, CVE-2018-16227, CVE-2018-16228, CVE-2018-16229, CVE-2018-16230, CVE-2018-16300, CVE-2018-16451, CVE-2018-16452, CVE-2019-15166; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-18218 File Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200115-0001/

NetApp published this final advisory covering CVE-2019-18218; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above.

Open source
Advisory

January 2020 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200114-0003/

NetApp published this final advisory covering CVE-2019-19923, CVE-2019-19924, CVE-2019-19925, CVE-2019-19926; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2019-19956 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200114-0002/

NetApp published this final advisory covering CVE-2019-19956; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp Manageability SDK; NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-19880 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200114-0001/

NetApp published this final advisory covering CVE-2019-19880; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2019-19844 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200110-0003/

NetApp published this final advisory covering CVE-2019-19844; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-17571 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200110-0001/

NetApp published this final advisory covering CVE-2019-17571; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand System Manager 3.x; OnCommand Workflow Automation.

Open source
Advisory

December 2019 Sudo Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200103-0004/

NetApp published this final advisory covering CVE-2019-19232, CVE-2019-19234; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node.

Open source
Advisory

December 2019 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200103-0002/

NetApp published this final advisory covering CVE-2019-11044, CVE-2019-11045, CVE-2019-11046, CVE-2019-11047, CVE-2019-11049, CVE-2019-11050; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200103-0001/

NetApp published this final advisory covering CVE-2019-14815, CVE-2019-19227, CVE-2019-10220, CVE-2019-19318, CVE-2019-14896, CVE-2019-19252, CVE-2019-18660, CVE-2019-19319, CVE-2019-10207, CVE-2019-18675, CVE-2019-19602, CVE-2019-19378, CVE-2019-19377, CVE-2019-19447, CVE-2019-19448, CVE-2019-19449, CVE-2019-19768, CVE-2019-19769, CVE-2019-19770, CVE-2019-19767, CVE-2019-19807, CVE-2019-19241, CVE-2019-19815, CVE-2019-19814, CVE-2019-19816, CVE-2019-19813; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source