Content Library · Advisory

Advisory 2020

Browse 272 2020 NetApp advisory records in the NetApp Black Box content library. Page 3 of 3.

Library JSON API

Showing all 32 items on this page

Advisory

CVE-2020-8492 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200221-0001/

NetApp published this final advisory covering CVE-2020-8492; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-7471 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200221-0006/

NetApp published this final advisory covering CVE-2020-7471; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-9674 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200221-0003/

NetApp published this final advisory covering CVE-2019-9674; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

Intel SA-00329 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200210-0004/

NetApp published this final advisory covering CVE-2020-0548, CVE-2020-0549; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

February 2020 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200210-0003/

NetApp published this final advisory covering CVE-2020-7450, CVE-2019-5613, CVE-2019-15875; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-20386 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200210-0002/

NetApp published this final advisory covering CVE-2019-20386; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-18634 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200210-0001/

NetApp published this final advisory covering CVE-2019-18634; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

January 2020 NTP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200204-0003/

NetApp published this final advisory covering CVE-2015-8139, CVE-2015-8140; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

January 2020 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200204-0002/

NetApp published this final advisory covering CVE-2019-19966, CVE-2019-19965, CVE-2019-19947, CVE-2019-20054, CVE-2019-5108, CVE-2019-19922, CVE-2019-19927, CVE-2019-20095, CVE-2019-19332, CVE-2020-7053, CVE-2007-4774, CVE-2019-18282; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-19959 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200204-0001/

NetApp published this final advisory covering CVE-2019-19959; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2019-20372 NGINX vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200127-0003/

NetApp published this final advisory covering CVE-2019-20372; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2019-20330 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200127-0004/

NetApp published this final advisory covering CVE-2019-20330; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for VMware vSphere 9.5 and above; Active IQ Unified Manager (formerly OnCommand Unified Manager) for Windows 7.3 and above; NetApp Service Level Manager; NetApp SteelStore Cloud Integrated Storage; OnCommand API Services; SnapCenter.

Open source
Advisory

CVE-2019-15601 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200127-0002/

NetApp published this final advisory covering CVE-2019-15601; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

January 2020 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200122-0001/

NetApp published this final advisory covering CVE-2019-14902, CVE-2019-14907, CVE-2019-19344; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2020 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200122-0002/

NetApp published this final advisory covering CVE-2020-2579, CVE-2020-2686, CVE-2020-2627, CVE-2019-1547, CVE-2020-2572, CVE-2020-2573, CVE-2020-2574, CVE-2020-2577, CVE-2020-2580, CVE-2020-2584, CVE-2020-2588, CVE-2020-2589, CVE-2020-2660, CVE-2020-2679, CVE-2020-2694; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2020 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200122-0003/

NetApp published this final advisory covering CVE-2020-2604, CVE-2019-13117, CVE-2019-13118, CVE-2019-16168, CVE-2020-2583, CVE-2020-2585, CVE-2020-2590, CVE-2020-2593, CVE-2020-2601, CVE-2020-2654, CVE-2020-2655, CVE-2020-2659; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity Management Plug-ins (VMware vCenter); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Web Services (REST API) for Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer; NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; OnCommand Insight; OnCommand Workflow Automation; SANtricity Unified Manager.

Open source
Advisory

October 2019 Tcpdump Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200120-0001/

NetApp published this final advisory covering CVE-2018-10103, CVE-2018-10105, CVE-2018-14461, CVE-2018-14462, CVE-2018-14463, CVE-2018-14464, CVE-2018-14465, CVE-2018-14466, CVE-2018-14467, CVE-2018-14468, CVE-2018-14469, CVE-2018-14470, CVE-2018-14879, CVE-2018-14880, CVE-2018-14881, CVE-2018-14882, CVE-2018-16227, CVE-2018-16228, CVE-2018-16229, CVE-2018-16230, CVE-2018-16300, CVE-2018-16451, CVE-2018-16452, CVE-2019-15166; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-18218 File Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200115-0001/

NetApp published this final advisory covering CVE-2019-18218; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager (formerly OnCommand Unified Manager) for Linux 7.3 and above.

Open source
Advisory

January 2020 SQLite Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200114-0003/

NetApp published this final advisory covering CVE-2019-19923, CVE-2019-19924, CVE-2019-19925, CVE-2019-19926; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2019-19956 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200114-0002/

NetApp published this final advisory covering CVE-2019-19956; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp Manageability SDK; NetApp Plug-in for Symantec NetBackup; NetApp SteelStore Cloud Integrated Storage; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-19880 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200114-0001/

NetApp published this final advisory covering CVE-2019-19880; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2019-19844 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200110-0003/

NetApp published this final advisory covering CVE-2019-19844; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-17571 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200110-0001/

NetApp published this final advisory covering CVE-2019-17571; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand System Manager 3.x; OnCommand Workflow Automation.

Open source
Advisory

December 2019 Sudo Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200103-0004/

NetApp published this final advisory covering CVE-2019-19232, CVE-2019-19234; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node.

Open source
Advisory

December 2019 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200103-0002/

NetApp published this final advisory covering CVE-2019-11044, CVE-2019-11045, CVE-2019-11046, CVE-2019-11047, CVE-2019-11049, CVE-2019-11050; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2019 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20200103-0001/

NetApp published this final advisory covering CVE-2019-14815, CVE-2019-19227, CVE-2019-10220, CVE-2019-19318, CVE-2019-14896, CVE-2019-19252, CVE-2019-18660, CVE-2019-19319, CVE-2019-10207, CVE-2019-18675, CVE-2019-19602, CVE-2019-19378, CVE-2019-19377, CVE-2019-19447, CVE-2019-19448, CVE-2019-19449, CVE-2019-19768, CVE-2019-19769, CVE-2019-19770, CVE-2019-19767, CVE-2019-19807, CVE-2019-19241, CVE-2019-19815, CVE-2019-19814, CVE-2019-19816, CVE-2019-19813; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp Data Availability Services; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source