Content Library · Advisory

Advisory 2021

Browse 447 2021 NetApp advisory records in the NetApp Black Box content library.

Library JSON API

Advisory

December 2021 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211229-0004/

NetApp published this final advisory covering CVE-2021-41090, CVE-2021-43798; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-44420 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211229-0006/

NetApp published this final advisory covering CVE-2021-44420; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-43527 Libnss Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211229-0002/

NetApp published this final advisory covering CVE-2021-43527; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-42550 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211229-0001/

NetApp published this final advisory covering CVE-2021-42550; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp BlueXP; NetApp Service Level Manager; Snap Creator Framework.

Open source
Advisory

CVE-2021-41805 HashiCorp Consul Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211229-0007/

NetApp published this final advisory covering CVE-2021-41805; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-4044 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211229-0003/

NetApp published this final advisory covering CVE-2021-4044; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp E-Series Performance Analyzer; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP Select Deploy administration utility; SnapCenter.

Open source
Advisory

CVE-2018-25020 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211229-0005/

NetApp published this final advisory covering CVE-2018-25020; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

November 2021 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211223-0006/

NetApp published this final advisory covering CVE-2021-20470, CVE-2021-20493, CVE-2021-29716, CVE-2021-29719, CVE-2021-29756, CVE-2021-29867, CVE-2021-38909; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

November 2021 BusyBox Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211223-0002/

NetApp published this final advisory covering CVE-2021-42373, CVE-2021-42374, CVE-2021-42375, CVE-2021-42376, CVE-2021-42377, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381, CVE-2021-42382, CVE-2021-42383, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2021-41244 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211223-0001/

NetApp published this final advisory covering CVE-2021-41244; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-4104 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211223-0007/

NetApp published this final advisory covering CVE-2021-4104; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23732 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211223-0004/

NetApp published this final advisory covering CVE-2021-23732; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-21707 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211223-0005/

NetApp published this final advisory covering CVE-2021-21707; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

CVE-2017-5123 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211223-0003/

NetApp published this final advisory covering CVE-2017-5123; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-45105 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211218-0001/

NetApp published this final advisory covering CVE-2021-45105; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager; Cloud Secure Agent; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere.

Open source
Advisory

CVE-2021-45046 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211215-0001/

NetApp published this final advisory covering CVE-2021-45046; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Cloud Insights Acquisition Unit; Cloud Manager; Cloud Secure Agent; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere; OnCommand Insight; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

November 2021 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211210-0001/

NetApp published this final advisory covering CVE-2021-43975, CVE-2021-43976; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

November 2021 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211210-0003/

NetApp published this interim advisory covering CVE-2021-41771, CVE-2021-41772; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00555 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211210-0005/

NetApp published this final advisory covering CVE-2021-33058, CVE-2021-33059, CVE-2021-33098; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00554 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211210-0004/

NetApp published this final advisory covering CVE-2021-0197, CVE-2021-0198, CVE-2021-0199, CVE-2021-0200; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-44228 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211210-0007/

NetApp published this final advisory covering CVE-2021-44228; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Cloud Insights Acquisition Unit; Cloud Manager; Cloud Secure Agent; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere; OnCommand Insight; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2021-43616 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211210-0002/

NetApp published this final advisory covering CVE-2021-43616; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2021 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211206-0001/

NetApp published this final advisory covering CVE-2016-2124, CVE-2020-25717, CVE-2020-25718, CVE-2020-25719, CVE-2020-25721, CVE-2020-25722, CVE-2021-23192, CVE-2021-3738; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2021 BlueZ Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211203-0002/

NetApp published this final advisory covering CVE-2019-8921, CVE-2019-8922; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-41229 BlueZ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211203-0004/

NetApp published this final advisory covering CVE-2021-41229; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3715 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211203-0003/

NetApp published this final advisory covering CVE-2021-3715; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-25742 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211203-0001/

NetApp published this final advisory covering CVE-2021-25742; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23718 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211203-0005/

NetApp published this final advisory covering CVE-2021-23718; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-43267 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211125-0002/

NetApp published this final advisory covering CVE-2021-43267; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-43057 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211125-0001/

NetApp published this final advisory covering CVE-2021-43057; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-41174 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211125-0003/

NetApp published this final advisory covering CVE-2021-41174; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22096 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211125-0005/

NetApp published this final advisory covering CVE-2021-22096; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; MetroCluster Tiebreaker for clustered Data ONTAP; OnCommand Insight; Snap Creator Framework; SnapCenter.

Open source
Advisory

CVE-2011-1075 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211125-0004/

NetApp published this final advisory covering CVE-2011-1075; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

October 2021 jQuery Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211118-0004/

NetApp published this final advisory covering CVE-2021-41182, CVE-2021-41183, CVE-2021-41184; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Virtual Desktop Service (VDS); SnapCenter.

Open source
Advisory

CVE-2021-42739 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211118-0001/

NetApp published this final advisory covering CVE-2021-42739; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-42327 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211118-0005/

NetApp published this final advisory covering CVE-2021-42327; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-38297 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211118-0006/

NetApp published this final advisory covering CVE-2021-38297; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-25219 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211118-0002/

NetApp published this final advisory covering CVE-2021-25219; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-21703 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211118-0003/

NetApp published this final advisory covering CVE-2021-21703; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

October 2021 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211112-0003/

NetApp published this final advisory covering CVE-2021-32028, CVE-2021-32029; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2021 Libwebp Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211112-0001/

NetApp published this final advisory covering CVE-2018-25010, CVE-2018-25012, CVE-2018-25013, CVE-2020-36328, CVE-2020-36329, CVE-2020-36331; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-42252 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211112-0006/

NetApp published this final advisory covering CVE-2021-42252; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-22930 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211112-0002/

NetApp published this final advisory covering CVE-2021-22930; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2021 Redis Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211104-0003/

NetApp published this final advisory covering CVE-2021-32628, CVE-2021-41099, CVE-2021-32672, CVE-2021-32762, CVE-2021-32626, CVE-2021-32627, CVE-2021-32765, CVE-2021-32687, CVE-2021-32675; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

October 2021 Libwebp Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211104-0004/

NetApp published this final advisory covering CVE-2018-25009, CVE-2018-25011, CVE-2018-25014, CVE-2020-36330, CVE-2020-36332; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-42008 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211104-0002/

NetApp published this final advisory covering CVE-2021-42008; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3580 Nettle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211104-0006/

NetApp published this final advisory covering CVE-2021-3580; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3520 lz4 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211104-0005/

NetApp published this final advisory covering CVE-2021-3520; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-33910 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211104-0008/

NetApp published this final advisory covering CVE-2021-33910; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

September 2021 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211029-0003/

NetApp published this final advisory covering CVE-2021-22945, CVE-2021-22946, CVE-2021-22947; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

September 2021 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211029-0006/

NetApp published this final advisory covering CVE-2021-21704, CVE-2021-21705; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

September 2021 IBM Db2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211029-0005/

NetApp published this final advisory covering CVE-2021-29825, CVE-2021-29763; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-41864 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211029-0004/

NetApp published this interim advisory covering CVE-2021-41864; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-39226 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211029-0008/

NetApp published this final advisory covering CVE-2021-39226; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23449 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211029-0010/

NetApp published this final advisory covering CVE-2021-23449; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-21706 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211029-0007/

NetApp published this final advisory covering CVE-2021-21706; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2021 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211022-0003/

NetApp published this final advisory covering CVE-2021-22926, CVE-2021-22931, CVE-2021-2478, CVE-2021-2479, CVE-2021-2481, CVE-2021-35537, CVE-2021-35546, CVE-2021-35575, CVE-2021-35577, CVE-2021-35583, CVE-2021-35584, CVE-2021-35590, CVE-2021-35591, CVE-2021-35592, CVE-2021-35593, CVE-2021-35594, CVE-2021-35596, CVE-2021-35598, CVE-2021-35602, CVE-2021-35604, CVE-2021-35607, CVE-2021-35608, CVE-2021-35610, CVE-2021-35612, CVE-2021-35613, CVE-2021-35618, CVE-2021-35621, CVE-2021-35622, CVE-2021-35623, CVE-2021-35624, CVE-2021-35625, CVE-2021-35626, CVE-2021-35627, CVE-2021-35628, CVE-2021-35629, CVE-2021-35630, CVE-2021-35631, CVE-2021-35632, CVE-2021-35633, CVE-2021-35634, CVE-2021-35635, CVE-2021-35636, CVE-2021-35637, CVE-2021-35638, CVE-2021-35639, CVE-2021-35640, CVE-2021-35641, CVE-2021-35642, CVE-2021-35643, CVE-2021-35644, CVE-2021-35645, CVE-2021-35646, CVE-2021-35647, CVE-2021-35648, CVE-2021-36222, CVE-2021-3711; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2021 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211022-0004/

NetApp published this interim advisory covering CVE-2021-3517, CVE-2021-35560, CVE-2021-35567, CVE-2021-35550, CVE-2021-3522, CVE-2021-35586, CVE-2021-35564, CVE-2021-35556, CVE-2021-35559, CVE-2021-35561, CVE-2021-35565, CVE-2021-35578, CVE-2021-35603, CVE-2021-35588; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Insights Acquisition Unit; Cloud Secure Agent; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; OnCommand Insight; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP; SolidFire Storage Replication Adapter.

Open source
Advisory

July 2021 Apache Commons Compress Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211022-0001/

NetApp published this final advisory covering CVE-2021-36090, CVE-2021-35515, CVE-2021-35516, CVE-2021-35517; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Insights Acquisition Unit; OnCommand Insight.

Open source
Advisory

CVE-2021-35597 MySQL Client Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211022-0005/

NetApp published this final advisory covering CVE-2021-35597; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2021-20305 Nettle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211022-0002/

NetApp published this final advisory covering CVE-2021-20305; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-41617 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211014-0004/

NetApp published this interim advisory covering CVE-2021-41617; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-41073 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211014-0003/

NetApp published this final advisory covering CVE-2021-41073; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-25740 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211014-0001/

NetApp published this final advisory covering CVE-2021-25740; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8561 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211014-0002/

NetApp published this final advisory covering CVE-2020-8561; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2016-20012 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211014-0005/

NetApp published this final advisory covering CVE-2016-20012; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2021 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211008-0004/

NetApp published this final advisory covering CVE-2021-34798, CVE-2021-36160, CVE-2021-39275, CVE-2021-40438; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); ONTAP 9; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2021-40839 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211008-0001/

NetApp published this final advisory covering CVE-2021-40839; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-38300 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211008-0003/

NetApp published this final advisory covering CVE-2021-38300; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-25741 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211008-0006/

NetApp published this final advisory covering CVE-2021-25741; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22147 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211008-0002/

NetApp published this final advisory covering CVE-2021-22147; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2021 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211004-0005/

NetApp published this final advisory covering CVE-2020-19143, CVE-2020-19144; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-40490 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211004-0001/

NetApp published this interim advisory covering CVE-2021-40490; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3634 libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211004-0003/

NetApp published this final advisory covering CVE-2021-3634; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-25737 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211004-0004/

NetApp published this final advisory covering CVE-2021-25737; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-16871 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20211004-0002/

NetApp published this final advisory covering CVE-2018-16871; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3713 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210923-0006/

NetApp published this final advisory covering CVE-2021-3713; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29631 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210923-0004/

NetApp published this final advisory covering CVE-2021-29631; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-29630 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210923-0005/

NetApp published this final advisory covering CVE-2021-29630; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

August 2021 XStream Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210923-0003/

NetApp published this interim advisory covering CVE-2021-39139, CVE-2021-39140, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145, CVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149, CVE-2021-39150, CVE-2021-39151, CVE-2021-39152, CVE-2021-39153, CVE-2021-39154; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

August 2021 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210923-0001/

NetApp published this final advisory covering CVE-2021-22931, CVE-2021-22940; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-37576 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210917-0005/

NetApp published this final advisory covering CVE-2021-37576; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-33193 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210917-0004/

NetApp published this final advisory covering CVE-2021-33193; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-31810 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210917-0001/

NetApp published this final advisory covering CVE-2021-31810; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-30468 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210917-0002/

NetApp published this final advisory covering CVE-2021-30468; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22939 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210917-0003/

NetApp published this final advisory covering CVE-2021-22939; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-38604 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210909-0005/

NetApp published this interim advisory covering CVE-2021-38604; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-38166 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210909-0001/

NetApp published this interim advisory covering CVE-2021-38166; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-36770 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210909-0003/

NetApp published this final advisory covering CVE-2021-36770; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility; Snap Creator Framework.

Open source
Advisory

CVE-2021-25218 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210909-0002/

NetApp published this final advisory covering CVE-2021-25218; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2020-22403 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210909-0004/

NetApp published this final advisory covering CVE-2020-22403; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-38207 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0007/

NetApp published this final advisory covering CVE-2021-38207; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3682 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0006/

NetApp published this final advisory covering CVE-2021-3682; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29657 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0008/

NetApp published this final advisory covering CVE-2021-29657; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2012-2666 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0009/

NetApp published this final advisory covering CVE-2012-2666; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2021 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0003/

NetApp published this interim advisory covering CVE-2021-22922, CVE-2021-22923, CVE-2021-22924, CVE-2021-22925, CVE-2021-22926; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

August 2021 Ruby Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0004/

NetApp published this final advisory covering CVE-2021-28966, CVE-2021-31799, CVE-2021-32066; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2021 Linux Kernel 5.13.4 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210902-0010/

NetApp published this interim advisory covering CVE-2021-38160, CVE-2021-38199, CVE-2021-38201, CVE-2021-38202, CVE-2021-38203; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

July 2021 Elasticsearch Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0006/

NetApp published this final advisory covering CVE-2021-22144, CVE-2021-22145; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2021 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0007/

NetApp published this final advisory covering CVE-2021-30639, CVE-2021-30640, CVE-2021-33037; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

Intel SA-00515 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0008/

NetApp published this final advisory covering CVE-2021-0002, CVE-2021-0003, CVE-2021-0084; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00479 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0009/

NetApp published this final advisory covering CVE-2021-0004, CVE-2021-0005, CVE-2021-0006, CVE-2021-0007, CVE-2021-0008, CVE-2021-0009; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-35942 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0005/

NetApp published this final advisory covering CVE-2021-35942; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-32761 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0004/

NetApp published this final advisory covering CVE-2021-32761; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

August 2021 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210827-0010/

NetApp published this interim advisory covering CVE-2021-3711, CVE-2021-3712; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Global File Cache; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Converged Systems Advisor Agent; NetApp E-Series Performance Analyzer; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp Storage Encryption; ONTAP 9; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

May 2021 Brocade Fabric OS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0002/

NetApp published this final advisory covering CVE-2021-27792, CVE-2021-27791, CVE-2021-27790, CVE-2021-27789, CVE-2020-15388, CVE-2020-15386, CVE-2020-15383; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

July 2021 Apache Ant Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0007/

NetApp published this final advisory covering CVE-2021-36373, CVE-2021-36374; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-37159 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0003/

NetApp published this final advisory covering CVE-2021-37159; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-34429 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0006/

NetApp published this final advisory covering CVE-2021-34429; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; SANtricity Storage Plugin for vCenter; Snap Creator Framework; SnapCenter Plug-in for VMware vSphere/BlueXP backup and Recovery for Virtual Machine.

Open source
Advisory

CVE-2021-33909 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0004/

NetApp published this final advisory covering CVE-2021-33909; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-22146 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210819-0005/

NetApp published this final advisory covering CVE-2021-22146; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-35039 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210813-0004/

NetApp published this final advisory covering CVE-2021-35039; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-34558 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210813-0005/

NetApp published this final advisory covering CVE-2021-34558; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident; Cloud Insights Telegraf Agent; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2021-34428 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210813-0003/

NetApp published this final advisory covering CVE-2021-34428; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; NetApp SANtricity Cloud Connector; SANtricity Storage Plugin for vCenter; Snap Creator Framework; SnapManager for SAP.

Open source
Advisory

CVE-2021-32078 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210813-0002/

NetApp published this final advisory covering CVE-2021-32078; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-31535 X.Org X Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210813-0001/

NetApp published this final advisory covering CVE-2021-31535; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

June 2021 Ruby Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0009/

NetApp published this final advisory covering CVE-2021-22904, CVE-2021-22880, CVE-2021-22885; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2021 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0004/

NetApp published this final advisory covering CVE-2021-3592, CVE-2021-3593, CVE-2021-3594, CVE-2021-3595; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2021 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0003/

NetApp published this final advisory covering CVE-2021-22918, CVE-2021-22921; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3612 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0005/

NetApp published this final advisory covering CVE-2021-3612; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3541 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0007/

NetApp published this interim advisory covering CVE-2021-3541; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Manageability SDK; NetApp SMI-S Provider; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix; SnapManager for Hyper-V.

Open source
Advisory

CVE-2021-35042 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0008/

NetApp published this final advisory covering CVE-2021-35042; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28691 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0002/

NetApp published this final advisory covering CVE-2021-28691; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-22555 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0010/

NetApp published this interim advisory covering CVE-2021-22555; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-28097 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0001/

NetApp published this final advisory covering CVE-2020-28097; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2017-20005 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210805-0006/

NetApp published this final advisory covering CVE-2017-20005; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

June 2021 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0007/

NetApp published this final advisory covering CVE-2021-22897, CVE-2021-22901; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

June 2021 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0004/

NetApp published this final advisory covering CVE-2021-33203, CVE-2021-33571; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28169 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0009/

NetApp published this final advisory covering CVE-2021-28169; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Management Services for Element Software and NetApp HCI; Snap Creator Framework.

Open source
Advisory

CVE-2020-36387 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0006/

NetApp published this final advisory covering CVE-2020-36387; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2019-12067 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0001/

NetApp published this final advisory covering CVE-2019-12067; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2013-4536 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0002/

NetApp published this final advisory covering CVE-2013-4536; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2002-2438 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210727-0003/

NetApp published this final advisory covering CVE-2002-2438; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

July 2021 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210723-0001/

NetApp published this final advisory covering CVE-2019-17543, CVE-2021-22884, CVE-2021-22901, CVE-2021-2339, CVE-2021-2340, CVE-2021-2342, CVE-2021-2352, CVE-2021-2354, CVE-2021-2356, CVE-2021-2357, CVE-2021-2367, CVE-2021-2370, CVE-2021-2372, CVE-2021-2374, CVE-2021-2383, CVE-2021-2384, CVE-2021-2385, CVE-2021-2387, CVE-2021-2389, CVE-2021-2390, CVE-2021-2399, CVE-2021-2402, CVE-2021-2410, CVE-2021-2411, CVE-2021-2412, CVE-2021-2417, CVE-2021-2418, CVE-2021-2422, CVE-2021-2424, CVE-2021-2425, CVE-2021-2426, CVE-2021-2427, CVE-2021-2429, CVE-2021-2437, CVE-2021-2440, CVE-2021-2441, CVE-2021-2444; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2021 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210723-0002/

NetApp published this interim advisory covering CVE-2021-2388, CVE-2021-2369, CVE-2021-2432, CVE-2021-2341; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Secure Agent; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

June 2021 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0008/

NetApp published this final advisory covering CVE-2021-3544, CVE-2021-3545, CVE-2021-3546, CVE-2020-35503; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2021 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0006/

NetApp published this final advisory covering CVE-2020-4885, CVE-2020-4945, CVE-2021-20579, CVE-2021-29703, CVE-2021-29777; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29702 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0005/

NetApp published this final advisory covering CVE-2021-29702; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20181 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0009/

NetApp published this final advisory covering CVE-2021-20181; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-36385 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0004/

NetApp published this final advisory covering CVE-2020-36385; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27661 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0010/

NetApp published this final advisory covering CVE-2020-27661; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-25045 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0003/

NetApp published this interim advisory covering CVE-2019-25045; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2018-25015 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210720-0002/

NetApp published this final advisory covering CVE-2018-25015; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

June 2021 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0007/

NetApp published this final advisory covering CVE-2021-28651, CVE-2021-31806, CVE-2021-31807, CVE-2021-31808; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

June 2021 OpenLDAP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0003/

NetApp published this final advisory covering CVE-2020-25709, CVE-2020-25710; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

June 2021 Linux Kernel 5.12.4 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0004/

NetApp published this final advisory covering CVE-2021-3489, CVE-2021-3490, CVE-2021-3491; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3530 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0006/

NetApp published this final advisory covering CVE-2021-3530; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3516 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0005/

NetApp published this final advisory covering CVE-2021-3516; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SMI-S Provider; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-26707 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0008/

NetApp published this final advisory covering CVE-2021-26707; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-0129 Intel BlueZ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0002/

NetApp published this final advisory covering CVE-2021-0129; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-0051 Intel SPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210716-0001/

NetApp published this final advisory covering CVE-2021-0051; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

May 2021 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210713-0006/

NetApp published this final advisory covering CVE-2020-35504, CVE-2020-35505, CVE-2020-35506; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-32027 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210713-0004/

NetApp published this final advisory covering CVE-2021-32027; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29629 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210713-0003/

NetApp published this final advisory covering CVE-2021-29629; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29628 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210713-0002/

NetApp published this final advisory covering CVE-2021-29628; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3527 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0008/

NetApp published this final advisory covering CVE-2021-3527; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-30465 Opencontainers-runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0003/

NetApp published this final advisory covering CVE-2021-30465; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29505 XStream Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0007/

NetApp published this final advisory covering CVE-2021-29505; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2021-23017 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0006/

NetApp published this final advisory covering CVE-2021-23017; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-22543 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0002/

NetApp published this final advisory covering CVE-2021-22543; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-20221 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0005/

NetApp published this final advisory covering CVE-2021-20221; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20196 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0004/

NetApp published this final advisory covering CVE-2021-20196; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10701 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210708-0001/

NetApp published this final advisory covering CVE-2020-10701; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3559 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0006/

NetApp published this final advisory covering CVE-2021-3559; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-33587 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0007/

NetApp published this final advisory covering CVE-2021-33587; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-33502 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0001/

NetApp published this final advisory covering CVE-2021-33502; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-33200 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0004/

NetApp published this final advisory covering CVE-2021-33200; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-32640 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0005/

NetApp published this final advisory covering CVE-2021-32640; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-31440 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0003/

NetApp published this final advisory covering CVE-2021-31440; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-10688 RESTEasy Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210706-0008/

NetApp published this final advisory covering CVE-2020-10688; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2021 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0008/

NetApp published this final advisory covering CVE-2020-25670, CVE-2020-25671, CVE-2020-25672, CVE-2020-25673; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

June 2021 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0001/

NetApp published this final advisory covering CVE-2019-17567, CVE-2020-13938, CVE-2020-13950, CVE-2020-35452, CVE-2021-26690, CVE-2021-26691, CVE-2021-30641; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

Intel SA-00463 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0002/

NetApp published this interim advisory covering CVE-2020-8670, CVE-2020-8700, CVE-2020-12357, CVE-2020-12358, CVE-2020-12359, CVE-2020-12360, CVE-2020-24486; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series BIOS; FAS/AFF BIOS - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

CVE-2021-33623 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0007/

NetApp published this final advisory covering CVE-2021-33623; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2020-27815 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0004/

NetApp published this final advisory covering CVE-2020-27815; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25724 RESTEasy Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0003/

NetApp published this final advisory covering CVE-2020-25724; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25669 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0006/

NetApp published this final advisory covering CVE-2020-25669; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25668 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210702-0005/

NetApp published this final advisory covering CVE-2020-25668; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3483 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0002/

NetApp published this final advisory covering CVE-2021-3483; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3426 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0003/

NetApp published this final advisory covering CVE-2021-3426; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility; SnapCenter.

Open source
Advisory

CVE-2021-33574 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0005/

NetApp published this final advisory covering CVE-2021-33574; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-22138 Logstash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0001/

NetApp published this final advisory covering CVE-2021-22138; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-14301 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0007/

NetApp published this final advisory covering CVE-2020-14301; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-4588 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0004/

NetApp published this final advisory covering CVE-2019-4588; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-25044 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210629-0006/

NetApp published this final advisory covering CVE-2019-25044; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

May 2021 Libxml2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0002/

NetApp published this final advisory covering CVE-2021-3517, CVE-2021-3518, CVE-2021-3537; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Manageability SDK; NetApp SMI-S Provider; ONTAP 9; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

May 2021 Elasticsearch Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0003/

NetApp published this final advisory covering CVE-2021-22135, CVE-2021-22137; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-33204 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0006/

NetApp published this final advisory covering CVE-2021-33204; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-32606 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0001/

NetApp published this final advisory covering CVE-2021-32606; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-23134 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0007/

NetApp published this final advisory covering CVE-2021-23134; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-0095 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0009/

NetApp published this final advisory covering CVE-2021-0095; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2020-27830 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0004/

NetApp published this final advisory covering CVE-2020-27830; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-13529 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210625-0005/

NetApp published this interim advisory covering CVE-2020-13529; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

June 2021 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0004/

NetApp published this final advisory covering CVE-2019-4471, CVE-2019-4653, CVE-2019-4722, CVE-2019-4723, CVE-2019-4724, CVE-2019-4730, CVE-2020-4300, CVE-2020-4354, CVE-2020-4520, CVE-2020-4561; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

February 2021 MySQL Client Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0001/

NetApp published this final advisory covering CVE-2020-14550, CVE-2021-2006, CVE-2021-2007, CVE-2021-2010, CVE-2021-2011; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2021-32399 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0006/

NetApp published this final advisory covering CVE-2021-32399; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-29921 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0003/

NetApp published this final advisory covering CVE-2021-29921; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp XCP NFS; NetApp XCP SMB; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-29491 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0002/

NetApp published this final advisory covering CVE-2021-29491; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29489 Highcharts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0005/

NetApp published this final advisory covering CVE-2021-29489; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2020-15522 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210622-0007/

NetApp published this final advisory covering CVE-2020-15522; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; OnCommand Insight; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter; SnapCenter.

Open source
Advisory

CVE-2021-3501 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0008/

NetApp published this final advisory covering CVE-2021-3501; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-31879 GNU Wget Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0002/

NetApp published this interim advisory covering CVE-2021-31879; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-31597 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0004/

NetApp published this final advisory covering CVE-2021-31597; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31542 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0001/

NetApp published this final advisory covering CVE-2021-31542; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31542 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0010/

NetApp published this final advisory covering CVE-2021-31542; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29484 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0006/

NetApp published this final advisory covering CVE-2021-29484; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28860 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0005/

NetApp published this final advisory covering CVE-2021-28860; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23383 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0007/

NetApp published this final advisory covering CVE-2021-23383; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-21414 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0003/

NetApp published this final advisory covering CVE-2021-21414; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-35519 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0009/

NetApp published this final advisory covering CVE-2020-35519; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

Intel SA-00464 Intel Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0005/

NetApp published this final advisory covering CVE-2020-24511, CVE-2020-24512; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

Intel SA-00459 CSME Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0004/

NetApp published this final advisory covering CVE-2020-8703, CVE-2020-24506, CVE-2020-24507; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-3506 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0007/

NetApp published this final advisory covering CVE-2021-3506; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-32052 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0002/

NetApp published this final advisory covering CVE-2021-32052; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31231 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0001/

NetApp published this final advisory covering CVE-2021-31231; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29469 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0010/

NetApp published this final advisory covering CVE-2021-29469; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-27905 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0009/

NetApp published this final advisory covering CVE-2021-27905; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23133 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0008/

NetApp published this final advisory covering CVE-2021-23133; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

April 2021 Eclipse Jetty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0006/

NetApp published this final advisory covering CVE-2021-28163, CVE-2021-28164, CVE-2021-28165; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; NetApp BlueXP; NetApp E-Series Performance Analyzer; NetApp SANtricity Cloud Connector; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; ONTAP tools for VMware vSphere 9; SANtricity Storage Plugin for vCenter; SnapCenter; SnapCenter Plug-in for VMware vSphere/BlueXP backup and Recovery for Virtual Machine; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above.

Open source
Advisory

March 2021 Apache Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0003/

NetApp published this final advisory covering CVE-2021-21295, CVE-2021-21409; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand API Services; OnCommand Workflow Automation.

Open source
Advisory

CVE-2021-29662 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0002/

NetApp published this final advisory covering CVE-2021-29662; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); SnapCenter.

Open source
Advisory

CVE-2021-29424 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0007/

NetApp published this final advisory covering CVE-2021-29424; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-29418 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0001/

NetApp published this final advisory covering CVE-2021-29418; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29154 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0006/

NetApp published this final advisory covering CVE-2021-29154; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-26073 Node.JS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0004/

NetApp published this final advisory covering CVE-2021-26073; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23369 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0008/

NetApp published this final advisory covering CVE-2021-23369; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-36313 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0005/

NetApp published this final advisory covering CVE-2020-36313; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-15225 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0010/

NetApp published this final advisory covering CVE-2020-15225; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2021 Apache Solr Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0009/

NetApp published this final advisory covering CVE-2021-29943, CVE-2021-29262; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3507 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0005/

NetApp published this final advisory covering CVE-2021-3507; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-30638 Apache Tapestry Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0004/

NetApp published this final advisory covering CVE-2021-30638; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28965 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0003/

NetApp published this final advisory covering CVE-2021-28965; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28918 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0010/

NetApp published this final advisory covering CVE-2021-28918; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28658 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0001/

NetApp published this final advisory covering CVE-2021-28658; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-27850 Apache Tapestry Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0002/

NetApp published this final advisory covering CVE-2021-27850; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-21267 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0006/

NetApp published this final advisory covering CVE-2021-21267; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer; OnCommand Insight.

Open source
Advisory

CVE-2021-20197 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0009/

NetApp published this final advisory covering CVE-2021-20197; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

March 2021 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0009/

NetApp published this final advisory covering CVE-2020-35521, CVE-2020-35522, CVE-2020-35523, CVE-2020-35524; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-20284 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0010/

NetApp published this final advisory covering CVE-2021-20284; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-27825 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0008/

NetApp published this final advisory covering CVE-2020-27825; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-17516 Apache Cassandra Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0002/

NetApp published this final advisory covering CVE-2020-17516; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-12762 JSON-C Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0001/

NetApp published this final advisory covering CVE-2020-12762; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2021 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0007/

NetApp published this interim advisory covering CVE-2021-22876, CVE-2021-22890; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software).

Open source
Advisory

April 2021 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0006/

NetApp published this final advisory covering CVE-2021-25214, CVE-2021-25215, CVE-2021-25216; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-29266 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0005/

NetApp published this final advisory covering CVE-2021-29266; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-28092 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0008/

NetApp published this final advisory covering CVE-2021-28092; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-27358 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0007/

NetApp published this final advisory covering CVE-2021-27358; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-23926 Apache XMLBeans Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0004/

NetApp published this final advisory covering CVE-2021-23926; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager Core Package; Snap Creator Framework; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2020-35508 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0006/

NetApp published this final advisory covering CVE-2020-35508; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-13954 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0010/

NetApp published this final advisory covering CVE-2020-13954; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; Snap Creator Framework.

Open source
Advisory

April 2021 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0002/

NetApp published this final advisory covering CVE-2020-1971, CVE-2021-3449, CVE-2020-28196, CVE-2021-23841, CVE-2021-2144, CVE-2021-2172, CVE-2021-2298, CVE-2021-2178, CVE-2021-2202, CVE-2021-2307, CVE-2021-2304, CVE-2021-2180, CVE-2021-2194, CVE-2021-2154, CVE-2021-2166, CVE-2021-2196, CVE-2021-2300, CVE-2021-2305, CVE-2021-2179, CVE-2021-2226, CVE-2021-2160, CVE-2021-2164, CVE-2021-2169, CVE-2021-2170, CVE-2021-2193, CVE-2021-2203, CVE-2021-2212, CVE-2021-2213, CVE-2021-2278, CVE-2021-2299, CVE-2021-2230, CVE-2021-2146, CVE-2021-2201, CVE-2021-2208, CVE-2021-2215, CVE-2021-2217, CVE-2021-2293, CVE-2021-2174, CVE-2021-2171, CVE-2021-2162, CVE-2021-2301, CVE-2021-2308, CVE-2021-2232; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2021 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0001/

NetApp published this interim advisory covering CVE-2021-2161, CVE-2021-2163; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Secure Agent; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

March 2021 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0001/

NetApp published this final advisory covering CVE-2021-3392, CVE-2021-3409; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3393 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0006/

NetApp published this final advisory covering CVE-2021-3393; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28660 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0008/

NetApp published this final advisory covering CVE-2021-28660; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-28657 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0004/

NetApp published this final advisory covering CVE-2021-28657; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20255 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0003/

NetApp published this final advisory covering CVE-2021-20255; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-36309 OpenResty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0005/

NetApp published this final advisory covering CVE-2020-36309; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2021 Unbound Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0007/

NetApp published this final advisory covering CVE-2019-25031, CVE-2019-25032, CVE-2019-25033, CVE-2019-25034, CVE-2019-25035, CVE-2019-25036, CVE-2019-25037, CVE-2019-25038, CVE-2019-25039, CVE-2019-25040, CVE-2019-25041, CVE-2019-25042; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2021 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0002/

NetApp published this final advisory covering CVE-2021-3416, CVE-2021-20263; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2021 XStream Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0002/

NetApp published this final advisory covering CVE-2021-21341, CVE-2021-21342, CVE-2021-21343, CVE-2021-21344, CVE-2021-21345, CVE-2021-21346, CVE-2021-21347, CVE-2021-21348, CVE-2021-21349, CVE-2021-21350, CVE-2021-21351; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

March 2021 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0004/

NetApp published this final advisory covering CVE-2019-10127, CVE-2019-10128; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2021 Linux Kernel 5.11.8 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0003/

NetApp published this final advisory covering CVE-2021-28951, CVE-2021-28952, CVE-2021-28964, CVE-2021-28971, CVE-2021-28972; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

March 2021 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0005/

NetApp published this final advisory covering CVE-2021-28147, CVE-2021-28148; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22134 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0006/

NetApp published this final advisory covering CVE-2021-22134; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20254 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0001/

NetApp published this final advisory covering CVE-2021-20254; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29627 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0007/

NetApp published this final advisory covering CVE-2021-29627; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29626 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0008/

NetApp published this final advisory covering CVE-2021-29626; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20227 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0010/

NetApp published this final advisory covering CVE-2021-20227; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25584 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0009/

NetApp published this final advisory covering CVE-2020-25584; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25583 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0004/

NetApp published this final advisory covering CVE-2020-25583; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25582 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0003/

NetApp published this final advisory covering CVE-2020-25582; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25581 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0006/

NetApp published this final advisory covering CVE-2020-25581; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25580 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0005/

NetApp published this final advisory covering CVE-2020-25580; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25577 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0001/

NetApp published this final advisory covering CVE-2020-25577; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2021 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0002/

NetApp published this final advisory covering CVE-2020-25578, CVE-2020-25579; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2021 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0001/

NetApp published this final advisory covering CVE-2021-22883, CVE-2021-22884; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

March 2021 GnuTLS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0005/

NetApp published this final advisory covering CVE-2021-20231, CVE-2021-20232; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-3444 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0006/

NetApp published this final advisory covering CVE-2021-3444; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-28041 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0002/

NetApp published this interim advisory covering CVE-2021-28041; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-14372 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0004/

NetApp published this final advisory covering CVE-2020-14372; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

March 2021 Linux Kernel 5.11.3 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0001/

NetApp published this final advisory covering CVE-2021-27363, CVE-2021-27364, CVE-2021-27365, CVE-2021-28038, CVE-2021-28039; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

March 2021 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0003/

NetApp published this final advisory covering CVE-2020-4976, CVE-2020-5024, CVE-2020-5025; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

March 2021 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0002/

NetApp published this final advisory covering CVE-2021-25329, CVE-2021-25122; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Storage Workload Security Agent; Element Plug-in for vCenter Server.

Open source
Advisory

December 2020 XStream Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0005/

NetApp published this final advisory covering CVE-2020-26258, CVE-2020-26259; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20268 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0006/

NetApp published this final advisory covering CVE-2021-20268; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-26217 XStream Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0004/

NetApp published this final advisory covering CVE-2020-26217; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2021-3189 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210401-0004/

NetApp published this final advisory covering CVE-2021-3189; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28375 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210401-0003/

NetApp published this interim advisory covering CVE-2021-28375; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27618 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210401-0006/

NetApp published this final advisory covering CVE-2020-27618; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-27543 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210401-0002/

NetApp published this final advisory covering CVE-2020-27543; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-27223 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210401-0005/

NetApp published this final advisory covering CVE-2020-27223; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; NetApp SolidFire & HCI Management Node; SANtricity Storage Plugin for vCenter; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

March 2021 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0007/

NetApp published this final advisory covering CVE-2021-20277, CVE-2020-27840; the API labels exploitation information as **Not public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2021 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0006/

NetApp published this final advisory covering CVE-2021-3449, CVE-2021-3450; the API labels exploitation information as **Not public**. The API currently lists affected products as: Cloud Volumes ONTAP Mediator; Global File Cache; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp E-Series Performance Analyzer; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility; OnCommand Workflow Automation; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

February 2021 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0001/

NetApp published this final advisory covering CVE-2021-26930, CVE-2021-26931, CVE-2021-26932, CVE-2021-26934; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-27405 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0002/

NetApp published this final advisory covering CVE-2021-27405; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23336 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0004/

NetApp published this final advisory covering CVE-2021-23336; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility; SnapCenter.

Open source
Advisory

CVE-2021-20229 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0005/

NetApp published this final advisory covering CVE-2021-20229; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20194 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0003/

NetApp published this final advisory covering CVE-2021-20194; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

February 2021 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210319-0002/

NetApp published this final advisory covering CVE-2021-27185, CVE-2021-27191; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2021 GNOME GLib Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210319-0004/

NetApp published this final advisory covering CVE-2021-27218, CVE-2021-27219; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-27212 OpenLDAP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210319-0005/

NetApp published this final advisory covering CVE-2021-27212; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-8625 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210319-0001/

NetApp published this final advisory covering CVE-2020-8625; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2020-7021 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210319-0003/

NetApp published this final advisory covering CVE-2020-7021; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-26987 SpringBoot Framework Remote Code Execution Vulnerability in Management Software for Element Software and NetApp HCI

Source: https://security.netapp.com/advisory/NTAP-20210315-0001/

NetApp published this final advisory covering CVE-2021-26987; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; NetApp SolidFire & HCI Management Node.

Open source
Advisory

June 2020 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0001/

NetApp published this final advisory covering CVE-2020-14058, CVE-2020-14059, CVE-2020-15049; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

February 2021 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0005/

NetApp published this final advisory covering CVE-2020-7071, CVE-2021-21702; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.

Open source
Advisory

February 2021 Lodash Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0006/

NetApp published this final advisory covering CVE-2020-28500, CVE-2021-23337; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; System Manager 9.x.

Open source
Advisory

CVE-2021-26708 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0008/

NetApp published this final advisory covering CVE-2021-26708; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-21315 Node.JS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0007/

NetApp published this final advisory covering CVE-2021-21315; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-35517 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0002/

NetApp published this final advisory covering CVE-2020-35517; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-17380 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0003/

NetApp published this final advisory covering CVE-2020-17380; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2020 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0002/

NetApp published this final advisory covering CVE-2020-8449, CVE-2020-8450, CVE-2020-8517; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

CVE-2021-3347 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0005/

NetApp published this final advisory covering CVE-2021-3347; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3326 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0007/

NetApp published this final advisory covering CVE-2021-3326; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-9492 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0001/

NetApp published this final advisory covering CVE-2020-9492; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-29443 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0003/

NetApp published this final advisory covering CVE-2020-29443; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-16119 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0006/

NetApp published this final advisory covering CVE-2020-16119; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

February 2021 OpenLDAP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210226-0002/

NetApp published this final advisory covering CVE-2020-36221, CVE-2020-36222, CVE-2020-36223, CVE-2020-36224, CVE-2020-36225, CVE-2020-36226, CVE-2020-36227, CVE-2020-36228, CVE-2020-36229, CVE-2020-36230; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

February 2021 Docker Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210226-0005/

NetApp published this final advisory covering CVE-2021-21284, CVE-2021-21285; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x.

Open source
Advisory

CVE-2021-3177 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210226-0003/

NetApp published this final advisory covering CVE-2021-3177; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-28488 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210226-0001/

NetApp published this final advisory covering CVE-2020-28488; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2020 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210226-0006/

NetApp published this final advisory covering CVE-2020-15810, CVE-2020-15811, CVE-2020-24606; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

September 2020 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0007/

NetApp published this final advisory covering CVE-2020-15811, CVE-2020-15810, CVE-2020-24606; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

January 2021 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0003/

NetApp published this final advisory covering CVE-2021-1998, CVE-2021-2001, CVE-2021-2002, CVE-2021-2009, CVE-2021-2012, CVE-2021-2014, CVE-2021-2016, CVE-2021-2019, CVE-2021-2020, CVE-2021-2021, CVE-2021-2022, CVE-2021-2024, CVE-2021-2028, CVE-2021-2030, CVE-2021-2031, CVE-2021-2032, CVE-2021-2036, CVE-2021-2038, CVE-2021-2042, CVE-2021-2046, CVE-2021-2048, CVE-2021-2055, CVE-2021-2056, CVE-2021-2058, CVE-2021-2060, CVE-2021-2061, CVE-2021-2065, CVE-2021-2070, CVE-2021-2072, CVE-2021-2076, CVE-2021-2081, CVE-2021-2087, CVE-2021-2088, CVE-2021-2122; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

February 2021 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0009/

NetApp published this final advisory covering CVE-2021-23839, CVE-2021-23840, CVE-2021-23841; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Service Processor - 8080/8060/8040/8020; Global File Cache; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Antivirus Connector; OnCommand Workflow Automation; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

February 2021 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0001/

NetApp published this final advisory covering CVE-2021-3114, CVE-2021-3115; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2021-3121 GoGo Protobuf Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0006/

NetApp published this final advisory covering CVE-2021-3121; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22132 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0004/

NetApp published this final advisory covering CVE-2021-22132; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-21252 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0005/

NetApp published this final advisory covering CVE-2021-21252; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); SnapCenter.

Open source
Advisory

CVE-2021-20190 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0008/

NetApp published this final advisory covering CVE-2021-20190; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Element Plug-in for vCenter Server; NetApp Cloud Backup (formerly AltaVault); NetApp Service Level Manager; OnCommand API Services; OnCommand Insight.

Open source
Advisory

CVE-2020-28374 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0002/

NetApp published this final advisory covering CVE-2020-28374; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

January 2021 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0003/

NetApp published this final advisory covering CVE-2020-8265, CVE-2020-8287; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2021 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0004/

NetApp published this final advisory covering CVE-2020-28851, CVE-2020-28852; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2021 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0007/

NetApp published this final advisory covering CVE-2020-35493, CVE-2020-35494, CVE-2020-35495, CVE-2020-35496, CVE-2020-35507; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

Intel SA-00456 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0005/

NetApp published this final advisory covering CVE-2020-24492, CVE-2020-24493, CVE-2020-24494, CVE-2020-24495, CVE-2020-24496, CVE-2020-24497, CVE-2020-24498, CVE-2020-24500, CVE-2020-24501, CVE-2020-24505; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00438 Graphics Drivers Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0006/

NetApp published this final advisory covering CVE-2020-0544, CVE-2020-0521, CVE-2020-12362, CVE-2020-12361, CVE-2020-24450, CVE-2020-8678, CVE-2020-0518, CVE-2020-12367, CVE-2020-12368, CVE-2020-12369, CVE-2020-12365, CVE-2020-12366, CVE-2020-24448, CVE-2020-12386, CVE-2020-12385, CVE-2020-12384, CVE-2020-12363, CVE-2020-12364, CVE-2020-12370, CVE-2020-12371, CVE-2020-12372, CVE-2020-12373; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-36158 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0002/

NetApp published this final advisory covering CVE-2020-36158; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-11947 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0001/

NetApp published this final advisory covering CVE-2020-11947; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2021 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0006/

NetApp published this final advisory covering CVE-2019-12519, CVE-2019-12520, CVE-2019-12521, CVE-2019-12522, CVE-2019-12524; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

January 2021 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0005/

NetApp published this final advisory covering CVE-2020-36179, CVE-2020-36180, CVE-2020-36181, CVE-2020-36182, CVE-2020-36183, CVE-2020-36184, CVE-2020-36185, CVE-2020-36186, CVE-2020-36187, CVE-2020-36188, CVE-2020-36189; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; NetApp Cloud Backup (formerly AltaVault); NetApp Service Level Manager.

Open source
Advisory

CVE-2020-29569 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0001/

NetApp published this final advisory covering CVE-2020-29569; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27846 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0002/

NetApp published this final advisory covering CVE-2020-27846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-25013 GNU C (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0004/

NetApp published this final advisory covering CVE-2019-25013; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-20808 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0003/

NetApp published this final advisory covering CVE-2019-20808; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2021 Treck TCP/IP Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210201-0003/

NetApp published this final advisory covering CVE-2020-25066, CVE-2020-27337, CVE-2020-27338, CVE-2020-27336; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2021 Sudo Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0010/

NetApp published this final advisory covering CVE-2021-23239, CVE-2021-23240; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node.

Open source
Advisory

December 2020 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0006/

NetApp published this final advisory covering CVE-2020-29509, CVE-2020-29510, CVE-2020-29511; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident.

Open source
Advisory

CVE-2020-4642 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0009/

NetApp published this final advisory covering CVE-2020-4642; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-35448 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0008/

NetApp published this final advisory covering CVE-2020-35448; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-11724 OpenResty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0002/

NetApp published this final advisory covering CVE-2020-11724; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10732 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0005/

NetApp published this final advisory covering CVE-2020-10732; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-19462 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0004/

NetApp published this final advisory covering CVE-2019-19462; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-17006 Libnss Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0001/

NetApp published this final advisory covering CVE-2019-17006; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-3156 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210128-0002/

NetApp published this final advisory covering CVE-2021-3156; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

Intel SA-00390 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0008/

NetApp published this final advisory covering CVE-2020-8764, CVE-2020-8738, CVE-2020-8740, CVE-2020-8739; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

December 2020 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0007/

NetApp published this final advisory covering CVE-2020-8284, CVE-2020-8285, CVE-2020-8286; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

December 2020 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0001/

NetApp published this final advisory covering CVE-2020-29660, CVE-2020-29661; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

December 2020 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0006/

NetApp published this final advisory covering CVE-2020-8563, CVE-2020-8564, CVE-2020-8566; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2020 GNU C Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0004/

NetApp published this final advisory covering CVE-2020-29562, CVE-2020-29573; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

December 2020 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0003/

NetApp published this final advisory covering CVE-2020-16593, CVE-2020-16599; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

December 2020 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0005/

NetApp published this final advisory covering CVE-2020-35490, CVE-2020-35491; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; NetApp Cloud Backup (formerly AltaVault); NetApp Service Level Manager.

Open source
Advisory

CVE-2020-27786 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0002/

NetApp published this final advisory covering CVE-2020-27786; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

December 2020 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0003/

NetApp published this final advisory covering CVE-2020-16590, CVE-2020-16591, CVE-2020-16592, CVE-2020-16598; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-29374 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0002/

NetApp published this final advisory covering CVE-2020-29374; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-29369 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0001/

NetApp published this final advisory covering CVE-2020-29369; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27821 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0006/

NetApp published this final advisory covering CVE-2020-27821; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-27730 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0004/

NetApp published this final advisory covering CVE-2020-27730; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2020-25613 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0008/

NetApp published this final advisory covering CVE-2020-25613; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-17531 Apache Tapestry Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0007/

NetApp published this final advisory covering CVE-2020-17531; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-17530 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0005/

NetApp published this final advisory covering CVE-2020-17530; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8584 Arbitrary Code Execution Vulnerability in Element OS

Source: https://security.netapp.com/advisory/NTAP-20210108-0008/

NetApp published this final advisory covering CVE-2020-8584; the API labels exploitation information as **Not public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-29368 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0002/

NetApp published this final advisory covering CVE-2020-29368; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-28974 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0003/

NetApp published this final advisory covering CVE-2020-28974; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27350 APT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0005/

NetApp published this final advisory covering CVE-2020-27350; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25692 OpenLDAP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0006/

NetApp published this final advisory covering CVE-2020-25692; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25649 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0007/

NetApp published this final advisory covering CVE-2020-25649; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; OnCommand API Services; OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

CVE-2015-9251 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0004/

NetApp published this interim advisory covering CVE-2015-9251; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).

Open source