Content Library · Advisory

Advisory 2021

Browse 447 2021 NetApp advisory records in the NetApp Black Box content library. Page 3 of 4.

Library JSON API

Showing all 120 items on this page

Advisory

CVE-2021-28860 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0005/

NetApp published this final advisory covering CVE-2021-28860; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23383 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0007/

NetApp published this final advisory covering CVE-2021-23383; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-21414 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0003/

NetApp published this final advisory covering CVE-2021-21414; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-35519 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210618-0009/

NetApp published this final advisory covering CVE-2020-35519; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

Intel SA-00464 Intel Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0005/

NetApp published this final advisory covering CVE-2020-24511, CVE-2020-24512; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

Intel SA-00459 CSME Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0004/

NetApp published this final advisory covering CVE-2020-8703, CVE-2020-24506, CVE-2020-24507; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-3506 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0007/

NetApp published this final advisory covering CVE-2021-3506; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-32052 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0002/

NetApp published this final advisory covering CVE-2021-32052; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31231 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0001/

NetApp published this final advisory covering CVE-2021-31231; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29469 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0010/

NetApp published this final advisory covering CVE-2021-29469; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-27905 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0009/

NetApp published this final advisory covering CVE-2021-27905; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23133 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0008/

NetApp published this final advisory covering CVE-2021-23133; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

April 2021 Eclipse Jetty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210611-0006/

NetApp published this final advisory covering CVE-2021-28163, CVE-2021-28164, CVE-2021-28165; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; NetApp BlueXP; NetApp E-Series Performance Analyzer; NetApp SANtricity Cloud Connector; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; ONTAP tools for VMware vSphere 9; SANtricity Storage Plugin for vCenter; SnapCenter; SnapCenter Plug-in for VMware vSphere/BlueXP backup and Recovery for Virtual Machine; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above.

Open source
Advisory

March 2021 Apache Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0003/

NetApp published this final advisory covering CVE-2021-21295, CVE-2021-21409; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand API Services; OnCommand Workflow Automation.

Open source
Advisory

CVE-2021-29662 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0002/

NetApp published this final advisory covering CVE-2021-29662; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); SnapCenter.

Open source
Advisory

CVE-2021-29424 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0007/

NetApp published this final advisory covering CVE-2021-29424; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2021-29418 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0001/

NetApp published this final advisory covering CVE-2021-29418; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29154 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0006/

NetApp published this final advisory covering CVE-2021-29154; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-26073 Node.JS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0004/

NetApp published this final advisory covering CVE-2021-26073; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23369 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0008/

NetApp published this final advisory covering CVE-2021-23369; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-36313 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0005/

NetApp published this final advisory covering CVE-2020-36313; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-15225 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0010/

NetApp published this final advisory covering CVE-2020-15225; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2021 Apache Solr Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210604-0009/

NetApp published this final advisory covering CVE-2021-29943, CVE-2021-29262; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3507 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0005/

NetApp published this final advisory covering CVE-2021-3507; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-30638 Apache Tapestry Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0004/

NetApp published this final advisory covering CVE-2021-30638; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28965 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0003/

NetApp published this final advisory covering CVE-2021-28965; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28918 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0010/

NetApp published this final advisory covering CVE-2021-28918; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28658 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0001/

NetApp published this final advisory covering CVE-2021-28658; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-27850 Apache Tapestry Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0002/

NetApp published this final advisory covering CVE-2021-27850; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-21267 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0006/

NetApp published this final advisory covering CVE-2021-21267; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer; OnCommand Insight.

Open source
Advisory

CVE-2021-20197 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210528-0009/

NetApp published this final advisory covering CVE-2021-20197; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

March 2021 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0009/

NetApp published this final advisory covering CVE-2020-35521, CVE-2020-35522, CVE-2020-35523, CVE-2020-35524; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-20284 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0010/

NetApp published this final advisory covering CVE-2021-20284; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-27825 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0008/

NetApp published this final advisory covering CVE-2020-27825; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-17516 Apache Cassandra Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0002/

NetApp published this final advisory covering CVE-2020-17516; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-12762 JSON-C Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0001/

NetApp published this final advisory covering CVE-2020-12762; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2021 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0007/

NetApp published this interim advisory covering CVE-2021-22876, CVE-2021-22890; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software).

Open source
Advisory

April 2021 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210521-0006/

NetApp published this final advisory covering CVE-2021-25214, CVE-2021-25215, CVE-2021-25216; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-29266 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0005/

NetApp published this final advisory covering CVE-2021-29266; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-28092 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0008/

NetApp published this final advisory covering CVE-2021-28092; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-27358 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0007/

NetApp published this final advisory covering CVE-2021-27358; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-23926 Apache XMLBeans Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0004/

NetApp published this final advisory covering CVE-2021-23926; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager Core Package; Snap Creator Framework; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2020-35508 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0006/

NetApp published this final advisory covering CVE-2020-35508; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-13954 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0010/

NetApp published this final advisory covering CVE-2020-13954; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; Snap Creator Framework.

Open source
Advisory

April 2021 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0002/

NetApp published this final advisory covering CVE-2020-1971, CVE-2021-3449, CVE-2020-28196, CVE-2021-23841, CVE-2021-2144, CVE-2021-2172, CVE-2021-2298, CVE-2021-2178, CVE-2021-2202, CVE-2021-2307, CVE-2021-2304, CVE-2021-2180, CVE-2021-2194, CVE-2021-2154, CVE-2021-2166, CVE-2021-2196, CVE-2021-2300, CVE-2021-2305, CVE-2021-2179, CVE-2021-2226, CVE-2021-2160, CVE-2021-2164, CVE-2021-2169, CVE-2021-2170, CVE-2021-2193, CVE-2021-2203, CVE-2021-2212, CVE-2021-2213, CVE-2021-2278, CVE-2021-2299, CVE-2021-2230, CVE-2021-2146, CVE-2021-2201, CVE-2021-2208, CVE-2021-2215, CVE-2021-2217, CVE-2021-2293, CVE-2021-2174, CVE-2021-2171, CVE-2021-2162, CVE-2021-2301, CVE-2021-2308, CVE-2021-2232; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2021 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210513-0001/

NetApp published this interim advisory covering CVE-2021-2161, CVE-2021-2163; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Secure Agent; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

March 2021 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0001/

NetApp published this final advisory covering CVE-2021-3392, CVE-2021-3409; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3393 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0006/

NetApp published this final advisory covering CVE-2021-3393; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28660 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0008/

NetApp published this final advisory covering CVE-2021-28660; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-28657 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0004/

NetApp published this final advisory covering CVE-2021-28657; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20255 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0003/

NetApp published this final advisory covering CVE-2021-20255; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-36309 OpenResty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0005/

NetApp published this final advisory covering CVE-2020-36309; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2021 Unbound Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0007/

NetApp published this final advisory covering CVE-2019-25031, CVE-2019-25032, CVE-2019-25033, CVE-2019-25034, CVE-2019-25035, CVE-2019-25036, CVE-2019-25037, CVE-2019-25038, CVE-2019-25039, CVE-2019-25040, CVE-2019-25041, CVE-2019-25042; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2021 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210507-0002/

NetApp published this final advisory covering CVE-2021-3416, CVE-2021-20263; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2021 XStream Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0002/

NetApp published this final advisory covering CVE-2021-21341, CVE-2021-21342, CVE-2021-21343, CVE-2021-21344, CVE-2021-21345, CVE-2021-21346, CVE-2021-21347, CVE-2021-21348, CVE-2021-21349, CVE-2021-21350, CVE-2021-21351; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

March 2021 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0004/

NetApp published this final advisory covering CVE-2019-10127, CVE-2019-10128; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2021 Linux Kernel 5.11.8 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0003/

NetApp published this final advisory covering CVE-2021-28951, CVE-2021-28952, CVE-2021-28964, CVE-2021-28971, CVE-2021-28972; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

March 2021 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0005/

NetApp published this final advisory covering CVE-2021-28147, CVE-2021-28148; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22134 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0006/

NetApp published this final advisory covering CVE-2021-22134; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20254 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210430-0001/

NetApp published this final advisory covering CVE-2021-20254; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29627 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0007/

NetApp published this final advisory covering CVE-2021-29627; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-29626 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0008/

NetApp published this final advisory covering CVE-2021-29626; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20227 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0010/

NetApp published this final advisory covering CVE-2021-20227; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25584 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0009/

NetApp published this final advisory covering CVE-2020-25584; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25583 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0004/

NetApp published this final advisory covering CVE-2020-25583; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25582 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0003/

NetApp published this final advisory covering CVE-2020-25582; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25581 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0006/

NetApp published this final advisory covering CVE-2020-25581; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25580 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0005/

NetApp published this final advisory covering CVE-2020-25580; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-25577 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0001/

NetApp published this final advisory covering CVE-2020-25577; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2021 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210423-0002/

NetApp published this final advisory covering CVE-2020-25578, CVE-2020-25579; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2021 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0001/

NetApp published this final advisory covering CVE-2021-22883, CVE-2021-22884; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

March 2021 GnuTLS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0005/

NetApp published this final advisory covering CVE-2021-20231, CVE-2021-20232; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-3444 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0006/

NetApp published this final advisory covering CVE-2021-3444; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-28041 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0002/

NetApp published this interim advisory covering CVE-2021-28041; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-14372 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210416-0004/

NetApp published this final advisory covering CVE-2020-14372; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.

Open source
Advisory

March 2021 Linux Kernel 5.11.3 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0001/

NetApp published this final advisory covering CVE-2021-27363, CVE-2021-27364, CVE-2021-27365, CVE-2021-28038, CVE-2021-28039; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

March 2021 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0003/

NetApp published this final advisory covering CVE-2020-4976, CVE-2020-5024, CVE-2020-5025; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

March 2021 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0002/

NetApp published this final advisory covering CVE-2021-25329, CVE-2021-25122; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Storage Workload Security Agent; Element Plug-in for vCenter Server.

Open source
Advisory

December 2020 XStream Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0005/

NetApp published this final advisory covering CVE-2020-26258, CVE-2020-26259; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20268 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0006/

NetApp published this final advisory covering CVE-2021-20268; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-26217 XStream Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210409-0004/

NetApp published this final advisory covering CVE-2020-26217; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

CVE-2021-3189 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210401-0004/

NetApp published this final advisory covering CVE-2021-3189; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-28375 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210401-0003/

NetApp published this interim advisory covering CVE-2021-28375; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27618 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210401-0006/

NetApp published this final advisory covering CVE-2020-27618; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-27543 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210401-0002/

NetApp published this final advisory covering CVE-2020-27543; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-27223 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210401-0005/

NetApp published this final advisory covering CVE-2020-27223; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; NetApp SolidFire & HCI Management Node; SANtricity Storage Plugin for vCenter; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

March 2021 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0007/

NetApp published this final advisory covering CVE-2021-20277, CVE-2020-27840; the API labels exploitation information as **Not public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2021 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0006/

NetApp published this final advisory covering CVE-2021-3449, CVE-2021-3450; the API labels exploitation information as **Not public**. The API currently lists affected products as: Cloud Volumes ONTAP Mediator; Global File Cache; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp E-Series Performance Analyzer; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility; OnCommand Workflow Automation; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

February 2021 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0001/

NetApp published this final advisory covering CVE-2021-26930, CVE-2021-26931, CVE-2021-26932, CVE-2021-26934; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-27405 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0002/

NetApp published this final advisory covering CVE-2021-27405; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23336 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0004/

NetApp published this final advisory covering CVE-2021-23336; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility; SnapCenter.

Open source
Advisory

CVE-2021-20229 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0005/

NetApp published this final advisory covering CVE-2021-20229; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20194 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210326-0003/

NetApp published this final advisory covering CVE-2021-20194; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

February 2021 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210319-0002/

NetApp published this final advisory covering CVE-2021-27185, CVE-2021-27191; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2021 GNOME GLib Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210319-0004/

NetApp published this final advisory covering CVE-2021-27218, CVE-2021-27219; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-27212 OpenLDAP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210319-0005/

NetApp published this final advisory covering CVE-2021-27212; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-8625 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210319-0001/

NetApp published this final advisory covering CVE-2020-8625; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

CVE-2020-7021 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210319-0003/

NetApp published this final advisory covering CVE-2020-7021; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-26987 SpringBoot Framework Remote Code Execution Vulnerability in Management Software for Element Software and NetApp HCI

Source: https://security.netapp.com/advisory/NTAP-20210315-0001/

NetApp published this final advisory covering CVE-2021-26987; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; NetApp SolidFire & HCI Management Node.

Open source
Advisory

June 2020 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0001/

NetApp published this final advisory covering CVE-2020-14058, CVE-2020-14059, CVE-2020-15049; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

February 2021 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0005/

NetApp published this final advisory covering CVE-2020-7071, CVE-2021-21702; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.

Open source
Advisory

February 2021 Lodash Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0006/

NetApp published this final advisory covering CVE-2020-28500, CVE-2021-23337; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; System Manager 9.x.

Open source