Content Library · Advisory

Advisory 2021

Browse 447 2021 NetApp advisory records in the NetApp Black Box content library. Page 4 of 4.

Library JSON API

Showing all 87 items on this page

Advisory

CVE-2021-26708 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0008/

NetApp published this final advisory covering CVE-2021-26708; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-21315 Node.JS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0007/

NetApp published this final advisory covering CVE-2021-21315; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-35517 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0002/

NetApp published this final advisory covering CVE-2020-35517; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-17380 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210312-0003/

NetApp published this final advisory covering CVE-2020-17380; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2020 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0002/

NetApp published this final advisory covering CVE-2020-8449, CVE-2020-8450, CVE-2020-8517; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

CVE-2021-3347 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0005/

NetApp published this final advisory covering CVE-2021-3347; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2021-3326 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0007/

NetApp published this final advisory covering CVE-2021-3326; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-9492 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0001/

NetApp published this final advisory covering CVE-2020-9492; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-29443 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0003/

NetApp published this final advisory covering CVE-2020-29443; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-16119 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210304-0006/

NetApp published this final advisory covering CVE-2020-16119; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

February 2021 OpenLDAP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210226-0002/

NetApp published this final advisory covering CVE-2020-36221, CVE-2020-36222, CVE-2020-36223, CVE-2020-36224, CVE-2020-36225, CVE-2020-36226, CVE-2020-36227, CVE-2020-36228, CVE-2020-36229, CVE-2020-36230; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

February 2021 Docker Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210226-0005/

NetApp published this final advisory covering CVE-2021-21284, CVE-2021-21285; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x.

Open source
Advisory

CVE-2021-3177 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210226-0003/

NetApp published this final advisory covering CVE-2021-3177; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-28488 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210226-0001/

NetApp published this final advisory covering CVE-2020-28488; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2020 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210226-0006/

NetApp published this final advisory covering CVE-2020-15810, CVE-2020-15811, CVE-2020-24606; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

September 2020 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0007/

NetApp published this final advisory covering CVE-2020-15811, CVE-2020-15810, CVE-2020-24606; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

January 2021 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0003/

NetApp published this final advisory covering CVE-2021-1998, CVE-2021-2001, CVE-2021-2002, CVE-2021-2009, CVE-2021-2012, CVE-2021-2014, CVE-2021-2016, CVE-2021-2019, CVE-2021-2020, CVE-2021-2021, CVE-2021-2022, CVE-2021-2024, CVE-2021-2028, CVE-2021-2030, CVE-2021-2031, CVE-2021-2032, CVE-2021-2036, CVE-2021-2038, CVE-2021-2042, CVE-2021-2046, CVE-2021-2048, CVE-2021-2055, CVE-2021-2056, CVE-2021-2058, CVE-2021-2060, CVE-2021-2061, CVE-2021-2065, CVE-2021-2070, CVE-2021-2072, CVE-2021-2076, CVE-2021-2081, CVE-2021-2087, CVE-2021-2088, CVE-2021-2122; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

February 2021 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0009/

NetApp published this final advisory covering CVE-2021-23839, CVE-2021-23840, CVE-2021-23841; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Service Processor - 8080/8060/8040/8020; Global File Cache; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Antivirus Connector; OnCommand Workflow Automation; SnapDrive for Unix; SnapDrive for Windows.

Open source
Advisory

February 2021 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0001/

NetApp published this final advisory covering CVE-2021-3114, CVE-2021-3115; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2021-3121 GoGo Protobuf Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0006/

NetApp published this final advisory covering CVE-2021-3121; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22132 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0004/

NetApp published this final advisory covering CVE-2021-22132; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-21252 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0005/

NetApp published this final advisory covering CVE-2021-21252; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); SnapCenter.

Open source
Advisory

CVE-2021-20190 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0008/

NetApp published this final advisory covering CVE-2021-20190; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Element Plug-in for vCenter Server; NetApp Cloud Backup (formerly AltaVault); NetApp Service Level Manager; OnCommand API Services; OnCommand Insight.

Open source
Advisory

CVE-2020-28374 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210219-0002/

NetApp published this final advisory covering CVE-2020-28374; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

January 2021 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0003/

NetApp published this final advisory covering CVE-2020-8265, CVE-2020-8287; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2021 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0004/

NetApp published this final advisory covering CVE-2020-28851, CVE-2020-28852; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2021 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0007/

NetApp published this final advisory covering CVE-2020-35493, CVE-2020-35494, CVE-2020-35495, CVE-2020-35496, CVE-2020-35507; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

Intel SA-00456 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0005/

NetApp published this final advisory covering CVE-2020-24492, CVE-2020-24493, CVE-2020-24494, CVE-2020-24495, CVE-2020-24496, CVE-2020-24497, CVE-2020-24498, CVE-2020-24500, CVE-2020-24501, CVE-2020-24505; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00438 Graphics Drivers Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0006/

NetApp published this final advisory covering CVE-2020-0544, CVE-2020-0521, CVE-2020-12362, CVE-2020-12361, CVE-2020-24450, CVE-2020-8678, CVE-2020-0518, CVE-2020-12367, CVE-2020-12368, CVE-2020-12369, CVE-2020-12365, CVE-2020-12366, CVE-2020-24448, CVE-2020-12386, CVE-2020-12385, CVE-2020-12384, CVE-2020-12363, CVE-2020-12364, CVE-2020-12370, CVE-2020-12371, CVE-2020-12372, CVE-2020-12373; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-36158 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0002/

NetApp published this final advisory covering CVE-2020-36158; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-11947 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210212-0001/

NetApp published this final advisory covering CVE-2020-11947; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2021 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0006/

NetApp published this final advisory covering CVE-2019-12519, CVE-2019-12520, CVE-2019-12521, CVE-2019-12522, CVE-2019-12524; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.

Open source
Advisory

January 2021 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0005/

NetApp published this final advisory covering CVE-2020-36179, CVE-2020-36180, CVE-2020-36181, CVE-2020-36182, CVE-2020-36183, CVE-2020-36184, CVE-2020-36185, CVE-2020-36186, CVE-2020-36187, CVE-2020-36188, CVE-2020-36189; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; NetApp Cloud Backup (formerly AltaVault); NetApp Service Level Manager.

Open source
Advisory

CVE-2020-29569 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0001/

NetApp published this final advisory covering CVE-2020-29569; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27846 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0002/

NetApp published this final advisory covering CVE-2020-27846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-25013 GNU C (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0004/

NetApp published this final advisory covering CVE-2019-25013; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-20808 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210205-0003/

NetApp published this final advisory covering CVE-2019-20808; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2021 Treck TCP/IP Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210201-0003/

NetApp published this final advisory covering CVE-2020-25066, CVE-2020-27337, CVE-2020-27338, CVE-2020-27336; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2021 Sudo Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0010/

NetApp published this final advisory covering CVE-2021-23239, CVE-2021-23240; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node.

Open source
Advisory

December 2020 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0006/

NetApp published this final advisory covering CVE-2020-29509, CVE-2020-29510, CVE-2020-29511; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident.

Open source
Advisory

CVE-2020-4642 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0009/

NetApp published this final advisory covering CVE-2020-4642; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-35448 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0008/

NetApp published this final advisory covering CVE-2020-35448; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-11724 OpenResty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0002/

NetApp published this final advisory covering CVE-2020-11724; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10732 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0005/

NetApp published this final advisory covering CVE-2020-10732; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-19462 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0004/

NetApp published this final advisory covering CVE-2019-19462; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.

Open source
Advisory

CVE-2019-17006 Libnss Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210129-0001/

NetApp published this final advisory covering CVE-2019-17006; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-3156 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210128-0002/

NetApp published this final advisory covering CVE-2021-3156; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

Intel SA-00390 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0008/

NetApp published this final advisory covering CVE-2020-8764, CVE-2020-8738, CVE-2020-8740, CVE-2020-8739; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

December 2020 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0007/

NetApp published this final advisory covering CVE-2020-8284, CVE-2020-8285, CVE-2020-8286; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

December 2020 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0001/

NetApp published this final advisory covering CVE-2020-29660, CVE-2020-29661; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

December 2020 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0006/

NetApp published this final advisory covering CVE-2020-8563, CVE-2020-8564, CVE-2020-8566; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2020 GNU C Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0004/

NetApp published this final advisory covering CVE-2020-29562, CVE-2020-29573; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

December 2020 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0003/

NetApp published this final advisory covering CVE-2020-16593, CVE-2020-16599; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

December 2020 FasterXML jackson-databind Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0005/

NetApp published this final advisory covering CVE-2020-35490, CVE-2020-35491; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; NetApp Cloud Backup (formerly AltaVault); NetApp Service Level Manager.

Open source
Advisory

CVE-2020-27786 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210122-0002/

NetApp published this final advisory covering CVE-2020-27786; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

December 2020 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0003/

NetApp published this final advisory covering CVE-2020-16590, CVE-2020-16591, CVE-2020-16592, CVE-2020-16598; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-29374 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0002/

NetApp published this final advisory covering CVE-2020-29374; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-29369 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0001/

NetApp published this final advisory covering CVE-2020-29369; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27821 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0006/

NetApp published this final advisory covering CVE-2020-27821; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-27730 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0004/

NetApp published this final advisory covering CVE-2020-27730; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2020-25613 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0008/

NetApp published this final advisory covering CVE-2020-25613; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-17531 Apache Tapestry Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0007/

NetApp published this final advisory covering CVE-2020-17531; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-17530 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210115-0005/

NetApp published this final advisory covering CVE-2020-17530; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8584 Arbitrary Code Execution Vulnerability in Element OS

Source: https://security.netapp.com/advisory/NTAP-20210108-0008/

NetApp published this final advisory covering CVE-2020-8584; the API labels exploitation information as **Not public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-29368 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0002/

NetApp published this final advisory covering CVE-2020-29368; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-28974 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0003/

NetApp published this final advisory covering CVE-2020-28974; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-27350 APT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0005/

NetApp published this final advisory covering CVE-2020-27350; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25692 OpenLDAP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0006/

NetApp published this final advisory covering CVE-2020-25692; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).

Open source
Advisory

CVE-2020-25649 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0007/

NetApp published this final advisory covering CVE-2020-25649; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; OnCommand API Services; OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

CVE-2015-9251 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20210108-0004/

NetApp published this interim advisory covering CVE-2015-9251; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).

Open source