Content Library · Advisory

Advisory 2022

Browse 501 2022 NetApp advisory records in the NetApp Black Box content library.

Library JSON API

Advisory

CVE-2022-38178 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0009/

NetApp published this final advisory covering CVE-2022-38178; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-38177 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0010/

NetApp published this final advisory covering CVE-2022-38177; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-3541 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0001/

NetApp published this final advisory covering CVE-2022-3541; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3202 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0007/

NetApp published this final advisory covering CVE-2022-3202; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1199 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0006/

NetApp published this final advisory covering CVE-2022-1199; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4204 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0003/

NetApp published this final advisory covering CVE-2021-4204; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4028 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0002/

NetApp published this interim advisory covering CVE-2021-4028; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

CVE-2021-33621 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0004/

NetApp published this final advisory covering CVE-2021-33621; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2016-2338 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0005/

NetApp published this final advisory covering CVE-2016-2338; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221228-0008/

NetApp published this final advisory covering CVE-2022-0865, CVE-2022-0891, CVE-2022-1056; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-42252 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0005/

NetApp published this final advisory covering CVE-2022-42252; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3920 HashiCorp Consul Vulnerability Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0010/

NetApp published this final advisory covering CVE-2022-3920; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3705 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0004/

NetApp published this final advisory covering CVE-2022-3705; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-3564 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0001/

NetApp published this final advisory covering CVE-2022-3564; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2022-3545 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0003/

NetApp published this final advisory covering CVE-2022-3545; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3165 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0006/

NetApp published this final advisory covering CVE-2022-3165; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31630 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0008/

NetApp published this final advisory covering CVE-2022-31630; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2938 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0002/

NetApp published this final advisory covering CVE-2022-2938; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-46784 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0007/

NetApp published this final advisory covering CVE-2021-46784; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31693 VMware Tools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221223-0009/

NetApp published this final advisory covering CVE-2021-31693; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2022 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0001/

NetApp published this final advisory covering CVE-2022-35957, CVE-2022-36062; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2022 Spring Security Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0010/

NetApp published this final advisory covering CVE-2022-31690, CVE-2022-31692; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

November 2022 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0004/

NetApp published this final advisory covering CVE-2022-39306, CVE-2022-39307; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

December 2022 MegaRAC BMC Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0007/

NetApp published this interim advisory covering CVE-2022-40259, CVE-2022-40242, CVE-2022-2827; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

CVE-2022-43945 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0006/

NetApp published this final advisory covering CVE-2022-43945; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3970 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0009/

NetApp published this final advisory covering CVE-2022-3970; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-39328 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0003/

NetApp published this final advisory covering CVE-2022-39328; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3872 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0005/

NetApp published this final advisory covering CVE-2022-3872; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3671 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0002/

NetApp published this final advisory covering CVE-2021-3671; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2014-0144 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221215-0008/

NetApp published this final advisory covering CVE-2014-0144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2022 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0001/

NetApp published this final advisory covering CVE-2022-31628, CVE-2022-31629; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2022 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0010/

NetApp published this interim advisory covering CVE-2022-42915, CVE-2022-42916; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; ONTAP 9.

Open source
Advisory

November 2022 Libxml2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0003/

NetApp published this interim advisory covering CVE-2022-40303, CVE-2022-40304; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-45061 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0007/

NetApp published this interim advisory covering CVE-2022-45061; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp E-Series Performance Analyzer; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-42919 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0006/

NetApp published this final advisory covering CVE-2022-42919; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31176 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0004/

NetApp published this final advisory covering CVE-2022-31176; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23093 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0009/

NetApp published this final advisory covering CVE-2022-23093; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2012-4244 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0008/

NetApp published this final advisory covering CVE-2012-4244; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

August 2022 Util-linux Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221209-0002/

NetApp published this final advisory covering CVE-2021-3995, CVE-2021-3996; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-41316 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221201-0001/

NetApp published this final advisory covering CVE-2022-41316; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3975 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221201-0002/

NetApp published this final advisory covering CVE-2021-3975; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3859 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221201-0004/

NetApp published this final advisory covering CVE-2021-3859; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2021-25642 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221201-0003/

NetApp published this final advisory covering CVE-2021-25642; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-43936 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20221128-0006/

NetApp published this final advisory covering CVE-2022-43936; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-43935 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20221128-0005/

NetApp published this final advisory covering CVE-2022-43935; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-43934 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20221128-0004/

NetApp published this final advisory covering CVE-2022-43934; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-43933 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20221128-0003/

NetApp published this final advisory covering CVE-2022-43933; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-42898 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221128-0001/

NetApp published this final advisory covering CVE-2022-42898; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-33187 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20221128-0002/

NetApp published this final advisory covering CVE-2022-33187; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-42003 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221124-0004/

NetApp published this interim advisory covering CVE-2022-42003; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-41323 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221124-0001/

NetApp published this final advisory covering CVE-2022-41323; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31123 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221124-0002/

NetApp published this final advisory covering CVE-2022-31123; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2021-3770 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221124-0003/

NetApp published this final advisory covering CVE-2021-3770; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-43680 libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221118-0007/

NetApp published this interim advisory covering CVE-2022-43680; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 10; OnCommand Workflow Automation; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2022-42004 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221118-0008/

NetApp published this interim advisory covering CVE-2022-42004; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-22577 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221118-0002/

NetApp published this final advisory covering CVE-2022-22577; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-21831 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221118-0001/

NetApp published this final advisory covering CVE-2022-21831; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-46848 GNU Libtasn1 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221118-0006/

NetApp published this final advisory covering CVE-2021-46848; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3796 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221118-0004/

NetApp published this final advisory covering CVE-2021-3796; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3778 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221118-0003/

NetApp published this final advisory covering CVE-2021-3778; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

Intel SA-00688 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221111-0006/

NetApp published this final advisory covering CVE-2022-26006, CVE-2022-21198; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-40186 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221111-0008/

NetApp published this final advisory covering CVE-2022-40186; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2526 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221111-0005/

NetApp published this final advisory covering CVE-2022-2526; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2022-24903 Rsyslog Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221111-0002/

NetApp published this final advisory covering CVE-2022-24903; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2021-43618 GMP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221111-0001/

NetApp published this final advisory covering CVE-2021-43618; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4203 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221111-0003/

NetApp published this interim advisory covering CVE-2021-4203; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-35527 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221111-0007/

NetApp published this final advisory covering CVE-2020-35527; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

September 2022 X.Org X Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0003/

NetApp published this final advisory covering CVE-2022-2319, CVE-2022-2320; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-39046 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0002/

NetApp published this interim advisory covering CVE-2022-39046; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-38791 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0008/

NetApp published this final advisory covering CVE-2022-38791; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-38533 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0007/

NetApp published this final advisory covering CVE-2022-38533; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2022-36033 jsoup Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0006/

NetApp published this final advisory covering CVE-2022-36033; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-1552 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0005/

NetApp published this final advisory covering CVE-2022-1552; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-4189 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0004/

NetApp published this final advisory covering CVE-2021-4189; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3999 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221104-0001/

NetApp published this final advisory covering CVE-2021-3999; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp NFS Plug-in for VMware VAAI; ONTAP Select Deploy administration utility.

Open source
Advisory

November 2022 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221102-0001/

NetApp published this interim advisory covering CVE-2022-3602, CVE-2022-3786; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

October 2022 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0011/

NetApp published this final advisory covering CVE-2022-3437, CVE-2022-3592; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

October 2022 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0013/

NetApp published this final advisory covering CVE-2022-21589, CVE-2022-21592, CVE-2022-21594, CVE-2022-21595, CVE-2022-21599, CVE-2022-21600, CVE-2022-21604, CVE-2022-21605, CVE-2022-21607, CVE-2022-21608, CVE-2022-21611, CVE-2022-21617, CVE-2022-21625, CVE-2022-21632, CVE-2022-21633, CVE-2022-21635, CVE-2022-21637, CVE-2022-21638, CVE-2022-21640, CVE-2022-21641, CVE-2022-39400, CVE-2022-39408, CVE-2022-39410; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2022 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0012/

NetApp published this interim advisory covering CVE-2022-21618, CVE-2022-21619, CVE-2022-21624, CVE-2022-21626, CVE-2022-21628, CVE-2022-39399; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter.

Open source
Advisory

June 2022 PCRE Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0009/

NetApp published this final advisory covering CVE-2022-1586, CVE-2022-1587; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-40674 libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0008/

NetApp published this interim advisory covering CVE-2022-40674; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2022-34339 IBM Cognos Analytics Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0016/

NetApp published this final advisory covering CVE-2022-34339; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3358 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0014/

NetApp published this final advisory covering CVE-2022-3358; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-26336 Apache POI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0006/

NetApp published this final advisory covering CVE-2022-26336; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-25258 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0007/

NetApp published this final advisory covering CVE-2022-25258; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3800 GNOME GLib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0004/

NetApp published this final advisory covering CVE-2021-3800; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2021-3753 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0003/

NetApp published this interim advisory covering CVE-2021-3753; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-14155 PCRE Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0010/

NetApp published this final advisory covering CVE-2020-14155; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SteelStore Cloud Integrated Storage; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2019-13990 Quartz Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0002/

NetApp published this final advisory covering CVE-2019-13990; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Insights Storage Workload Security Agent.

Open source
Advisory

CVE-2018-14550 libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221028-0001/

NetApp published this final advisory covering CVE-2018-14550; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; OnCommand API Services.

Open source
Advisory

September 2022 BlueZ Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221020-0002/

NetApp published this final advisory covering CVE-2022-39176, CVE-2022-39177; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-35951 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221020-0005/

NetApp published this final advisory covering CVE-2022-35951; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1012 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221020-0006/

NetApp published this interim advisory covering CVE-2022-1012; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-4214 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221020-0001/

NetApp published this final advisory covering CVE-2021-4214; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3998 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221020-0003/

NetApp published this final advisory covering CVE-2021-3998; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-36067 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221017-0002/

NetApp published this final advisory covering CVE-2022-36067; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00709 AMT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221014-0004/

NetApp published this final advisory covering CVE-2022-30601, CVE-2022-30944, CVE-2022-28697; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31129 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221014-0003/

NetApp published this final advisory covering CVE-2022-31129; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2953 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221014-0008/

NetApp published this final advisory covering CVE-2022-2953; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-43466 Thymeleaf Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221014-0001/

NetApp published this final advisory covering CVE-2021-43466; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3807 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221014-0002/

NetApp published this final advisory covering CVE-2021-3807; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2022 Undertow Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221014-0006/

NetApp published this interim advisory covering CVE-2022-1259, CVE-2022-1319, CVE-2022-2764; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

August 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221014-0007/

NetApp published this final advisory covering CVE-2022-1354, CVE-2022-1355; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

August 2022 IBM Cognos Analytics Vulnerabilities

Source: https://security.netapp.com/advisory/NTAP-20221014-0005/

NetApp published this final advisory covering CVE-2020-4301, CVE-2021-20468, CVE-2021-29823, CVE-2021-39009, CVE-2021-39045, CVE-2022-30614, CVE-2022-36773; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2022-29901 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0007/

NetApp published this final advisory covering CVE-2022-29901; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-28693 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0006/

NetApp published this final advisory covering CVE-2022-28693; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-26373 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0005/

NetApp published this final advisory covering CVE-2022-26373; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24407 Cyrus SASL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0003/

NetApp published this final advisory covering CVE-2022-24407; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-1664 Dpkg Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0002/

NetApp published this final advisory covering CVE-2022-1664; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-0358 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0008/

NetApp published this final advisory covering CVE-2022-0358; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-46828 libtirpc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0004/

NetApp published this final advisory covering CVE-2021-46828; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3772 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0001/

NetApp published this interim advisory covering CVE-2021-3772; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

July 2022 Grub Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0001/

NetApp published this final advisory covering CVE-2021-3695, CVE-2021-3696, CVE-2021-3697; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-35252 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0005/

NetApp published this interim advisory covering CVE-2022-35252; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9.

Open source
Advisory

CVE-2022-34526 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0002/

NetApp published this final advisory covering CVE-2022-34526; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-1619 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0007/

NetApp published this interim advisory covering CVE-2022-1619; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2022-1271 GNU Gzip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0006/

NetApp published this final advisory covering CVE-2022-1271; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32189 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220923-0003/

NetApp published this final advisory covering CVE-2022-32189; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-28948 Go-Yaml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220923-0006/

NetApp published this final advisory covering CVE-2022-28948; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident; Astra Trident Autosupport.

Open source
Advisory

CVE-2022-27664 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220923-0004/

NetApp published this final advisory covering CVE-2022-27664; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Astra Control Center - NetApp Kubernetes Monitoring Operator; BeeGFS CSI Driver; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator; Trident; Trident Autosupport.

Open source
Advisory

CVE-2022-21233 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220923-0002/

NetApp published this final advisory covering CVE-2022-21233; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-20824 Cisco Discovery Protocol Denial of Service and Arbitrary Code Execution Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20220923-0001/

NetApp published this final advisory covering CVE-2022-20824; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1996 go-restful Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220923-0005/

NetApp published this final advisory covering CVE-2022-1996; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2022 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0001/

NetApp published this final advisory covering CVE-2022-32212, CVE-2022-32213, CVE-2022-32214, CVE-2022-32215, CVE-2022-32222, CVE-2022-32223; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2022 Libcurl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0003/

NetApp published this interim advisory covering CVE-2022-32208, CVE-2022-32207, CVE-2022-32206, CVE-2022-32205; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

July 2022 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0004/

NetApp published this final advisory covering CVE-2022-30629, CVE-2022-30634; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2022-36359 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0008/

NetApp published this final advisory covering CVE-2022-36359; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-35737 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0009/

NetApp published this final advisory covering CVE-2022-35737; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-31150 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0002/

NetApp published this final advisory covering CVE-2022-31150; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-25168 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0007/

NetApp published this final advisory covering CVE-2022-25168; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2309 lxml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0006/

NetApp published this final advisory covering CVE-2022-2309; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-4209 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0005/

NetApp published this interim advisory covering CVE-2021-4209; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

April 2022 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0010/

NetApp published this final advisory covering CVE-2022-24675, CVE-2022-28327; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-36313 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0005/

NetApp published this final advisory covering CVE-2022-36313; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31160 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0007/

NetApp published this final advisory covering CVE-2022-31160; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Virtual Desktop Service (VDS); SnapCenter.

Open source
Advisory

CVE-2022-31151 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0006/

NetApp published this final advisory covering CVE-2022-31151; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31144 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0002/

NetApp published this final advisory covering CVE-2022-31144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2191 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0003/

NetApp published this final advisory covering CVE-2022-2191; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-17498 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0004/

NetApp published this interim advisory covering CVE-2019-17498; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

July 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0007/

NetApp published this interim advisory covering CVE-2022-36879, CVE-2022-36946; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

July 2022 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0010/

NetApp published this final advisory covering CVE-2022-31097, CVE-2022-31107; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2022-37434 Zlib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0005/

NetApp published this final advisory covering CVE-2022-37434; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; OnCommand Workflow Automation; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2022-36129 HashiCorp Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0011/

NetApp published this final advisory covering CVE-2022-36129; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-36123 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0003/

NetApp published this final advisory covering CVE-2022-36123; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-25647 Google Gson Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0009/

NetApp published this final advisory covering CVE-2022-25647; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2022-1671 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0004/

NetApp published this final advisory covering CVE-2022-1671; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1651 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0008/

NetApp published this final advisory covering CVE-2022-1651; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2020-28445 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0012/

NetApp published this final advisory covering CVE-2020-28445; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2022 Eclipse Jetty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0006/

NetApp published this interim advisory covering CVE-2022-2047, CVE-2022-2048; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); SnapCenter.

Open source
Advisory

June 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0001/

NetApp published this final advisory covering CVE-2022-2056, CVE-2022-2057, CVE-2022-2058; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-34918 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0004/

NetApp published this final advisory covering CVE-2022-34918; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-34903 GnuPG Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0005/

NetApp published this final advisory covering CVE-2022-34903; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-32086 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0007/

NetApp published this final advisory covering CVE-2022-32086; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32083 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0006/

NetApp published this final advisory covering CVE-2022-32083; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31627 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0008/

NetApp published this final advisory covering CVE-2022-31627; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-40663 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0002/

NetApp published this final advisory covering CVE-2021-40663; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220818-0005/

NetApp published this final advisory covering CVE-2022-32089, CVE-2022-32081, CVE-2022-32088, CVE-2022-32087, CVE-2022-32082, CVE-2022-32085, CVE-2022-32084, CVE-2022-32091; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00601 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220818-0003/

NetApp published this final advisory covering CVE-2021-0153, CVE-2021-0154, CVE-2021-0155, CVE-2021-0159, CVE-2021-0188, CVE-2021-0189, CVE-2021-0190, CVE-2021-33103, CVE-2021-33122, CVE-2021-33123, CVE-2021-33124; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00598 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220818-0004/

NetApp published this final advisory covering CVE-2022-0001, CVE-2022-0002; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-34265 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220818-0006/

NetApp published this final advisory covering CVE-2022-34265; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-33879 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220812-0004/

NetApp published this final advisory covering CVE-2022-33879; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32532 Apache Shiro Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220812-0002/

NetApp published this final advisory covering CVE-2022-32532; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-29582 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220812-0006/

NetApp published this final advisory covering CVE-2022-29582; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-26477 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220812-0003/

NetApp published this final advisory covering CVE-2022-26477; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23055 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220812-0001/

NetApp published this final advisory covering CVE-2021-23055; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2022-29078 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220804-0001/

NetApp published this final advisory covering CVE-2022-29078; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-25169 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220804-0004/

NetApp published this final advisory covering CVE-2022-25169; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3717 Wildfly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220804-0002/

NetApp published this final advisory covering CVE-2021-3717; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3597 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220804-0003/

NetApp published this final advisory covering CVE-2021-3597; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2017-20052 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220804-0005/

NetApp published this final advisory covering CVE-2017-20052; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2022 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0007/

NetApp published this final advisory covering CVE-2022-22389, CVE-2022-22390; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2022 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0010/

NetApp published this final advisory covering CVE-2022-2031, CVE-2022-32742, CVE-2022-32744, CVE-2022-32745, CVE-2022-32746; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2022 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0004/

NetApp published this final advisory covering CVE-2018-25032, CVE-2022-1292, CVE-2022-21455, CVE-2022-21509, CVE-2022-21515, CVE-2022-21517, CVE-2022-21519, CVE-2022-21522, CVE-2022-21525, CVE-2022-21526, CVE-2022-21527, CVE-2022-21528, CVE-2022-21529, CVE-2022-21530, CVE-2022-21531, CVE-2022-21534, CVE-2022-21537, CVE-2022-21538, CVE-2022-21539, CVE-2022-21547, CVE-2022-21550, CVE-2022-21553, CVE-2022-21556, CVE-2022-21569, CVE-2022-21824, CVE-2022-27778; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2022 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0009/

NetApp published this interim advisory covering CVE-2022-21540, CVE-2022-21541, CVE-2022-21549, CVE-2022-34169; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-34305 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0006/

NetApp published this final advisory covering CVE-2022-34305; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-33105 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0005/

NetApp published this final advisory covering CVE-2022-33105; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23708 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0003/

NetApp published this final advisory covering CVE-2022-23708; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3629 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0008/

NetApp published this final advisory covering CVE-2021-3629; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

July 2022 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0005/

NetApp published this final advisory covering CVE-2022-31625, CVE-2022-31626; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32981 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0006/

NetApp published this final advisory covering CVE-2022-32981; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-30973 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0004/

NetApp published this final advisory covering CVE-2022-30973; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-29244 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0007/

NetApp published this final advisory covering CVE-2022-29244; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1786 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0001/

NetApp published this final advisory covering CVE-2022-1786; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1652 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0002/

NetApp published this final advisory covering CVE-2022-1652; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-33036 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0003/

NetApp published this final advisory covering CVE-2021-33036; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2022 Redis Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0003/

NetApp published this final advisory covering CVE-2022-24735, CVE-2022-24736; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2022-32275 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0008/

NetApp published this final advisory covering CVE-2022-32275; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32250 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0005/

NetApp published this final advisory covering CVE-2022-32250; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-29968 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0009/

NetApp published this final advisory covering CVE-2022-29968; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2022-29824 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0006/

NetApp published this interim advisory covering CVE-2022-29824; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-2274 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0010/

NetApp published this final advisory covering CVE-2022-2274; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; SnapCenter.

Open source
Advisory

CVE-2022-2097 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0011/

NetApp published this final advisory covering CVE-2022-2097; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SMI-S Provider; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapCenter; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-1882 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0002/

NetApp published this final advisory covering CVE-2022-1882; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1678 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0001/

NetApp published this final advisory covering CVE-2022-1678; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; E-Series SANtricity OS Controller Software 11.x; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2021-37404 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0007/

NetApp published this final advisory covering CVE-2021-37404; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-33473 Ruby Gem Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0004/

NetApp published this final advisory covering CVE-2021-33473; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2022 Spring Security Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0003/

NetApp published this final advisory covering CVE-2022-22978, CVE-2022-22976; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

June 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0006/

NetApp published this final advisory covering CVE-2022-31621, CVE-2022-31622, CVE-2022-31623, CVE-2022-31624; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-30594 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0001/

NetApp published this final advisory covering CVE-2022-30594; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-29170 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0005/

NetApp published this final advisory covering CVE-2022-29170; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-28660 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0004/

NetApp published this final advisory covering CVE-2022-28660; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23712 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0010/

NetApp published this final advisory covering CVE-2022-23712; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2068 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0008/

NetApp published this interim advisory covering CVE-2022-2068; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-1998 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0009/

NetApp published this final advisory covering CVE-2022-1998; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1734 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0007/

NetApp published this final advisory covering CVE-2022-1734; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1183 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0002/

NetApp published this final advisory covering CVE-2022-1183; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

May 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0001/

NetApp published this final advisory covering CVE-2022-1353, CVE-2022-1048; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-30689 HashiCorp Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0006/

NetApp published this final advisory covering CVE-2022-30689; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-29885 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0002/

NetApp published this final advisory covering CVE-2022-29885; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-29581 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0005/

NetApp published this final advisory covering CVE-2022-29581; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-29218 RubyGems Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0010/

NetApp published this final advisory covering CVE-2022-29218; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-25844 AngularJS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0009/

NetApp published this interim advisory covering CVE-2022-25844; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Virtual Desktop Service (VDS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-25762 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0003/

NetApp published this final advisory covering CVE-2022-25762; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1679 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0007/

NetApp published this final advisory covering CVE-2022-1679; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1116 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0004/

NetApp published this final advisory covering CVE-2022-1116; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2018-10237 Guava Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0008/

NetApp published this interim advisory covering CVE-2018-10237; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Insights Acquisition Unit; Cloud Insights Storage Workload Security Agent; OnCommand Insight.

Open source
Advisory

CVE-2022-28168 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20220627-0003/

NetApp published this final advisory covering CVE-2022-28168; the API labels exploitation information as **Not public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-28167 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20220627-0002/

NetApp published this final advisory covering CVE-2022-28167; the API labels exploitation information as **Not public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-28166 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20220627-0001/

NetApp published this final advisory covering CVE-2022-28166; the API labels exploitation information as **Not public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

May 2022 Ruby Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0002/

NetApp published this final advisory covering CVE-2022-28738, CVE-2022-28739; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2022 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0005/

NetApp published this final advisory covering CVE-2022-28615, CVE-2022-29404, CVE-2022-30522, CVE-2022-26377, CVE-2022-31813, CVE-2022-30556, CVE-2022-28330, CVE-2022-28614; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

Intel SA-00615 Intel Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0008/

NetApp published this final advisory covering CVE-2022-21123, CVE-2022-21125, CVE-2022-21127, CVE-2022-21166; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-30126 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0004/

NetApp published this final advisory covering CVE-2022-30126; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-21180 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0006/

NetApp published this final advisory covering CVE-2022-21180; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3750 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0003/

NetApp published this final advisory covering CVE-2021-3750; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3611 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0001/

NetApp published this final advisory covering CVE-2021-3611; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220616-0005/

NetApp published this final advisory covering CVE-2022-1622, CVE-2022-1623; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-29176 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220616-0002/

NetApp published this final advisory covering CVE-2022-29176; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24823 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220616-0004/

NetApp published this final advisory covering CVE-2022-24823; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2022-22970 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220616-0006/

NetApp published this final advisory covering CVE-2022-22970; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); OnCommand Insight.

Open source
Advisory

CVE-2015-20107 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220616-0001/

NetApp published this interim advisory covering CVE-2015-20107; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility; SnapCenter.

Open source
Advisory

May 2022 Libcurl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0008/

NetApp published this interim advisory covering CVE-2022-22576, CVE-2022-27774, CVE-2022-27775, CVE-2022-27776; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

May 2022 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0006/

NetApp published this final advisory covering CVE-2021-25745, CVE-2021-25746; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2022 Libcurl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0009/

NetApp published this interim advisory covering CVE-2022-27778, CVE-2022-27779, CVE-2022-27780, CVE-2022-27781, CVE-2022-27782, CVE-2022-30115; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

CVE-2022-29155 OpenLDAP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0007/

NetApp published this final advisory covering CVE-2022-29155; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-28346 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0002/

NetApp published this final advisory covering CVE-2022-28346; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24857 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0003/

NetApp published this final advisory covering CVE-2022-24857; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-41303 Apache Shiro Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0001/

NetApp published this final advisory covering CVE-2021-41303; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3503 WildFly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0004/

NetApp published this final advisory covering CVE-2021-3503; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2021-32040 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0005/

NetApp published this final advisory covering CVE-2021-32040; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2022 Systemd Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0008/

NetApp published this final advisory covering CVE-2022-29799, CVE-2022-29800; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2022 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0009/

NetApp published this interim advisory covering CVE-2022-1292, CVE-2022-1343, CVE-2022-1434, CVE-2022-1473; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

March 2022 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0003/

NetApp published this final advisory covering CVE-2021-20464, CVE-2021-29824, CVE-2021-38886, CVE-2021-38903, CVE-2021-38904, CVE-2021-38905, CVE-2021-38946; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2022-29156 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0002/

NetApp published this final advisory covering CVE-2022-29156; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-29153 HashiCorp Consul Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0005/

NetApp published this final advisory covering CVE-2022-29153; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-22968 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0004/

NetApp published this final advisory covering CVE-2022-22968; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; MetroCluster Tiebreaker for clustered Data ONTAP; Snap Creator Framework.

Open source
Advisory

CVE-2022-0435 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0001/

NetApp published this final advisory covering CVE-2022-0435; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-4197 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0006/

NetApp published this final advisory covering CVE-2021-4197; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4157 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0007/

NetApp published this final advisory covering CVE-2021-4157; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

May 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0006/

NetApp published this final advisory covering CVE-2022-27452, CVE-2022-27451, CVE-2022-27449, CVE-2022-27447, CVE-2022-27446, CVE-2022-27445, CVE-2022-27444, CVE-2022-27448; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-28893 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0002/

NetApp published this final advisory covering CVE-2022-28893; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-27385 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0008/

NetApp published this final advisory covering CVE-2022-27385; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-27379 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0005/

NetApp published this final advisory covering CVE-2022-27379; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0330 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0001/

NetApp published this final advisory covering CVE-2022-0330; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-29752 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0003/

NetApp published this final advisory covering CVE-2021-29752; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-25032 Zlib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0009/

NetApp published this interim advisory covering CVE-2018-25032; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; OnCommand Workflow Automation.

Open source
Advisory

April 2022 MariaDB v10.6.3 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0007/

NetApp published this final advisory covering CVE-2022-27377, CVE-2022-27380, CVE-2022-27455, CVE-2022-27456, CVE-2022-27457, CVE-2022-27458; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0004/

NetApp published this final advisory covering CVE-2022-27378, CVE-2022-27382, CVE-2022-27386, CVE-2022-27387; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0006/

NetApp published this final advisory covering CVE-2022-27381, CVE-2022-27383, CVE-2022-27384; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-27376 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0007/

NetApp published this final advisory covering CVE-2022-27376; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-26612 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0004/

NetApp published this final advisory covering CVE-2022-26612; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24812 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0005/

NetApp published this final advisory covering CVE-2022-24812; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0897 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0002/

NetApp published this final advisory covering CVE-2022-0897; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-0500 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0001/

NetApp published this final advisory covering CVE-2022-0500; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-20295 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0003/

NetApp published this final advisory covering CVE-2021-20295; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2022 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0008/

NetApp published this final advisory covering CVE-2022-27007, CVE-2022-27008, CVE-2022-28049; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2022-24785 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0006/

NetApp published this final advisory covering CVE-2022-24785; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ mobile app.

Open source
Advisory

CVE-2022-1210 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0005/

NetApp published this final advisory covering CVE-2022-1210; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-0998 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0003/

NetApp published this final advisory covering CVE-2022-0998; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4202 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0002/

NetApp published this final advisory covering CVE-2021-4202; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4147 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0004/

NetApp published this final advisory covering CVE-2021-4147; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

April 2022 Linux Kernel 5.17.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0001/

NetApp published this final advisory covering CVE-2022-28388, CVE-2022-28389, CVE-2022-28390; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

March 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0002/

NetApp published this final advisory covering CVE-2022-0907, CVE-2022-0908, CVE-2022-0909, CVE-2022-0924; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-1055 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0007/

NetApp published this final advisory covering CVE-2022-1055; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2020-36518 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0004/

NetApp published this final advisory covering CVE-2020-36518; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); OnCommand Insight; OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

CVE-2019-5188 E2fsprogs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0001/

NetApp published this interim advisory covering CVE-2019-5188; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2017-12652 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0003/

NetApp published this final advisory covering CVE-2017-12652; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

April 2022 OpenBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0005/

NetApp published this final advisory covering CVE-2022-27881, CVE-2022-27882; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0006/

NetApp published this interim advisory covering CVE-2022-28356, CVE-2022-28796; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

March 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0001/

NetApp published this final advisory covering CVE-2022-27666, CVE-2022-0995; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-27191 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0002/

NetApp published this final advisory covering CVE-2022-27191; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-26490 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0004/

NetApp published this final advisory covering CVE-2022-26490; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3582 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0003/

NetApp published this final advisory covering CVE-2021-3582; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2022 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0005/

NetApp published this final advisory covering CVE-2021-22570, CVE-2022-0778, CVE-2022-21412, CVE-2022-21413, CVE-2022-21414, CVE-2022-21415, CVE-2022-21417, CVE-2022-21418, CVE-2022-21423, CVE-2022-21425, CVE-2022-21427, CVE-2022-21435, CVE-2022-21436, CVE-2022-21437, CVE-2022-21438, CVE-2022-21440, CVE-2022-21444, CVE-2022-21451, CVE-2022-21452, CVE-2022-21454, CVE-2022-21457, CVE-2022-21459, CVE-2022-21460, CVE-2022-21462, CVE-2022-21478, CVE-2022-21479, CVE-2022-21482, CVE-2022-21483, CVE-2022-21484, CVE-2022-21485, CVE-2022-21486, CVE-2022-21489, CVE-2022-21490; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2022 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0006/

NetApp published this interim advisory covering CVE-2022-21426, CVE-2022-21434, CVE-2022-21443, CVE-2022-21449, CVE-2022-21476, CVE-2022-21496; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

March 2022 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220425-0003/

NetApp published this final advisory covering CVE-2022-26353, CVE-2022-26354, CVE-2021-20257; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-26148 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220425-0005/

NetApp published this final advisory covering CVE-2022-26148; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1011 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220425-0002/

NetApp published this final advisory covering CVE-2022-1011; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-0742 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220425-0001/

NetApp published this final advisory covering CVE-2022-0742; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3748 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220425-0004/

NetApp published this final advisory covering CVE-2021-3748; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31805 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220420-0001/

NetApp published this final advisory covering CVE-2021-31805; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220419-0001/

NetApp published this final advisory covering CVE-2022-26966, CVE-2022-27223; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

February 2022 Linux Kernel 5.15.2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220419-0003/

NetApp published this final advisory covering CVE-2021-3640, CVE-2021-45868; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-26488 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220419-0005/

NetApp published this final advisory covering CVE-2022-26488; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-0492 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220419-0002/

NetApp published this final advisory covering CVE-2022-0492; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-3609 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220419-0004/

NetApp published this interim advisory covering CVE-2021-3609; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

March 2022 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220408-0001/

NetApp published this final advisory covering CVE-2021-25220, CVE-2022-0396, CVE-2022-0635, CVE-2022-0667; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

February 2022 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0004/

NetApp published this final advisory covering CVE-2021-46708, CVE-2018-25031; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23812 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0005/

NetApp published this final advisory covering CVE-2022-23812; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3743 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0007/

NetApp published this final advisory covering CVE-2021-3743; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3739 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0006/

NetApp published this final advisory covering CVE-2021-3739; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3737 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0009/

NetApp published this final advisory covering CVE-2021-3737; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp XCP NFS; NetApp XCP SMB; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3733 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0001/

NetApp published this interim advisory covering CVE-2021-3733; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3677 Postgresql Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0008/

NetApp published this final advisory covering CVE-2021-3677; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3658 BlueZ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0002/

NetApp published this final advisory covering CVE-2021-3658; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3638 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0003/

NetApp published this final advisory covering CVE-2021-3638; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-22950 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220401-0001/

NetApp published this final advisory covering CVE-2022-22950; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); MetroCluster Tiebreaker for clustered Data ONTAP; OnCommand Insight; Snap Creator Framework; SnapManager for Oracle.

Open source
Advisory

CVE-2022-25365 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0001/

NetApp published this final advisory covering CVE-2022-25365; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24687 HashiCorp Consul Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0006/

NetApp published this final advisory covering CVE-2022-24687; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24685 HashiCorp Nomad Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0007/

NetApp published this final advisory covering CVE-2022-24685; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23308 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0008/

NetApp published this interim advisory covering CVE-2022-23308; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-22965 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0011/

NetApp published this final advisory covering CVE-2022-22965; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0543 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0004/

NetApp published this final advisory covering CVE-2022-0543; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0516 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0009/

NetApp published this final advisory covering CVE-2022-0516; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3667 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0005/

NetApp published this final advisory covering CVE-2021-3667; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3631 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0010/

NetApp published this final advisory covering CVE-2021-3631; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-36516 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0003/

NetApp published this interim advisory covering CVE-2020-36516; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

March 2022 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0007/

NetApp published this final advisory covering CVE-2022-21824, CVE-2021-44531, CVE-2021-44532, CVE-2021-44533; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2022 NPM Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0006/

NetApp published this final advisory covering CVE-2022-0686, CVE-2022-0691; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2021 Grub2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0001/

NetApp published this final advisory covering CVE-2020-25632, CVE-2020-25647, CVE-2020-27749, CVE-2020-27779, CVE-2021-20225, CVE-2021-20233; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-25636 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0002/

NetApp published this final advisory covering CVE-2022-25636; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-24921 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0010/

NetApp published this final advisory covering CVE-2022-24921; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Astra Trident; Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2022-23710 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0009/

NetApp published this final advisory covering CVE-2022-23710; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23395 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0008/

NetApp published this final advisory covering CVE-2022-23395; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0847 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0005/

NetApp published this final advisory covering CVE-2022-0847; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-25217 ISC DHCP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0011/

NetApp published this final advisory covering CVE-2021-25217; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-21708 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0004/

NetApp published this final advisory covering CVE-2021-21708; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-14844 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0003/

NetApp published this final advisory covering CVE-2019-14844; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23235 Information Disclosure Vulnerability in Active IQ Unified Manager

Source: https://security.netapp.com/advisory/NTAP-20220324-0001/

NetApp published this final advisory covering CVE-2022-23235; the API labels exploitation information as **Not public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

March 2022 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220321-0001/

NetApp published this final advisory covering CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0778 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220321-0002/

NetApp published this interim advisory covering CVE-2022-0778; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; Cloud Volumes ONTAP Mediator; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Service Processor - 2554/2552/2520; FAS/AFF Service Processor - 8080/8060/8040/8020; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp Storage Encryption; ONTAP 9; ONTAP Antivirus Connector; ONTAP tools for VMware vSphere 9; SnapManager for Hyper-V; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

February 2022 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0002/

NetApp published this final advisory covering CVE-2021-3607, CVE-2021-3608; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0004/

NetApp published this final advisory covering CVE-2022-24048, CVE-2022-24050, CVE-2022-24051, CVE-2022-24052; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0001/

NetApp published this final advisory covering CVE-2022-0561, CVE-2022-0562; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

February 2022 HashiCorp Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0008/

NetApp published this final advisory covering CVE-2022-24683, CVE-2022-24684, CVE-2022-24686; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-25265 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0005/

NetApp published this interim advisory covering CVE-2022-25265; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2022-0646 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0006/

NetApp published this final advisory covering CVE-2022-0646; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4090 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0010/

NetApp published this final advisory covering CVE-2021-4090; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3947 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0003/

NetApp published this final advisory covering CVE-2021-3947; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3760 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0007/

NetApp published this final advisory covering CVE-2021-3760; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3752 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220318-0009/

NetApp published this final advisory covering CVE-2021-3752; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-22844 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220311-0002/

NetApp published this final advisory covering CVE-2022-22844; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-21724 PostgreSQL JDBC Driver Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220311-0005/

NetApp published this final advisory covering CVE-2022-21724; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-46659 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220311-0003/

NetApp published this final advisory covering CVE-2021-46659; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-4145 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220311-0004/

NetApp published this final advisory covering CVE-2021-4145; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-33150 Intel Trace Hub Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220311-0001/

NetApp published this final advisory covering CVE-2021-33150; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2022 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220303-0007/

NetApp published this final advisory covering CVE-2022-25139, CVE-2021-46461, CVE-2021-46462, CVE-2021-46463; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

February 2022 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220303-0005/

NetApp published this final advisory covering CVE-2022-21702, CVE-2022-21703, CVE-2022-21713; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

February 2022 Expat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220303-0008/

NetApp published this interim advisory covering CVE-2022-25235, CVE-2022-25236, CVE-2022-25313, CVE-2022-25314, CVE-2022-25315; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; ONTAP 9; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-21673 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220303-0004/

NetApp published this final advisory covering CVE-2022-21673; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-45346 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220303-0001/

NetApp published this final advisory covering CVE-2021-45346; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-41816 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220303-0006/

NetApp published this final advisory covering CVE-2021-41816; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20322 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220303-0002/

NetApp published this interim advisory covering CVE-2021-20322; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

February 2022 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0006/

NetApp published this final advisory covering CVE-2022-23772, CVE-2022-23773, CVE-2022-23806; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; BeeGFS CSI Driver; Cloud Insights Telegraf Agent; NetApp Kubernetes Monitoring Operator; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2022-24958 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0008/

NetApp published this interim advisory covering CVE-2022-24958; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

CVE-2022-0391 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0009/

NetApp published this interim advisory covering CVE-2022-0391; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-0185 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0003/

NetApp published this final advisory covering CVE-2022-0185; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-44521 Apache Cassandra Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0001/

NetApp published this final advisory covering CVE-2021-44521; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-4154 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0004/

NetApp published this final advisory covering CVE-2021-4154; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2021-3930 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0007/

NetApp published this final advisory covering CVE-2021-3930; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20373 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0005/

NetApp published this final advisory covering CVE-2021-20373; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-8562 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220225-0002/

NetApp published this final advisory covering CVE-2020-8562; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-41842 InsydeH2O Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220223-0002/

NetApp published this final advisory covering CVE-2021-41842; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/A200/2650/2620/C190/A220/2720/2750/A150.

Open source
Advisory

CVE-2020-5956 InsydeH2O Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220223-0001/

NetApp published this final advisory covering CVE-2020-5956; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-5955 InsydeH2O Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220223-0003/

NetApp published this final advisory covering CVE-2020-5955; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-12532 InsydeH2O Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220223-0004/

NetApp published this final advisory covering CVE-2019-12532; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-41837 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220222-0003/

NetApp published this final advisory covering CVE-2021-41837; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/C190/A220/2720/2750/A150; FAS/AFF BIOS - A700/9000; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2021-33627 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220222-0002/

NetApp published this final advisory covering CVE-2021-33627; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/A200/2650/2620/C190/A220/2720/2750.

Open source
Advisory

CVE-2021-33625 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220222-0004/

NetApp published this final advisory covering CVE-2021-33625; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-5953 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220222-0005/

NetApp published this final advisory covering CVE-2020-5953; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220221-0002/

NetApp published this final advisory covering CVE-2021-46657, CVE-2021-46658, CVE-2021-46661, CVE-2021-46662, CVE-2021-46663, CVE-2021-46664, CVE-2021-46665, CVE-2021-46666, CVE-2021-46667, CVE-2021-46668, CVE-2021-46669; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2022 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220221-0003/

NetApp published this final advisory covering CVE-2022-22818, CVE-2022-23833; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24122 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220221-0001/

NetApp published this final advisory covering CVE-2022-24122; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2019-16884 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220221-0004/

NetApp published this final advisory covering CVE-2019-16884; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23852 Expat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0001/

NetApp published this interim advisory covering CVE-2022-23852; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP 9.

Open source
Advisory

CVE-2022-23222 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0002/

NetApp published this interim advisory covering CVE-2022-23222; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2022-23181 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0010/

NetApp published this final advisory covering CVE-2022-23181; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-43323 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0013/

NetApp published this final advisory covering CVE-2021-43323; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/C190/A220/2720/2750/A150; FAS/AFF BIOS - A700/9000; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2021-42060 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0015/

NetApp published this final advisory covering CVE-2021-42060; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/C190/A220/2720/2750/A150; FAS/AFF BIOS - A700/9000.

Open source
Advisory

CVE-2021-41841 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0012/

NetApp published this interim advisory covering CVE-2021-41841; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/A200/2650/2620/C190/A220/2720/2750; FAS/AFF BIOS - A700/9000; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2021-41840 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0014/

NetApp published this final advisory covering CVE-2021-41840; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-4083 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0005/

NetApp published this interim advisory covering CVE-2021-4083; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2021-39293 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0009/

NetApp published this final advisory covering CVE-2021-39293; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2021-34866 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0008/

NetApp published this final advisory covering CVE-2021-34866; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2021-29632 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0004/

NetApp published this final advisory covering CVE-2021-29632; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-25743 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220217-0003/

NetApp published this final advisory covering CVE-2021-25743; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2022 InsydeH2O Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0004/

NetApp published this final advisory covering CVE-2021-45969, CVE-2021-45970, CVE-2021-45971; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2022-24069 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0002/

NetApp published this final advisory covering CVE-2022-24069; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/C190/A220/2720/2750/A150; FAS/AFF BIOS - A700/9000; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2022-24030 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0011/

NetApp published this final advisory covering CVE-2022-24030; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/C190/A220/2720/2750/A150; FAS/AFF BIOS - A700/9000; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2021-43615 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0010/

NetApp published this final advisory covering CVE-2021-43615; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-43522 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0003/

NetApp published this final advisory covering CVE-2021-43522; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-42554 InsydeH2O Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0007/

NetApp published this interim advisory covering CVE-2021-42554; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - A300/8200/A200/2650/2620/C190/A220/2720/2750; FAS/AFF BIOS - A700/9000; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2021-42113 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0012/

NetApp published this final advisory covering CVE-2021-42113; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-42059 InsydeH20 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0008/

NetApp published this final advisory covering CVE-2021-42059; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-27339 InsydeH2O Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220216-0005/

NetApp published this final advisory covering CVE-2020-27339; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-19343 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220211-0002/

NetApp published this final advisory covering CVE-2019-19343; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-14888 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220211-0001/

NetApp published this final advisory covering CVE-2019-14888; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

Intel SA-00571 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0010/

NetApp published this final advisory covering CVE-2021-33061, CVE-2021-33096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00527 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0007/

NetApp published this interim advisory covering CVE-2021-0091, CVE-2021-0092, CVE-2021-0093, CVE-2021-0099, CVE-2021-0103, CVE-2021-0107, CVE-2021-0111, CVE-2021-0114, CVE-2021-0115, CVE-2021-0116, CVE-2021-0117, CVE-2021-0118, CVE-2021-0119, CVE-2021-0124, CVE-2021-0125, CVE-2021-0156; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series BIOS; FAS/AFF BIOS - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

February 2022 Undertow Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0014/

NetApp published this final advisory covering CVE-2020-10705, CVE-2020-10719; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

February 2022 Apache Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0012/

NetApp published this final advisory covering CVE-2021-37136, CVE-2021-37137; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Cloud Insights Storage Workload Security Agent; OnCommand Insight; SnapCenter.

Open source
Advisory

CVE-2021-37714 jsoup Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0022/

NetApp published this final advisory covering CVE-2021-37714; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2021-3690 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0021/

NetApp published this final advisory covering CVE-2021-3690; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2021-29425 Apache Commons IO Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0004/

NetApp published this final advisory covering CVE-2021-29425; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2021-21290 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0011/

NetApp published this final advisory covering CVE-2021-21290; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2021-20220 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0013/

NetApp published this final advisory covering CVE-2021-20220; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2021-0145 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0009/

NetApp published this final advisory covering CVE-2021-0145; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-0127 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0008/

NetApp published this interim advisory covering CVE-2021-0127; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series BIOS; FAS/AFF BIOS - 8300/8700/A400; NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

CVE-2021-0060 Intel SPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0005/

NetApp published this interim advisory covering CVE-2021-0060; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.

Open source
Advisory

CVE-2020-8908 Guava Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0003/

NetApp published this final advisory covering CVE-2020-8908; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2020-25711 Infinispan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0023/

NetApp published this final advisory covering CVE-2020-25711; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2020-1954 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0001/

NetApp published this final advisory covering CVE-2020-1954; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Workflow Automation; SnapManager for SAP.

Open source
Advisory

CVE-2020-13956 Apache HttpClient Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0002/

NetApp published this final advisory covering CVE-2020-13956; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

CVE-2020-10687 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0015/

NetApp published this final advisory covering CVE-2020-10687; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2019-3888 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0019/

NetApp published this final advisory covering CVE-2019-3888; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-14900 Hibernate ORM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0020/

NetApp published this final advisory covering CVE-2019-14900; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-10219 Hibernate Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0024/

NetApp published this final advisory covering CVE-2019-10219; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-10212 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0017/

NetApp published this final advisory covering CVE-2019-10212; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-10184 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0016/

NetApp published this final advisory covering CVE-2019-10184; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-10174 Infinispan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220210-0018/

NetApp published this final advisory covering CVE-2019-10174; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-21676 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220209-0002/

NetApp published this final advisory covering CVE-2022-21676; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2020 Apache Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220204-0001/

NetApp published this final advisory covering CVE-2019-20445, CVE-2019-20444, CVE-2020-7238, CVE-2019-16869; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Data Availability Services; OnCommand API Services; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2022-23990 Expat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220204-0006/

NetApp published this interim advisory covering CVE-2022-23990; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; ONTAP 9.

Open source
Advisory

CVE-2021-4160 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220204-0005/

NetApp published this final advisory covering CVE-2021-4160; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SMI-S Provider; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

CVE-2020-25638 Hibernate ORM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220204-0003/

NetApp published this final advisory covering CVE-2020-25638; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Snap Creator Framework.

Open source
Advisory

CVE-2022-0336 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220201-0003/

NetApp published this final advisory covering CVE-2022-0336; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-44142 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220201-0002/

NetApp published this final advisory covering CVE-2021-44142; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-44141 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220201-0001/

NetApp published this final advisory covering CVE-2021-44141; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2022 GNU C Library Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220131-0003/

NetApp published this final advisory covering CVE-2022-23218, CVE-2022-23219; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

January 2022 Expat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220131-0004/

NetApp published this interim advisory covering CVE-2022-22822, CVE-2022-22823, CVE-2022-22824, CVE-2022-22825, CVE-2022-22826, CVE-2022-22827; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; ONTAP 9; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-22846 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220131-0005/

NetApp published this interim advisory covering CVE-2022-22846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-41817 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220131-0002/

NetApp published this final advisory covering CVE-2021-41817; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22060 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220131-0001/

NetApp published this final advisory covering CVE-2021-22060; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Element Plug-in for vCenter Server; MetroCluster Tiebreaker for clustered Data ONTAP; OnCommand Insight; Snap Creator Framework; SnapCenter.

Open source
Advisory

CVE-2021-4034 PolicyKit Privilege Escalation Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220128-0001/

NetApp published this final advisory covering CVE-2021-4034; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2022 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0008/

NetApp published this final advisory covering CVE-2021-22946, CVE-2022-21245, CVE-2022-21249, CVE-2022-21253, CVE-2022-21254, CVE-2022-21256, CVE-2022-21264, CVE-2022-21265, CVE-2022-21270, CVE-2022-21278, CVE-2022-21279, CVE-2022-21280, CVE-2022-21284, CVE-2022-21285, CVE-2022-21286, CVE-2022-21287, CVE-2022-21288, CVE-2022-21289, CVE-2022-21290, CVE-2022-21297, CVE-2022-21301, CVE-2022-21302, CVE-2022-21303, CVE-2022-21304, CVE-2022-21307, CVE-2022-21308, CVE-2022-21309, CVE-2022-21310, CVE-2022-21311, CVE-2022-21312, CVE-2022-21313, CVE-2022-21314, CVE-2022-21315, CVE-2022-21316, CVE-2022-21317, CVE-2022-21318, CVE-2022-21319, CVE-2022-21320, CVE-2022-21321, CVE-2022-21322, CVE-2022-21323, CVE-2022-21324, CVE-2022-21325, CVE-2022-21326, CVE-2022-21327, CVE-2022-21328, CVE-2022-21329, CVE-2022-21330, CVE-2022-21331, CVE-2022-21332, CVE-2022-21333, CVE-2022-21334, CVE-2022-21335, CVE-2022-21336, CVE-2022-21337, CVE-2022-21339, CVE-2022-21342, CVE-2022-21344, CVE-2022-21348, CVE-2022-21351, CVE-2022-21352, CVE-2022-21355, CVE-2022-21356, CVE-2022-21357, CVE-2022-21358, CVE-2022-21362, CVE-2022-21367, CVE-2022-21368, CVE-2022-21370, CVE-2022-21372, CVE-2022-21374, CVE-2022-21378, CVE-2022-21379, CVE-2022-21380; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2022 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0007/

NetApp published this interim advisory covering CVE-2022-21248, CVE-2022-21271, CVE-2022-21277, CVE-2022-21282, CVE-2022-21283, CVE-2022-21291, CVE-2022-21293, CVE-2022-21294, CVE-2022-21296, CVE-2022-21299, CVE-2022-21305, CVE-2022-21340, CVE-2022-21341, CVE-2022-21349, CVE-2022-21360, CVE-2022-21365, CVE-2022-21366; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Cloud Insights Acquisition Unit; Cloud Insights Storage Workload Security Agent; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter; SANtricity Unified Manager; SnapManager for Oracle; SnapManager for SAP.

Open source
Advisory

January 2022 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0005/

NetApp published this final advisory covering CVE-2021-45115, CVE-2021-45116, CVE-2021-45452; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-46143 Expat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0006/

NetApp published this interim advisory covering CVE-2021-46143; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; ONTAP 9; OnCommand Workflow Automation.

Open source
Advisory

CVE-2021-45960 Expat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0004/

NetApp published this interim advisory covering CVE-2021-45960; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SolidFire & HCI Management Node; OnCommand Workflow Automation.

Open source
Advisory

CVE-2021-45485 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0001/

NetApp published this interim advisory covering CVE-2021-45485; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-44716 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0002/

NetApp published this final advisory covering CVE-2021-44716; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Astra Control Center - NetApp Kubernetes Monitoring Operator; Cloud Insights Telegraf Agent; NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2021-41819 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220121-0003/

NetApp published this final advisory covering CVE-2021-41819; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-42392 H2 Database Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220119-0001/

NetApp published this final advisory covering CVE-2021-42392; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2022 X.Org X Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220114-0004/

NetApp published this final advisory covering CVE-2021-4008, CVE-2021-4009, CVE-2021-4010, CVE-2021-4011; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220114-0003/

NetApp published this final advisory covering CVE-2021-44733, CVE-2021-45469; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

December 2021 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220114-0002/

NetApp published this final advisory covering CVE-2021-29678, CVE-2021-38926, CVE-2021-39002; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2021-44548 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220114-0005/

NetApp published this final advisory covering CVE-2021-44548; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-38931 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220114-0001/

NetApp published this final advisory covering CVE-2021-38931; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-43566 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220110-0001/

NetApp published this final advisory covering CVE-2021-43566; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20316 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220110-0002/

NetApp published this final advisory covering CVE-2021-20316; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2022 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220107-0006/

NetApp published this final advisory covering CVE-2021-43813, CVE-2021-43815; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-45459 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220107-0004/

NetApp published this final advisory covering CVE-2021-45459; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-45100 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220107-0001/

NetApp published this final advisory covering CVE-2021-45100; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-45078 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220107-0002/

NetApp published this final advisory covering CVE-2021-45078; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-43818 lxml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220107-0005/

NetApp published this interim advisory covering CVE-2021-43818; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-44832 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220104-0001/

NetApp published this final advisory covering CVE-2021-44832; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source