Content Library · Advisory

Advisory 2022

Browse 501 2022 NetApp advisory records in the NetApp Black Box content library. Page 2 of 5.

Library JSON API

Showing all 120 items on this page

Advisory

CVE-2022-0358 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0008/

NetApp published this final advisory covering CVE-2022-0358; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-46828 libtirpc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0004/

NetApp published this final advisory covering CVE-2021-46828; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3772 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20221007-0001/

NetApp published this interim advisory covering CVE-2021-3772; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

July 2022 Grub Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0001/

NetApp published this final advisory covering CVE-2021-3695, CVE-2021-3696, CVE-2021-3697; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-35252 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0005/

NetApp published this interim advisory covering CVE-2022-35252; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9.

Open source
Advisory

CVE-2022-34526 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0002/

NetApp published this final advisory covering CVE-2022-34526; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-1619 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0007/

NetApp published this interim advisory covering CVE-2022-1619; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2022-1271 GNU Gzip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220930-0006/

NetApp published this final advisory covering CVE-2022-1271; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32189 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220923-0003/

NetApp published this final advisory covering CVE-2022-32189; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-28948 Go-Yaml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220923-0006/

NetApp published this final advisory covering CVE-2022-28948; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident; Astra Trident Autosupport.

Open source
Advisory

CVE-2022-27664 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220923-0004/

NetApp published this final advisory covering CVE-2022-27664; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Astra Control Center - NetApp Kubernetes Monitoring Operator; BeeGFS CSI Driver; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator; Trident; Trident Autosupport.

Open source
Advisory

CVE-2022-21233 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220923-0002/

NetApp published this final advisory covering CVE-2022-21233; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-20824 Cisco Discovery Protocol Denial of Service and Arbitrary Code Execution Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20220923-0001/

NetApp published this final advisory covering CVE-2022-20824; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1996 go-restful Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220923-0005/

NetApp published this final advisory covering CVE-2022-1996; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2022 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0001/

NetApp published this final advisory covering CVE-2022-32212, CVE-2022-32213, CVE-2022-32214, CVE-2022-32215, CVE-2022-32222, CVE-2022-32223; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2022 Libcurl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0003/

NetApp published this interim advisory covering CVE-2022-32208, CVE-2022-32207, CVE-2022-32206, CVE-2022-32205; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

July 2022 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0004/

NetApp published this final advisory covering CVE-2022-30629, CVE-2022-30634; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2022-36359 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0008/

NetApp published this final advisory covering CVE-2022-36359; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-35737 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0009/

NetApp published this final advisory covering CVE-2022-35737; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-31150 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0002/

NetApp published this final advisory covering CVE-2022-31150; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-25168 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0007/

NetApp published this final advisory covering CVE-2022-25168; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2309 lxml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0006/

NetApp published this final advisory covering CVE-2022-2309; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-4209 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0005/

NetApp published this interim advisory covering CVE-2021-4209; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

April 2022 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220915-0010/

NetApp published this final advisory covering CVE-2022-24675, CVE-2022-28327; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-36313 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0005/

NetApp published this final advisory covering CVE-2022-36313; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31160 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0007/

NetApp published this final advisory covering CVE-2022-31160; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Virtual Desktop Service (VDS); SnapCenter.

Open source
Advisory

CVE-2022-31151 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0006/

NetApp published this final advisory covering CVE-2022-31151; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31144 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0002/

NetApp published this final advisory covering CVE-2022-31144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2191 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0003/

NetApp published this final advisory covering CVE-2022-2191; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-17498 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220909-0004/

NetApp published this interim advisory covering CVE-2019-17498; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

July 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0007/

NetApp published this interim advisory covering CVE-2022-36879, CVE-2022-36946; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

July 2022 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0010/

NetApp published this final advisory covering CVE-2022-31097, CVE-2022-31107; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.

Open source
Advisory

CVE-2022-37434 Zlib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0005/

NetApp published this final advisory covering CVE-2022-37434; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; OnCommand Workflow Automation; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2022-36129 HashiCorp Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0011/

NetApp published this final advisory covering CVE-2022-36129; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-36123 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0003/

NetApp published this final advisory covering CVE-2022-36123; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-25647 Google Gson Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0009/

NetApp published this final advisory covering CVE-2022-25647; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2022-1671 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0004/

NetApp published this final advisory covering CVE-2022-1671; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1651 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0008/

NetApp published this final advisory covering CVE-2022-1651; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2020-28445 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0012/

NetApp published this final advisory covering CVE-2020-28445; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2022 Eclipse Jetty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220901-0006/

NetApp published this interim advisory covering CVE-2022-2047, CVE-2022-2048; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); SnapCenter.

Open source
Advisory

June 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0001/

NetApp published this final advisory covering CVE-2022-2056, CVE-2022-2057, CVE-2022-2058; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-34918 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0004/

NetApp published this final advisory covering CVE-2022-34918; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-34903 GnuPG Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0005/

NetApp published this final advisory covering CVE-2022-34903; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-32086 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0007/

NetApp published this final advisory covering CVE-2022-32086; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32083 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0006/

NetApp published this final advisory covering CVE-2022-32083; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-31627 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0008/

NetApp published this final advisory covering CVE-2022-31627; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-40663 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220826-0002/

NetApp published this final advisory covering CVE-2021-40663; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220818-0005/

NetApp published this final advisory covering CVE-2022-32089, CVE-2022-32081, CVE-2022-32088, CVE-2022-32087, CVE-2022-32082, CVE-2022-32085, CVE-2022-32084, CVE-2022-32091; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00601 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220818-0003/

NetApp published this final advisory covering CVE-2021-0153, CVE-2021-0154, CVE-2021-0155, CVE-2021-0159, CVE-2021-0188, CVE-2021-0189, CVE-2021-0190, CVE-2021-33103, CVE-2021-33122, CVE-2021-33123, CVE-2021-33124; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00598 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220818-0004/

NetApp published this final advisory covering CVE-2022-0001, CVE-2022-0002; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-34265 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220818-0006/

NetApp published this final advisory covering CVE-2022-34265; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-33879 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220812-0004/

NetApp published this final advisory covering CVE-2022-33879; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32532 Apache Shiro Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220812-0002/

NetApp published this final advisory covering CVE-2022-32532; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-29582 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220812-0006/

NetApp published this final advisory covering CVE-2022-29582; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-26477 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220812-0003/

NetApp published this final advisory covering CVE-2022-26477; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23055 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220812-0001/

NetApp published this final advisory covering CVE-2021-23055; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2022-29078 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220804-0001/

NetApp published this final advisory covering CVE-2022-29078; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-25169 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220804-0004/

NetApp published this final advisory covering CVE-2022-25169; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3717 Wildfly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220804-0002/

NetApp published this final advisory covering CVE-2021-3717; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3597 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220804-0003/

NetApp published this final advisory covering CVE-2021-3597; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2017-20052 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220804-0005/

NetApp published this final advisory covering CVE-2017-20052; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2022 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0007/

NetApp published this final advisory covering CVE-2022-22389, CVE-2022-22390; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2022 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0010/

NetApp published this final advisory covering CVE-2022-2031, CVE-2022-32742, CVE-2022-32744, CVE-2022-32745, CVE-2022-32746; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2022 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0004/

NetApp published this final advisory covering CVE-2018-25032, CVE-2022-1292, CVE-2022-21455, CVE-2022-21509, CVE-2022-21515, CVE-2022-21517, CVE-2022-21519, CVE-2022-21522, CVE-2022-21525, CVE-2022-21526, CVE-2022-21527, CVE-2022-21528, CVE-2022-21529, CVE-2022-21530, CVE-2022-21531, CVE-2022-21534, CVE-2022-21537, CVE-2022-21538, CVE-2022-21539, CVE-2022-21547, CVE-2022-21550, CVE-2022-21553, CVE-2022-21556, CVE-2022-21569, CVE-2022-21824, CVE-2022-27778; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2022 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0009/

NetApp published this interim advisory covering CVE-2022-21540, CVE-2022-21541, CVE-2022-21549, CVE-2022-34169; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-34305 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0006/

NetApp published this final advisory covering CVE-2022-34305; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-33105 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0005/

NetApp published this final advisory covering CVE-2022-33105; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23708 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0003/

NetApp published this final advisory covering CVE-2022-23708; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3629 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220729-0008/

NetApp published this final advisory covering CVE-2021-3629; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

July 2022 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0005/

NetApp published this final advisory covering CVE-2022-31625, CVE-2022-31626; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32981 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0006/

NetApp published this final advisory covering CVE-2022-32981; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-30973 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0004/

NetApp published this final advisory covering CVE-2022-30973; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-29244 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0007/

NetApp published this final advisory covering CVE-2022-29244; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1786 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0001/

NetApp published this final advisory covering CVE-2022-1786; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1652 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0002/

NetApp published this final advisory covering CVE-2022-1652; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-33036 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220722-0003/

NetApp published this final advisory covering CVE-2021-33036; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2022 Redis Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0003/

NetApp published this final advisory covering CVE-2022-24735, CVE-2022-24736; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2022-32275 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0008/

NetApp published this final advisory covering CVE-2022-32275; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32250 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0005/

NetApp published this final advisory covering CVE-2022-32250; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-29968 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0009/

NetApp published this final advisory covering CVE-2022-29968; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2022-29824 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0006/

NetApp published this interim advisory covering CVE-2022-29824; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-2274 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0010/

NetApp published this final advisory covering CVE-2022-2274; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; SnapCenter.

Open source
Advisory

CVE-2022-2097 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0011/

NetApp published this final advisory covering CVE-2022-2097; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SMI-S Provider; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapCenter; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-1882 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0002/

NetApp published this final advisory covering CVE-2022-1882; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1678 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0001/

NetApp published this final advisory covering CVE-2022-1678; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; E-Series SANtricity OS Controller Software 11.x; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2021-37404 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0007/

NetApp published this final advisory covering CVE-2021-37404; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-33473 Ruby Gem Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220715-0004/

NetApp published this final advisory covering CVE-2021-33473; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2022 Spring Security Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0003/

NetApp published this final advisory covering CVE-2022-22978, CVE-2022-22976; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

June 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0006/

NetApp published this final advisory covering CVE-2022-31621, CVE-2022-31622, CVE-2022-31623, CVE-2022-31624; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-30594 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0001/

NetApp published this final advisory covering CVE-2022-30594; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-29170 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0005/

NetApp published this final advisory covering CVE-2022-29170; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-28660 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0004/

NetApp published this final advisory covering CVE-2022-28660; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23712 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0010/

NetApp published this final advisory covering CVE-2022-23712; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2068 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0008/

NetApp published this interim advisory covering CVE-2022-2068; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-1998 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0009/

NetApp published this final advisory covering CVE-2022-1998; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1734 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0007/

NetApp published this final advisory covering CVE-2022-1734; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1183 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220707-0002/

NetApp published this final advisory covering CVE-2022-1183; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

May 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0001/

NetApp published this final advisory covering CVE-2022-1353, CVE-2022-1048; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-30689 HashiCorp Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0006/

NetApp published this final advisory covering CVE-2022-30689; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-29885 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0002/

NetApp published this final advisory covering CVE-2022-29885; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-29581 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0005/

NetApp published this final advisory covering CVE-2022-29581; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-29218 RubyGems Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0010/

NetApp published this final advisory covering CVE-2022-29218; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-25844 AngularJS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0009/

NetApp published this interim advisory covering CVE-2022-25844; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Virtual Desktop Service (VDS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-25762 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0003/

NetApp published this final advisory covering CVE-2022-25762; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1679 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0007/

NetApp published this final advisory covering CVE-2022-1679; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-1116 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0004/

NetApp published this final advisory covering CVE-2022-1116; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2018-10237 Guava Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220629-0008/

NetApp published this interim advisory covering CVE-2018-10237; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Insights Acquisition Unit; Cloud Insights Storage Workload Security Agent; OnCommand Insight.

Open source