Content Library · Advisory

Advisory 2022

Browse 501 2022 NetApp advisory records in the NetApp Black Box content library. Page 3 of 5.

Library JSON API

Showing all 120 items on this page

Advisory

CVE-2022-28168 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20220627-0003/

NetApp published this final advisory covering CVE-2022-28168; the API labels exploitation information as **Not public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-28167 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20220627-0002/

NetApp published this final advisory covering CVE-2022-28167; the API labels exploitation information as **Not public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2022-28166 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20220627-0001/

NetApp published this final advisory covering CVE-2022-28166; the API labels exploitation information as **Not public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

May 2022 Ruby Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0002/

NetApp published this final advisory covering CVE-2022-28738, CVE-2022-28739; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2022 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0005/

NetApp published this final advisory covering CVE-2022-28615, CVE-2022-29404, CVE-2022-30522, CVE-2022-26377, CVE-2022-31813, CVE-2022-30556, CVE-2022-28330, CVE-2022-28614; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

Intel SA-00615 Intel Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0008/

NetApp published this final advisory covering CVE-2022-21123, CVE-2022-21125, CVE-2022-21127, CVE-2022-21166; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-30126 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0004/

NetApp published this final advisory covering CVE-2022-30126; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-21180 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0006/

NetApp published this final advisory covering CVE-2022-21180; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3750 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0003/

NetApp published this final advisory covering CVE-2021-3750; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3611 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220624-0001/

NetApp published this final advisory covering CVE-2021-3611; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220616-0005/

NetApp published this final advisory covering CVE-2022-1622, CVE-2022-1623; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-29176 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220616-0002/

NetApp published this final advisory covering CVE-2022-29176; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24823 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220616-0004/

NetApp published this final advisory covering CVE-2022-24823; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2022-22970 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220616-0006/

NetApp published this final advisory covering CVE-2022-22970; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); OnCommand Insight.

Open source
Advisory

CVE-2015-20107 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220616-0001/

NetApp published this interim advisory covering CVE-2015-20107; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility; SnapCenter.

Open source
Advisory

May 2022 Libcurl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0008/

NetApp published this interim advisory covering CVE-2022-22576, CVE-2022-27774, CVE-2022-27775, CVE-2022-27776; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

May 2022 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0006/

NetApp published this final advisory covering CVE-2021-25745, CVE-2021-25746; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2022 Libcurl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0009/

NetApp published this interim advisory covering CVE-2022-27778, CVE-2022-27779, CVE-2022-27780, CVE-2022-27781, CVE-2022-27782, CVE-2022-30115; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

CVE-2022-29155 OpenLDAP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0007/

NetApp published this final advisory covering CVE-2022-29155; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-28346 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0002/

NetApp published this final advisory covering CVE-2022-28346; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24857 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0003/

NetApp published this final advisory covering CVE-2022-24857; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-41303 Apache Shiro Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0001/

NetApp published this final advisory covering CVE-2021-41303; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3503 WildFly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0004/

NetApp published this final advisory covering CVE-2021-3503; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2021-32040 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220609-0005/

NetApp published this final advisory covering CVE-2021-32040; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2022 Systemd Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0008/

NetApp published this final advisory covering CVE-2022-29799, CVE-2022-29800; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2022 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0009/

NetApp published this interim advisory covering CVE-2022-1292, CVE-2022-1343, CVE-2022-1434, CVE-2022-1473; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

March 2022 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0003/

NetApp published this final advisory covering CVE-2021-20464, CVE-2021-29824, CVE-2021-38886, CVE-2021-38903, CVE-2021-38904, CVE-2021-38905, CVE-2021-38946; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2022-29156 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0002/

NetApp published this final advisory covering CVE-2022-29156; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-29153 HashiCorp Consul Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0005/

NetApp published this final advisory covering CVE-2022-29153; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-22968 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0004/

NetApp published this final advisory covering CVE-2022-22968; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; MetroCluster Tiebreaker for clustered Data ONTAP; Snap Creator Framework.

Open source
Advisory

CVE-2022-0435 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0001/

NetApp published this final advisory covering CVE-2022-0435; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-4197 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0006/

NetApp published this final advisory covering CVE-2021-4197; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4157 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220602-0007/

NetApp published this final advisory covering CVE-2021-4157; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

May 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0006/

NetApp published this final advisory covering CVE-2022-27452, CVE-2022-27451, CVE-2022-27449, CVE-2022-27447, CVE-2022-27446, CVE-2022-27445, CVE-2022-27444, CVE-2022-27448; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-28893 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0002/

NetApp published this final advisory covering CVE-2022-28893; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-27385 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0008/

NetApp published this final advisory covering CVE-2022-27385; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-27379 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0005/

NetApp published this final advisory covering CVE-2022-27379; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0330 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0001/

NetApp published this final advisory covering CVE-2022-0330; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-29752 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0003/

NetApp published this final advisory covering CVE-2021-29752; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-25032 Zlib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0009/

NetApp published this interim advisory covering CVE-2018-25032; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; OnCommand Workflow Automation.

Open source
Advisory

April 2022 MariaDB v10.6.3 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0007/

NetApp published this final advisory covering CVE-2022-27377, CVE-2022-27380, CVE-2022-27455, CVE-2022-27456, CVE-2022-27457, CVE-2022-27458; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220526-0004/

NetApp published this final advisory covering CVE-2022-27378, CVE-2022-27382, CVE-2022-27386, CVE-2022-27387; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2022 MariaDB Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0006/

NetApp published this final advisory covering CVE-2022-27381, CVE-2022-27383, CVE-2022-27384; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-27376 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0007/

NetApp published this final advisory covering CVE-2022-27376; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-26612 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0004/

NetApp published this final advisory covering CVE-2022-26612; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24812 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0005/

NetApp published this final advisory covering CVE-2022-24812; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0897 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0002/

NetApp published this final advisory covering CVE-2022-0897; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-0500 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0001/

NetApp published this final advisory covering CVE-2022-0500; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-20295 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0003/

NetApp published this final advisory covering CVE-2021-20295; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2022 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220519-0008/

NetApp published this final advisory covering CVE-2022-27007, CVE-2022-27008, CVE-2022-28049; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).

Open source
Advisory

CVE-2022-24785 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0006/

NetApp published this final advisory covering CVE-2022-24785; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ mobile app.

Open source
Advisory

CVE-2022-1210 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0005/

NetApp published this final advisory covering CVE-2022-1210; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-0998 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0003/

NetApp published this final advisory covering CVE-2022-0998; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4202 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0002/

NetApp published this final advisory covering CVE-2021-4202; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-4147 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0004/

NetApp published this final advisory covering CVE-2021-4147; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

April 2022 Linux Kernel 5.17.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220513-0001/

NetApp published this final advisory covering CVE-2022-28388, CVE-2022-28389, CVE-2022-28390; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

March 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0002/

NetApp published this final advisory covering CVE-2022-0907, CVE-2022-0908, CVE-2022-0909, CVE-2022-0924; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-1055 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0007/

NetApp published this final advisory covering CVE-2022-1055; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2020-36518 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0004/

NetApp published this final advisory covering CVE-2020-36518; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); OnCommand Insight; OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

CVE-2019-5188 E2fsprogs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0001/

NetApp published this interim advisory covering CVE-2019-5188; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2017-12652 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0003/

NetApp published this final advisory covering CVE-2017-12652; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

April 2022 OpenBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0005/

NetApp published this final advisory covering CVE-2022-27881, CVE-2022-27882; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220506-0006/

NetApp published this interim advisory covering CVE-2022-28356, CVE-2022-28796; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

March 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0001/

NetApp published this final advisory covering CVE-2022-27666, CVE-2022-0995; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-27191 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0002/

NetApp published this final advisory covering CVE-2022-27191; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-26490 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0004/

NetApp published this final advisory covering CVE-2022-26490; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3582 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0003/

NetApp published this final advisory covering CVE-2021-3582; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2022 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0005/

NetApp published this final advisory covering CVE-2021-22570, CVE-2022-0778, CVE-2022-21412, CVE-2022-21413, CVE-2022-21414, CVE-2022-21415, CVE-2022-21417, CVE-2022-21418, CVE-2022-21423, CVE-2022-21425, CVE-2022-21427, CVE-2022-21435, CVE-2022-21436, CVE-2022-21437, CVE-2022-21438, CVE-2022-21440, CVE-2022-21444, CVE-2022-21451, CVE-2022-21452, CVE-2022-21454, CVE-2022-21457, CVE-2022-21459, CVE-2022-21460, CVE-2022-21462, CVE-2022-21478, CVE-2022-21479, CVE-2022-21482, CVE-2022-21483, CVE-2022-21484, CVE-2022-21485, CVE-2022-21486, CVE-2022-21489, CVE-2022-21490; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2022 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220429-0006/

NetApp published this interim advisory covering CVE-2022-21426, CVE-2022-21434, CVE-2022-21443, CVE-2022-21449, CVE-2022-21476, CVE-2022-21496; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Storage Manager; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

March 2022 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220425-0003/

NetApp published this final advisory covering CVE-2022-26353, CVE-2022-26354, CVE-2021-20257; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-26148 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220425-0005/

NetApp published this final advisory covering CVE-2022-26148; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1011 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220425-0002/

NetApp published this final advisory covering CVE-2022-1011; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-0742 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220425-0001/

NetApp published this final advisory covering CVE-2022-0742; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3748 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220425-0004/

NetApp published this final advisory covering CVE-2021-3748; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31805 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220420-0001/

NetApp published this final advisory covering CVE-2021-31805; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2022 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220419-0001/

NetApp published this final advisory covering CVE-2022-26966, CVE-2022-27223; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

February 2022 Linux Kernel 5.15.2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220419-0003/

NetApp published this final advisory covering CVE-2021-3640, CVE-2021-45868; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-26488 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220419-0005/

NetApp published this final advisory covering CVE-2022-26488; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-0492 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220419-0002/

NetApp published this final advisory covering CVE-2022-0492; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-3609 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220419-0004/

NetApp published this interim advisory covering CVE-2021-3609; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

March 2022 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220408-0001/

NetApp published this final advisory covering CVE-2021-25220, CVE-2022-0396, CVE-2022-0635, CVE-2022-0667; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

February 2022 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0004/

NetApp published this final advisory covering CVE-2021-46708, CVE-2018-25031; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23812 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0005/

NetApp published this final advisory covering CVE-2022-23812; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3743 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0007/

NetApp published this final advisory covering CVE-2021-3743; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3739 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0006/

NetApp published this final advisory covering CVE-2021-3739; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3737 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0009/

NetApp published this final advisory covering CVE-2021-3737; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp XCP NFS; NetApp XCP SMB; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3733 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0001/

NetApp published this interim advisory covering CVE-2021-3733; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3677 Postgresql Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0008/

NetApp published this final advisory covering CVE-2021-3677; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3658 BlueZ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0002/

NetApp published this final advisory covering CVE-2021-3658; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3638 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220407-0003/

NetApp published this final advisory covering CVE-2021-3638; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-22950 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220401-0001/

NetApp published this final advisory covering CVE-2022-22950; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); MetroCluster Tiebreaker for clustered Data ONTAP; OnCommand Insight; Snap Creator Framework; SnapManager for Oracle.

Open source
Advisory

CVE-2022-25365 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0001/

NetApp published this final advisory covering CVE-2022-25365; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24687 HashiCorp Consul Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0006/

NetApp published this final advisory covering CVE-2022-24687; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24685 HashiCorp Nomad Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0007/

NetApp published this final advisory covering CVE-2022-24685; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23308 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0008/

NetApp published this interim advisory covering CVE-2022-23308; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-22965 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0011/

NetApp published this final advisory covering CVE-2022-22965; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0543 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0004/

NetApp published this final advisory covering CVE-2022-0543; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0516 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0009/

NetApp published this final advisory covering CVE-2022-0516; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-3667 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0005/

NetApp published this final advisory covering CVE-2021-3667; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-3631 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0010/

NetApp published this final advisory covering CVE-2021-3631; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-36516 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220331-0003/

NetApp published this interim advisory covering CVE-2020-36516; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

March 2022 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0007/

NetApp published this final advisory covering CVE-2022-21824, CVE-2021-44531, CVE-2021-44532, CVE-2021-44533; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2022 NPM Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0006/

NetApp published this final advisory covering CVE-2022-0686, CVE-2022-0691; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2021 Grub2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0001/

NetApp published this final advisory covering CVE-2020-25632, CVE-2020-25647, CVE-2020-27749, CVE-2020-27779, CVE-2021-20225, CVE-2021-20233; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-25636 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0002/

NetApp published this final advisory covering CVE-2022-25636; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-24921 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0010/

NetApp published this final advisory covering CVE-2022-24921; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Astra Trident; Cloud Insights Telegraf Agent.

Open source
Advisory

CVE-2022-23710 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0009/

NetApp published this final advisory covering CVE-2022-23710; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23395 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0008/

NetApp published this final advisory covering CVE-2022-23395; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0847 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0005/

NetApp published this final advisory covering CVE-2022-0847; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-25217 ISC DHCP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0011/

NetApp published this final advisory covering CVE-2021-25217; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-21708 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0004/

NetApp published this final advisory covering CVE-2021-21708; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-14844 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220325-0003/

NetApp published this final advisory covering CVE-2019-14844; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23235 Information Disclosure Vulnerability in Active IQ Unified Manager

Source: https://security.netapp.com/advisory/NTAP-20220324-0001/

NetApp published this final advisory covering CVE-2022-23235; the API labels exploitation information as **Not public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

March 2022 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220321-0001/

NetApp published this final advisory covering CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-0778 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20220321-0002/

NetApp published this interim advisory covering CVE-2022-0778; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; Cloud Volumes ONTAP Mediator; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Service Processor - 2554/2552/2520; FAS/AFF Service Processor - 8080/8060/8040/8020; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SANtricity SMI-S Provider; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp Storage Encryption; ONTAP 9; ONTAP Antivirus Connector; ONTAP tools for VMware vSphere 9; SnapManager for Hyper-V; StorageGRID (formerly StorageGRID Webscale).

Open source