Content Library · Advisory

Advisory 2023

Browse 560 2023 NetApp advisory records in the NetApp Black Box content library.

Library JSON API

Advisory

CVE-2023-5954 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0001/

NetApp published this final advisory covering CVE-2023-5954; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-48237 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0005/

NetApp published this interim advisory covering CVE-2023-48237; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-48236 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0002/

NetApp published this interim advisory covering CVE-2023-48236; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-48235 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0007/

NetApp published this interim advisory covering CVE-2023-48235; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-48234 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0004/

NetApp published this interim advisory covering CVE-2023-48234; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-48233 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0003/

NetApp published this interim advisory covering CVE-2023-48233; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-48232 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0006/

NetApp published this interim advisory covering CVE-2023-48232; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-48231 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0008/

NetApp published this interim advisory covering CVE-2023-48231; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2019-3773 Spring Web Services Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0011/

NetApp published this final advisory covering CVE-2019-3773; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-10158 Infinispan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0009/

NetApp published this final advisory covering CVE-2019-10158; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-8088 SLF4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231227-0010/

NetApp published this final advisory covering CVE-2018-8088; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

November 2023 AsyncSSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231222-0001/

NetApp published this final advisory covering CVE-2023-46445, CVE-2023-46446; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Converged Systems Advisor Agent.

Open source
Advisory

CVE-2023-4809 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0009/

NetApp published this final advisory covering CVE-2023-4809; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-43665 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0001/

NetApp published this final advisory covering CVE-2023-43665; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3955 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0002/

NetApp published this final advisory covering CVE-2023-3955; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3893 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0004/

NetApp published this final advisory covering CVE-2023-3893; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-34055 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0010/

NetApp published this final advisory covering CVE-2023-34055; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28376 Intel Ethernet Controller Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0007/

NetApp published this final advisory covering CVE-2023-28376; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1194 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0006/

NetApp published this interim advisory covering CVE-2023-1194; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-3172 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0005/

NetApp published this final advisory covering CVE-2022-3172; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-25736 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231221-0003/

NetApp published this final advisory covering CVE-2021-25736; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5978 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0003/

NetApp published this final advisory covering CVE-2023-5978; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5941 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0004/

NetApp published this final advisory covering CVE-2023-5941; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-50164 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0010/

NetApp published this final advisory covering CVE-2023-50164; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46848 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0005/

NetApp published this final advisory covering CVE-2023-46848; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46728 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0006/

NetApp published this final advisory covering CVE-2023-46728; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46695 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0001/

NetApp published this final advisory covering CVE-2023-46695; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-45283 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0008/

NetApp published this final advisory covering CVE-2023-45283; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Cloud Insights Telegraf Agent; NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2023-41164 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0002/

NetApp published this final advisory covering CVE-2023-41164; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-34053 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231214-0007/

NetApp published this final advisory covering CVE-2023-34053; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2023 Supermicro BMC Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0009/

NetApp published this final advisory covering CVE-2023-40284, CVE-2023-40285, CVE-2023-40286, CVE-2023-40287, CVE-2023-40288, CVE-2023-40289, CVE-2023-40290; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

October 2023 Grub Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0002/

NetApp published this final advisory covering CVE-2023-4692, CVE-2023-4693; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-5178 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0004/

NetApp published this interim advisory covering CVE-2023-5178; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-5088 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0005/

NetApp published this final advisory covering CVE-2023-5088; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46724 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0001/

NetApp published this final advisory covering CVE-2023-46724; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46246 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0006/

NetApp published this interim advisory covering CVE-2023-46246; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4399 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0003/

NetApp published this final advisory covering CVE-2023-4399; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-34969 D-Bus Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0007/

NetApp published this interim advisory covering CVE-2023-34969; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS; NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-3138 libX11 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0008/

NetApp published this interim advisory covering CVE-2023-3138; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-27539 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0016/

NetApp published this final advisory covering CVE-2023-27539; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-27530 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0015/

NetApp published this final advisory covering CVE-2023-27530; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-44572 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0014/

NetApp published this final advisory covering CVE-2022-44572; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-44571 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0013/

NetApp published this final advisory covering CVE-2022-44571; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-44570 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0010/

NetApp published this final advisory covering CVE-2022-44570; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-30123 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0011/

NetApp published this final advisory covering CVE-2022-30123; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-30122 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231208-0012/

NetApp published this final advisory covering CVE-2022-30122; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2023 X.Org X Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0004/

NetApp published this final advisory covering CVE-2023-5574, CVE-2023-5367, CVE-2023-5380; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2023 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0002/

NetApp published this final advisory covering CVE-2023-46847, CVE-2023-46846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5824 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0003/

NetApp published this final advisory covering CVE-2023-5824; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5678 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0010/

NetApp published this interim advisory covering CVE-2023-5678; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-45853 Zlib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0009/

NetApp published this interim advisory covering CVE-2023-45853; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4163 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20231130-0001/

NetApp published this final advisory covering CVE-2023-4163; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2023-3676 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0007/

NetApp published this final advisory covering CVE-2023-3676; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-31418 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0005/

NetApp published this final advisory covering CVE-2023-31418; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-31417 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0006/

NetApp published this final advisory covering CVE-2023-31417; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-4900 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231130-0008/

NetApp published this final advisory covering CVE-2022-4900; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2023 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231124-0002/

NetApp published this final advisory covering CVE-2023-3961, CVE-2023-4154, CVE-2023-4091, CVE-2023-42669, CVE-2023-42670; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2023-5568 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231124-0007/

NetApp published this final advisory covering CVE-2023-5568; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5370 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231124-0005/

NetApp published this final advisory covering CVE-2023-5370; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5369 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231124-0009/

NetApp published this final advisory covering CVE-2023-5369; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5368 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231124-0004/

NetApp published this final advisory covering CVE-2023-5368; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46136 Werkzeug Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231124-0008/

NetApp published this final advisory covering CVE-2023-46136; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-4162 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20231124-0010/

NetApp published this final advisory covering CVE-2023-4162; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3489 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20231124-0003/

NetApp published this final advisory covering CVE-2023-3489; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2023-32252 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231124-0001/

NetApp published this final advisory covering CVE-2023-32252; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

October 2023 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0009/

NetApp published this final advisory covering CVE-2023-39331, CVE-2023-39332; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2023 IBM DB2 11.5.x Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0007/

NetApp published this final advisory covering CVE-2023-40372, CVE-2023-38740, CVE-2023-40374; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2023 IBM DB2 11.1.4.x and 11.5.x Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0005/

NetApp published this final advisory covering CVE-2023-38720, CVE-2023-30991; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2023 IBM DB2 10.5.0.x, 11.1.4.x, and 11.5.x Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0006/

NetApp published this final advisory covering CVE-2023-40373, CVE-2023-38728, CVE-2023-30987; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-45862 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0004/

NetApp published this interim advisory covering CVE-2023-45862; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-4527 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0012/

NetApp published this interim advisory covering CVE-2023-4527; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-45145 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0014/

NetApp published this interim advisory covering CVE-2023-45145; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2023-44466 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0003/

NetApp published this interim advisory covering CVE-2023-44466; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-38719 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0008/

NetApp published this final advisory covering CVE-2023-38719; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38552 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0013/

NetApp published this final advisory covering CVE-2023-38552; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-31419 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0010/

NetApp published this final advisory covering CVE-2023-31419; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2680 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0001/

NetApp published this final advisory covering CVE-2023-2680; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-23583 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0015/

NetApp published this interim advisory covering CVE-2023-23583; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - 2820; FAS/AFF BIOS - A900/9500; NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2022-48554 File Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231116-0002/

NetApp published this final advisory covering CVE-2022-48554; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2023 Gradle Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0006/

NetApp published this final advisory covering CVE-2023-42445, CVE-2023-44387; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

October 2023 7-Zip Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0007/

NetApp published this final advisory covering CVE-2023-31102, CVE-2023-40481; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-4813 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0003/

NetApp published this interim advisory covering CVE-2023-4813; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-46604 Apache ActiveMQ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0010/

NetApp published this final advisory covering CVE-2023-46604; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity Unified Manager and Web Services Proxy; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2023-45871 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0001/

NetApp published this final advisory covering CVE-2023-45871; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-40791 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0009/

NetApp published this interim advisory covering CVE-2023-40791; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-40745 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0005/

NetApp published this final advisory covering CVE-2023-40745; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-32636 Gnome Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231110-0002/

NetApp published this final advisory covering CVE-2023-32636; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2023 GNU Binutils 2.40 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0003/

NetApp published this final advisory covering CVE-2023-25588, CVE-2023-25585, CVE-2023-25586; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

October 2023 libX11 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0006/

NetApp published this interim advisory covering CVE-2023-43785, CVE-2023-43786, CVE-2023-43787; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux.

Open source
Advisory

October 2023 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0007/

NetApp published this interim advisory covering CVE-2023-45648, CVE-2023-42795; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-4822 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0008/

NetApp published this final advisory covering CVE-2023-4822; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-42467 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0005/

NetApp published this final advisory covering CVE-2023-42467; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-32005 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0004/

NetApp published this final advisory covering CVE-2023-32005; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29499 Gnome Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0001/

NetApp published this interim advisory covering CVE-2023-29499; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-25584 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231103-0002/

NetApp published this final advisory covering CVE-2023-25584; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

October 2023 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0009/

NetApp published this final advisory covering CVE-2023-22015, CVE-2023-22026, CVE-2023-22028, CVE-2023-22032, CVE-2023-22059, CVE-2023-22064, CVE-2023-22065, CVE-2023-22066, CVE-2023-22068, CVE-2023-22070, CVE-2023-22078, CVE-2023-22079, CVE-2023-22084, CVE-2023-22092, CVE-2023-22095, CVE-2023-22097, CVE-2023-22103, CVE-2023-22104, CVE-2023-22110, CVE-2023-22111, CVE-2023-22112, CVE-2023-22113, CVE-2023-22114, CVE-2023-22115, CVE-2023-2650, CVE-2023-38545; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2023 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0006/

NetApp published this interim advisory covering CVE-2023-22025, CVE-2023-22067, CVE-2023-22081; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS); OnCommand Workflow Automation.

Open source
Advisory

October 2023 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0011/

NetApp published this final advisory covering CVE-2023-31122, CVE-2023-43622, CVE-2023-45802; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5363 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0010/

NetApp published this interim advisory covering CVE-2023-5363; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4004 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0001/

NetApp published this final advisory covering CVE-2023-4004; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-32611 Gnome Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0005/

NetApp published this final advisory covering CVE-2023-32611; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3223 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0004/

NetApp published this interim advisory covering CVE-2023-3223; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-22102 MySQL Connector/J Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0007/

NetApp published this final advisory covering CVE-2023-22102; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2014-3577 Apache HttpComponents HttpClient Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0003/

NetApp published this final advisory covering CVE-2014-3577; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2023 Linux Kernel 6.5-rc5 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231027-0002/

NetApp published this final advisory covering CVE-2023-4273, CVE-2023-4128, CVE-2023-4194; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

September 2023 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0008/

NetApp published this final advisory covering CVE-2023-3255, CVE-2023-3301; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2023 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0009/

NetApp published this final advisory covering CVE-2023-39318, CVE-2023-39319; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2023 Golang 1.21.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0004/

NetApp published this final advisory covering CVE-2023-39320, CVE-2023-39321, CVE-2023-39322; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-42503 Apache Commons Compress Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0003/

NetApp published this final advisory covering CVE-2023-42503; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-4147 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0006/

NetApp published this interim advisory covering CVE-2023-4147; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-4132 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0005/

NetApp published this final advisory covering CVE-2023-4132; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-40283 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0007/

NetApp published this final advisory covering CVE-2023-40283; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-39323 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0001/

NetApp published this final advisory covering CVE-2023-39323; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1260 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0010/

NetApp published this final advisory covering CVE-2023-1260; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1108 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0002/

NetApp published this final advisory covering CVE-2023-1108; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-44487 HTTP/2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231016-0001/

NetApp published this final advisory covering CVE-2023-44487; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; OnCommand Insight; Trident; Trident Autosupport.

Open source
Advisory

CVE-2023-4911 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231013-0006/

NetApp published this interim advisory covering CVE-2023-4911; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-4236 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231013-0004/

NetApp published this final advisory covering CVE-2023-4236; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-41835 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231013-0001/

NetApp published this final advisory covering CVE-2023-41835; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38039 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231013-0005/

NetApp published this final advisory covering CVE-2023-38039; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; ONTAP 9; ONTAP Antivirus Connector.

Open source
Advisory

CVE-2023-3341 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231013-0003/

NetApp published this final advisory covering CVE-2023-3341; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

October 2023 curl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231011-0001/

NetApp published this interim advisory covering CVE-2023-38545, CVE-2023-38546; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-41105 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0015/

NetApp published this interim advisory covering CVE-2023-41105; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-40217 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0014/

NetApp published this interim advisory covering CVE-2023-40217; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-32559 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0006/

NetApp published this final advisory covering CVE-2023-32559; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-48566 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0013/

NetApp published this interim advisory covering CVE-2022-48566; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; NetApp Converged Systems Advisor Agent; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-48565 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0007/

NetApp published this interim advisory covering CVE-2022-48565; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); NetApp XCP NFS; NetApp XCP SMB.

Open source
Advisory

CVE-2022-45703 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0003/

NetApp published this final advisory covering CVE-2022-45703; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

CVE-2022-36648 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0004/

NetApp published this final advisory covering CVE-2022-36648; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-35205 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0010/

NetApp published this final advisory covering CVE-2022-35205; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

CVE-2021-32050 MongoDB Drivers Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0001/

NetApp published this final advisory covering CVE-2021-32050; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-35342 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0009/

NetApp published this final advisory covering CVE-2020-35342; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

CVE-2020-24165 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0012/

NetApp published this final advisory covering CVE-2020-24165; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-22218 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0002/

NetApp published this interim advisory covering CVE-2020-22218; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

August 2023 GNU Ncurses Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0005/

NetApp published this final advisory covering CVE-2020-19190, CVE-2020-19189, CVE-2020-19188, CVE-2020-19187, CVE-2020-19186, CVE-2020-19185; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2023 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0008/

NetApp published this final advisory covering CVE-2022-48063, CVE-2022-48064, CVE-2022-48065; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

CVE-2023-4863 Libwebp Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0011/

NetApp published this final advisory covering CVE-2023-4863; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-3212 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0005/

NetApp published this final advisory covering CVE-2023-3212; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-2898 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0002/

NetApp published this final advisory covering CVE-2023-2898; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-2269 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0004/

NetApp published this final advisory covering CVE-2023-2269; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1206 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0006/

NetApp published this interim advisory covering CVE-2023-1206; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-48564 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0009/

NetApp published this interim advisory covering CVE-2022-48564; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-48560 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0008/

NetApp published this final advisory covering CVE-2022-48560; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-4269 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0001/

NetApp published this final advisory covering CVE-2022-4269; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-32292 JSON-C Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0010/

NetApp published this final advisory covering CVE-2021-32292; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2020-21490 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0007/

NetApp published this final advisory covering CVE-2020-21490; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

April 2023 Linux Kernel 6.2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0003/

NetApp published this final advisory covering CVE-2023-31081, CVE-2023-31082, CVE-2023-31083, CVE-2023-31084, CVE-2023-31085; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-4807 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230921-0001/

NetApp published this interim advisory covering CVE-2023-4807; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-41080 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230921-0006/

NetApp published this interim advisory covering CVE-2023-41080; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-1409 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230921-0007/

NetApp published this final advisory covering CVE-2023-1409; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-35637 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230921-0003/

NetApp published this final advisory covering CVE-2022-35637; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-22483 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230921-0004/

NetApp published this final advisory covering CVE-2022-22483; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 Linux Kernel 6.3.9 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0011/

NetApp published this final advisory covering CVE-2023-32258, CVE-2023-32257, CVE-2023-32247; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4135 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0012/

NetApp published this final advisory covering CVE-2023-4135; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-40360 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0004/

NetApp published this final advisory covering CVE-2023-40360; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-39975 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0014/

NetApp published this final advisory covering CVE-2023-39975; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38426 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0010/

NetApp published this interim advisory covering CVE-2023-38426; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2023-32248 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0006/

NetApp published this final advisory covering CVE-2023-32248; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-25775 Intel Ethernet Controller Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0013/

NetApp published this final advisory covering CVE-2023-25775; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22276 Intel Ethernet Controller Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0007/

NetApp published this final advisory covering CVE-2023-22276; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-48522 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0008/

NetApp published this interim advisory covering CVE-2022-48522; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Workflow Automation; SRA Plugin for Linux.

Open source
Advisory

CVE-2022-41804 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0003/

NetApp published this interim advisory covering CVE-2022-41804; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2021-3236 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0001/

NetApp published this interim advisory covering CVE-2021-3236; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2023 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0002/

NetApp published this final advisory covering CVE-2023-39417, CVE-2023-39418; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2023 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0009/

NetApp published this final advisory covering CVE-2023-32002, CVE-2023-32003, CVE-2023-32004, CVE-2023-32006; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3611 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0002/

NetApp published this final advisory covering CVE-2023-3611; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-36054 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0004/

NetApp published this interim advisory covering CVE-2023-36054; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP 9; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-3269 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0001/

NetApp published this final advisory covering CVE-2023-3269; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-1255 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0006/

NetApp published this interim advisory covering CVE-2023-1255; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-24999 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0005/

NetApp published this final advisory covering CVE-2022-24999; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24963 Apache Portable Runtime (APR) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0008/

NetApp published this final advisory covering CVE-2022-24963; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9.

Open source
Advisory

August 2023 Brocade Fabric OS Vulnerabilities

Source: https://security.netapp.com/advisory/NTAP-20230908-0007/

NetApp published this final advisory covering CVE-2023-31425, CVE-2023-31426, CVE-2023-31427, CVE-2023-31428, CVE-2023-31429, CVE-2023-31430, CVE-2023-31431, CVE-2023-31432, CVE-2023-31926, CVE-2023-31927, CVE-2023-31928; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

July 2023 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0005/

NetApp published this final advisory covering CVE-2023-1386, CVE-2023-3019; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0007/

NetApp published this final advisory covering CVE-2023-37903, CVE-2023-37466; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-4009 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0013/

NetApp published this final advisory covering CVE-2023-4009; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3896 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0012/

NetApp published this final advisory covering CVE-2023-3896; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-38633 GNOME Librsvg Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0011/

NetApp published this final advisory covering CVE-2023-38633; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38432 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0002/

NetApp published this final advisory covering CVE-2023-38432; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-38430 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0003/

NetApp published this final advisory covering CVE-2023-38430; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-38428 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0001/

NetApp published this final advisory covering CVE-2023-38428; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3494 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0006/

NetApp published this final advisory covering CVE-2023-3494; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3180 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0008/

NetApp published this final advisory covering CVE-2023-3180; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29409 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0010/

NetApp published this final advisory covering CVE-2023-29409; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); Trident.

Open source
Advisory

CVE-2023-26045 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0004/

NetApp published this final advisory covering CVE-2023-26045; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2023 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0009/

NetApp published this final advisory covering CVE-2023-29407, CVE-2023-29408; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 Grub Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230825-0002/

NetApp published this final advisory covering CVE-2022-28733, CVE-2022-28734, CVE-2022-28735, CVE-2022-28736; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2023 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230825-0001/

NetApp published this final advisory covering CVE-2023-3823, CVE-2023-3824; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 Linux Kernel 6.4 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0004/

NetApp published this final advisory covering CVE-2023-32250, CVE-2023-32254; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

July 2023 Linux Kernel 6.3.7 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0011/

NetApp published this final advisory covering CVE-2023-38427, CVE-2023-38431; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

Intel SA-00813 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0001/

NetApp published this interim advisory covering CVE-2022-27879, CVE-2022-37343, CVE-2022-38083, CVE-2022-43505, CVE-2022-44611; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00783 CSME Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0002/

NetApp published this interim advisory covering CVE-2022-36392, CVE-2022-29871, CVE-2022-38102; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38325 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0010/

NetApp published this interim advisory covering CVE-2023-38325; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-3618 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0012/

NetApp published this final advisory covering CVE-2023-3618; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-35001 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0007/

NetApp published this final advisory covering CVE-2023-35001; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3338 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0005/

NetApp published this final advisory covering CVE-2023-3338; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3268 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0006/

NetApp published this final advisory covering CVE-2023-3268; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-23908 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0003/

NetApp published this interim advisory covering CVE-2023-23908; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2022-31693 VMware Tools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0009/

NetApp published this final advisory covering CVE-2022-31693; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-32256 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0013/

NetApp published this interim advisory covering CVE-2021-32256; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); SRA Plugin for Linux.

Open source
Advisory

July 2023 Linux Kernel 6.3 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0005/

NetApp published this final advisory covering CVE-2023-3609, CVE-2023-3610; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

July 2023 JetBrains Kotlin Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0012/

NetApp published this final advisory covering CVE-2019-10101, CVE-2019-10102, CVE-2019-10103; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

February 2023 Werkzeug Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0003/

NetApp published this final advisory covering CVE-2023-23934, CVE-2023-25577; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2023-38403 iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0016/

NetApp published this final advisory covering CVE-2023-38403; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-3817 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0014/

NetApp published this interim advisory covering CVE-2023-3817; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-35012 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0013/

NetApp published this final advisory covering CVE-2023-35012; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3390 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0004/

NetApp published this final advisory covering CVE-2023-3390; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-30861 Flask Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0006/

NetApp published this final advisory covering CVE-2023-30861; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-2976 Guava Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0008/

NetApp published this interim advisory covering CVE-2023-2976; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); NetApp Manageability SDK; OnCommand Insight.

Open source
Advisory

CVE-2023-27558 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0017/

NetApp published this final advisory covering CVE-2023-27558; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23221 H2 Database Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0011/

NetApp published this final advisory covering CVE-2022-23221; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1471 SnakeYAML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0015/

NetApp published this interim advisory covering CVE-2022-1471; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS); Spot PC.

Open source
Advisory

CVE-2021-40690 Apache XML Security for Java Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0002/

NetApp published this final advisory covering CVE-2021-40690; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23463 H2 Database Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0010/

NetApp published this final advisory covering CVE-2021-23463; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10650 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0007/

NetApp published this final advisory covering CVE-2020-10650; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-12402 Apache Commons Compress Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0001/

NetApp published this final advisory covering CVE-2019-12402; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 MegaRAC BMC Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0004/

NetApp published this interim advisory covering CVE-2023-34329, CVE-2023-34330; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

CVE-2023-36824 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0009/

NetApp published this interim advisory covering CVE-2023-36824; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-34034 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0008/

NetApp published this final advisory covering CVE-2023-34034; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29406 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0002/

NetApp published this final advisory covering CVE-2023-29406; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator; Trident; Trident Autosupport.

Open source
Advisory

CVE-2023-28953 IBM Cognos Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0001/

NetApp published this final advisory covering CVE-2023-28953; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2878 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0003/

NetApp published this final advisory covering CVE-2023-2878; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24834 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0006/

NetApp published this final advisory covering CVE-2022-24834; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2021-31294 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0007/

NetApp published this final advisory covering CVE-2021-31294; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-40982 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230811-0001/

NetApp published this interim advisory covering CVE-2022-40982; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - 2820; FAS/AFF BIOS - 8300/8700/A400/C400; FAS/AFF BIOS - A250/500f/C250; FAS/AFF BIOS - A320; FAS/AFF BIOS - A800/C800; FAS/AFF BIOS - A900/9500; NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Advisory

June 2023 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0002/

NetApp published this final advisory covering CVE-2023-35823, CVE-2023-35824, CVE-2023-35826, CVE-2023-35828, CVE-2023-35829; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

July 2023 Kubernetes Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0004/

NetApp published this final advisory covering CVE-2023-2727, CVE-2023-2728; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 IBM DB2 JDBC Driver Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0006/

NetApp published this final advisory covering CVE-2023-27869, CVE-2023-27868, CVE-2023-27867; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38408 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0010/

NetApp published this interim advisory covering CVE-2023-38408; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-35947 Gradle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0007/

NetApp published this final advisory covering CVE-2023-35947; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-35827 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0003/

NetApp published this final advisory covering CVE-2023-35827; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-34462 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0001/

NetApp published this final advisory covering CVE-2023-34462; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-3446 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0011/

NetApp published this interim advisory covering CVE-2023-3446; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-34457 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0005/

NetApp published this final advisory covering CVE-2023-34457; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-30586 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230803-0008/

NetApp published this final advisory covering CVE-2023-30586; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0010/

NetApp published this final advisory covering CVE-2022-2127, CVE-2023-3347, CVE-2023-34966, CVE-2023-34967, CVE-2023-34968; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0007/

NetApp published this final advisory covering CVE-2023-23487, CVE-2023-29256, CVE-2023-30431, CVE-2023-30442, CVE-2023-30443, CVE-2023-30445, CVE-2023-30446, CVE-2023-30447, CVE-2023-30448, CVE-2023-30449; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2023 MegaRAC BMC Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0008/

NetApp published this final advisory covering CVE-2022-26872, CVE-2022-40258; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

CVE-2023-35946 Gradle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0003/

NetApp published this final advisory covering CVE-2023-35946; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3389 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0001/

NetApp published this final advisory covering CVE-2023-3389; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3312 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0005/

NetApp published this interim advisory covering CVE-2023-3312; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-3090 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0002/

NetApp published this final advisory covering CVE-2023-3090; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-2908 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0004/

NetApp published this final advisory covering CVE-2023-2908; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-1295 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0006/

NetApp published this final advisory covering CVE-2023-1295; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2015-20109 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230731-0009/

NetApp published this final advisory covering CVE-2015-20109; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

July 2023 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230725-0005/

NetApp published this final advisory covering CVE-2022-4899, CVE-2023-0361, CVE-2023-21950, CVE-2023-22005, CVE-2023-22007, CVE-2023-22008, CVE-2023-22033, CVE-2023-22038, CVE-2023-22046, CVE-2023-22048, CVE-2023-22053, CVE-2023-22054, CVE-2023-22056, CVE-2023-22057, CVE-2023-22058; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2023 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230725-0006/

NetApp published this interim advisory covering CVE-2023-22006, CVE-2023-22036, CVE-2023-22041, CVE-2023-22043, CVE-2023-22044, CVE-2023-22045, CVE-2023-22049, CVE-2023-25193; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-36617 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230725-0002/

NetApp published this final advisory covering CVE-2023-36617; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-2975 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230725-0004/

NetApp published this interim advisory covering CVE-2023-2975; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-20867 VMware Tools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230725-0001/

NetApp published this final advisory covering CVE-2023-20867; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-23064 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230725-0003/

NetApp published this final advisory covering CVE-2020-23064; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Brocade SAN Navigator (SANnav); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Virtual Desktop Service (VDS); Spot PC.

Open source
Advisory

CVE-2023-35788 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230714-0002/

NetApp published this final advisory covering CVE-2023-35788; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-34981 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230714-0003/

NetApp published this final advisory covering CVE-2023-34981; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3326 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230714-0005/

NetApp published this final advisory covering CVE-2023-3326; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3128 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230714-0004/

NetApp published this final advisory covering CVE-2023-3128; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0045 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230714-0001/

NetApp published this interim advisory covering CVE-2023-0045; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node.

Open source
Advisory

June 2023 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0006/

NetApp published this final advisory covering CVE-2023-2454, CVE-2023-2455; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

June 2023 Grafana Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0002/

NetApp published this final advisory covering CVE-2023-2801, CVE-2023-2183; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2023 Apache Struts Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0005/

NetApp published this final advisory covering CVE-2023-34149, CVE-2023-34396; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3141 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0004/

NetApp published this final advisory covering CVE-2023-3141; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-2700 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0001/

NetApp published this final advisory covering CVE-2023-2700; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-26965 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0009/

NetApp published this final advisory covering CVE-2023-26965; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-3515 Libksba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0008/

NetApp published this final advisory covering CVE-2022-3515; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-36732 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0003/

NetApp published this final advisory covering CVE-2020-36732; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-35525 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230706-0007/

NetApp published this final advisory covering CVE-2020-35525; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

May 2023 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0002/

NetApp published this final advisory covering CVE-2023-30775, CVE-2023-30774; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2023 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0010/

NetApp published this interim advisory covering CVE-2023-2828, CVE-2023-2829, CVE-2023-2911; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3111 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0007/

NetApp published this final advisory covering CVE-2023-3111; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-2953 OpenLDAP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0005/

NetApp published this interim advisory covering CVE-2023-2953; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP 9; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-2731 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0009/

NetApp published this final advisory covering CVE-2023-2731; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2650 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0001/

NetApp published this interim advisory covering CVE-2023-2650; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-2598 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0006/

NetApp published this final advisory covering CVE-2023-2598; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-20883 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0008/

NetApp published this final advisory covering CVE-2023-20883; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-48502 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0004/

NetApp published this final advisory covering CVE-2022-48502; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2015-20108 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230703-0003/

NetApp published this final advisory covering CVE-2015-20108; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

May 2023 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0007/

NetApp published this final advisory covering CVE-2023-27563, CVE-2023-27564, CVE-2023-27562; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-33250 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0006/

NetApp published this final advisory covering CVE-2023-33250; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-31125 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0002/

NetApp published this final advisory covering CVE-2023-31125; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28410 Intel Graphics Drivers Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0004/

NetApp published this final advisory covering CVE-2023-28410; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2156 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0001/

NetApp published this final advisory covering CVE-2023-2156; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-2124 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0010/

NetApp published this final advisory covering CVE-2023-2124; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2020-36694 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0005/

NetApp published this interim advisory covering CVE-2020-36694; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2018-3745 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230622-0009/

NetApp published this final advisory covering CVE-2018-3745; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Virtual Desktop Service (VDS); Spot PC.

Open source
Advisory

CVE-2023-32305 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230616-0006/

NetApp published this final advisory covering CVE-2023-32305; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-32233 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230616-0002/

NetApp published this final advisory covering CVE-2023-32233; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-31655 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230616-0005/

NetApp published this final advisory covering CVE-2023-31655; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-30086 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230616-0003/

NetApp published this final advisory covering CVE-2023-30086; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-40540 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230616-0001/

NetApp published this final advisory covering CVE-2022-40540; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

May 2023 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0009/

NetApp published this interim advisory covering CVE-2023-28319, CVE-2023-28320, CVE-2023-28321, CVE-2023-28322; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Antivirus Connector.

Open source
Advisory

May 2023 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0006/

NetApp published this final advisory covering CVE-2023-28724, CVE-2023-28656; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-31436 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0001/

NetApp published this final advisory covering CVE-2023-31436; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-31047 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0008/

NetApp published this final advisory covering CVE-2023-31047; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2235 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0002/

NetApp published this final advisory covering CVE-2023-2235; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-2197 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0007/

NetApp published this final advisory covering CVE-2023-2197; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2176 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0005/

NetApp published this final advisory covering CVE-2023-2176; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-2006 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0004/

NetApp published this final advisory covering CVE-2023-2006; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1387 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0003/

NetApp published this final advisory covering CVE-2023-1387; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-31239 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230609-0010/

NetApp published this final advisory covering CVE-2021-31239; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-30846 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0008/

NetApp published this final advisory covering CVE-2023-30846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28856 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0007/

NetApp published this interim advisory covering CVE-2023-28856; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2023-27043 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0003/

NetApp published this interim advisory covering CVE-2023-27043; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-2236 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0010/

NetApp published this final advisory covering CVE-2023-2236; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-20873 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0009/

NetApp published this interim advisory covering CVE-2023-20873; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-1989 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0004/

NetApp published this final advisory covering CVE-2023-1989; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1872 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0002/

NetApp published this final advisory covering CVE-2023-1872; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1829 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0001/

NetApp published this final advisory covering CVE-2023-1829; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-21216 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0005/

NetApp published this interim advisory covering CVE-2022-21216; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series BIOS; FAS/AFF BIOS - A900/9500; NetApp HCI Compute Node BIOS.

Open source
Advisory

April 2023 Libxml2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230601-0006/

NetApp published this final advisory covering CVE-2023-28484, CVE-2023-29469; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SMI-S Provider; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

March 2023 Hashicorp Vault Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0008/

NetApp published this final advisory covering CVE-2023-25000, CVE-2023-0665, CVE-2023-0620; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29323 OpenBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0006/

NetApp published this final advisory covering CVE-2023-29323; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28756 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0004/

NetApp published this final advisory covering CVE-2023-28756; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-28755 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0003/

NetApp published this final advisory covering CVE-2023-28755; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-20862 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0002/

NetApp published this final advisory covering CVE-2023-20862; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-1670 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0010/

NetApp published this final advisory covering CVE-2023-1670; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-4744 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0009/

NetApp published this final advisory covering CVE-2022-4744; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2020-24736 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0005/

NetApp published this final advisory covering CVE-2020-24736; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

April 2023 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0007/

NetApp published this final advisory covering CVE-2023-24536, CVE-2023-24534; the API labels exploitation information as **Public**. The API currently lists affected products as: Trident.

Open source
Advisory

April 2023 Eclipse Jetty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230526-0001/

NetApp published this interim advisory covering CVE-2023-26049, CVE-2023-26048; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

February 2023 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0001/

NetApp published this final advisory covering CVE-2023-0662, CVE-2023-0568; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

CVE-2023-28464 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0004/

NetApp published this final advisory covering CVE-2023-28464; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-26463 strongSwan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0010/

NetApp published this final advisory covering CVE-2023-26463; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2008 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0007/

NetApp published this final advisory covering CVE-2023-2008; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1838 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0003/

NetApp published this final advisory covering CVE-2023-1838; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0664 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0005/

NetApp published this final advisory covering CVE-2023-0664; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0210 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0002/

NetApp published this final advisory covering CVE-2023-0210; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-46880 LibreSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230517-0006/

NetApp published this final advisory covering CVE-2021-46880; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-30456 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0007/

NetApp published this final advisory covering CVE-2023-30456; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1652 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0006/

NetApp published this final advisory covering CVE-2023-1652; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1579 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0009/

NetApp published this final advisory covering CVE-2023-1579; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); SRA Plugin for Linux.

Open source
Advisory

CVE-2023-1550 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0008/

NetApp published this final advisory covering CVE-2023-1550; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-1544 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0005/

NetApp published this final advisory covering CVE-2023-1544; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1380 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0001/

NetApp published this final advisory covering CVE-2023-1380; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1077 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0002/

NetApp published this interim advisory covering CVE-2023-1077; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0179 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0003/

NetApp published this final advisory covering CVE-2023-0179; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3162 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0004/

NetApp published this final advisory covering CVE-2022-3162; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2023 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0010/

NetApp published this final advisory covering CVE-2023-26021, CVE-2023-26022, CVE-2023-27559, CVE-2023-29255, CVE-2023-29257, CVE-2023-25930, CVE-2023-27555; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-26604 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0009/

NetApp published this final advisory covering CVE-2023-26604; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-26464 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0008/

NetApp published this interim advisory covering CVE-2023-26464; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24999 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0001/

NetApp published this final advisory covering CVE-2023-24999; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-20860 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0006/

NetApp published this final advisory covering CVE-2023-20860; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-1252 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0005/

NetApp published this final advisory covering CVE-2023-1252; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1078 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0004/

NetApp published this final advisory covering CVE-2023-1078; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-48424 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0002/

NetApp published this final advisory covering CVE-2022-48424; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-48423 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0003/

NetApp published this final advisory covering CVE-2022-48423; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3294 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0007/

NetApp published this final advisory covering CVE-2022-3294; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3116 Heimdal Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0010/

NetApp published this final advisory covering CVE-2022-3116; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28772 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0005/

NetApp published this final advisory covering CVE-2023-28772; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-28466 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0006/

NetApp published this final advisory covering CVE-2023-28466; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-27475 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0003/

NetApp published this final advisory covering CVE-2023-27475; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-21971 MySQL Connector/J Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0010/

NetApp published this final advisory covering CVE-2023-21971; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2023-1281 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0004/

NetApp published this final advisory covering CVE-2023-1281; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0482 RESTEasy Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0001/

NetApp published this final advisory covering CVE-2023-0482; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-0812 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0011/

NetApp published this final advisory covering CVE-2022-0812; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-39537 GNU Ncurses Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0012/

NetApp published this interim advisory covering CVE-2021-39537; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer; NetApp SolidFire & HCI Management Node.

Open source
Advisory

April 2023 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0007/

NetApp published this final advisory covering CVE-2022-37434, CVE-2022-43548, CVE-2022-43551, CVE-2023-0215, CVE-2023-21911, CVE-2023-21912, CVE-2023-21913, CVE-2023-21917, CVE-2023-21919, CVE-2023-21920, CVE-2023-21929, CVE-2023-21933, CVE-2023-21935, CVE-2023-21940, CVE-2023-21945, CVE-2023-21946, CVE-2023-21947, CVE-2023-21953, CVE-2023-21955, CVE-2023-21962, CVE-2023-21963, CVE-2023-21966, CVE-2023-21971, CVE-2023-21972, CVE-2023-21976, CVE-2023-21977, CVE-2023-21980, CVE-2023-21982; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2023 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0008/

NetApp published this interim advisory covering CVE-2023-21930, CVE-2023-21937, CVE-2023-21938, CVE-2023-21939, CVE-2023-21954, CVE-2023-21967, CVE-2023-21968; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Brocade SAN Navigator (SANnav); Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp SolidFire & HCI Management Node; OnCommand Insight.

Open source
Advisory

March 2023 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0010/

NetApp published this interim advisory covering CVE-2023-27535, CVE-2023-27536, CVE-2023-27537, CVE-2023-27538; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9.

Open source
Advisory

March 2023 Sudo Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0002/

NetApp published this interim advisory covering CVE-2023-28486, CVE-2023-28487; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-27534 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0012/

NetApp published this final advisory covering CVE-2023-27534; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-27533 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0011/

NetApp published this final advisory covering CVE-2023-27533; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2023-27490 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0006/

NetApp published this final advisory covering CVE-2023-27490; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-20861 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0007/

NetApp published this final advisory covering CVE-2023-20861; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Snap Creator Framework.

Open source
Advisory

CVE-2023-1410 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0003/

NetApp published this final advisory covering CVE-2023-1410; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1390 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0001/

NetApp published this final advisory covering CVE-2023-1390; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0386 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0004/

NetApp published this final advisory covering CVE-2023-0386; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-4095 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0005/

NetApp published this final advisory covering CVE-2022-4095; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-2097 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0008/

NetApp published this final advisory covering CVE-2022-2097; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

March 2023 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230414-0001/

NetApp published this interim advisory covering CVE-2023-0465, CVE-2023-0466; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Manageability SDK; NetApp SMI-S Provider; ONTAP 9; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-28531 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0008/

NetApp published this final advisory covering CVE-2023-28531; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28425 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0005/

NetApp published this final advisory covering CVE-2023-28425; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28155 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0007/

NetApp published this final advisory covering CVE-2023-28155; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-27320 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0009/

NetApp published this final advisory covering CVE-2023-27320; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-26053 Gradle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0002/

NetApp published this final advisory covering CVE-2023-26053; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-22462 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0004/

NetApp published this final advisory covering CVE-2023-22462; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1118 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0003/

NetApp published this final advisory covering CVE-2023-1118; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0507 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0001/

NetApp published this final advisory covering CVE-2023-0507; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0030 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0010/

NetApp published this final advisory covering CVE-2023-0030; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-48425 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0006/

NetApp published this final advisory covering CVE-2022-48425; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

March 2023 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0007/

NetApp published this final advisory covering CVE-2023-0614, CVE-2023-0922, CVE-2023-0225; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-27567 OpenBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0001/

NetApp published this final advisory covering CVE-2023-27567; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-26242 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0002/

NetApp published this final advisory covering CVE-2023-26242; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0464 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0006/

NetApp published this interim advisory covering CVE-2023-0464; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-3857 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0004/

NetApp published this interim advisory covering CVE-2022-3857; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3424 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0005/

NetApp published this final advisory covering CVE-2022-3424; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-36713 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0003/

NetApp published this final advisory covering CVE-2021-36713; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Virtual Desktop Service (VDS); SnapCenter; Spot PC.

Open source
Advisory

March 2023 Redis Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0002/

NetApp published this interim advisory covering CVE-2023-25155, CVE-2022-36021; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

Februray 2023 Linux Kernel 5.16 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0004/

NetApp published this final advisory covering CVE-2023-22995, CVE-2023-23000; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

February 2023 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0009/

NetApp published this final advisory covering CVE-2022-41724, CVE-2022-41725; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); StorageGRID (formerly StorageGRID Webscale); Trident.

Open source
Advisory

CVE-2023-28708 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0012/

NetApp published this final advisory covering CVE-2023-28708; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24532 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0011/

NetApp published this final advisory covering CVE-2023-24532; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-23003 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0003/

NetApp published this final advisory covering CVE-2023-23003; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0594 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0007/

NetApp published this final advisory covering CVE-2023-0594; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0567 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0008/

NetApp published this final advisory covering CVE-2023-0567; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0461 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0006/

NetApp published this final advisory covering CVE-2023-0461; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-4645 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0001/

NetApp published this final advisory covering CVE-2022-4645; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20251 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0005/

NetApp published this final advisory covering CVE-2021-20251; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24807 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0010/

NetApp published this final advisory covering CVE-2023-24807; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24329 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0004/

NetApp published this final advisory covering CVE-2023-24329; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-23931 Cryptography Project Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0007/

NetApp published this interim advisory covering CVE-2023-23931; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Converged Systems Advisor Agent; NetApp Virtual Desktop Service (VDS); Spot PC.

Open source
Advisory

CVE-2023-0804 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0009/

NetApp published this final advisory covering CVE-2023-0804; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0767 Libnss Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0008/

NetApp published this final advisory covering CVE-2023-0767; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-0361 GNU TLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0005/

NetApp published this final advisory covering CVE-2023-0361; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Converged Systems Advisor Agent; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-48282 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0003/

NetApp published this final advisory covering CVE-2022-48282; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-4492 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0002/

NetApp published this final advisory covering CVE-2022-4492; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-3219 GnuPG Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0001/

NetApp published this interim advisory covering CVE-2022-3219; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-12403 Libnss Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0006/

NetApp published this final advisory covering CVE-2020-12403; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

March 2023 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0003/

NetApp published this final advisory covering CVE-2023-0795, CVE-2023-0796, CVE-2023-0798, CVE-2023-0799; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

February 2023 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0008/

NetApp published this final advisory covering CVE-2023-23918, CVE-2023-23919, CVE-2023-23920; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2023 Linux Kernel 6.0.8 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0010/

NetApp published this final advisory covering CVE-2023-26544, CVE-2023-26606, CVE-2023-26605, CVE-2023-26607; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

February 2023 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0002/

NetApp published this final advisory covering CVE-2023-0800, CVE-2023-0801, CVE-2023-0802, CVE-2023-0803; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-26545 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0009/

NetApp published this final advisory covering CVE-2023-26545; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-24580 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0006/

NetApp published this final advisory covering CVE-2023-24580; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0751 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0004/

NetApp published this final advisory covering CVE-2023-0751; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0240 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0001/

NetApp published this final advisory covering CVE-2023-0240; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-47629 Libksba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0011/

NetApp published this final advisory covering CVE-2022-47629; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2006-20001 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0005/

NetApp published this final advisory covering CVE-2006-20001; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2023 Trusted Platform Module 2.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230314-0001/

NetApp published this final advisory covering CVE-2023-1017, CVE-2023-1018; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2023 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0006/

NetApp published this interim advisory covering CVE-2023-23914, CVE-2023-23915, CVE-2023-23916; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

CVE-2023-25136 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0003/

NetApp published this final advisory covering CVE-2023-25136; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-22474 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0005/

NetApp published this final advisory covering CVE-2023-22474; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-47015 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0009/

NetApp published this final advisory covering CVE-2022-47015; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-4139 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0004/

NetApp published this final advisory covering CVE-2022-4139; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-39324 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0010/

NetApp published this final advisory covering CVE-2022-39324; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-37708 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0008/

NetApp published this final advisory covering CVE-2022-37708; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23498 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0007/

NetApp published this final advisory covering CVE-2022-23498; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-1000802 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0002/

NetApp published this final advisory covering CVE-2018-1000802; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2023 Redis Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0006/

NetApp published this interim advisory covering CVE-2022-35977, CVE-2023-22458; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

January 2023 Linux Kernel 6.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0005/

NetApp published this interim advisory covering CVE-2023-0266, CVE-2023-0394; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

Intel SA-00717 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0011/

NetApp published this interim advisory covering CVE-2022-26343, CVE-2022-30539, CVE-2022-32231, CVE-2022-26837, CVE-2022-30704, CVE-2021-0187; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2023 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0009/

NetApp published this final advisory covering CVE-2022-43927, CVE-2022-43929, CVE-2022-43930; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-25139 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0010/

NetApp published this final advisory covering CVE-2023-25139; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-24998 Apache Commons FileUpload Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0013/

NetApp published this interim advisory covering CVE-2023-24998; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter; Snap Creator Framework.

Open source
Advisory

CVE-2023-23969 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0007/

NetApp published this final advisory covering CVE-2023-23969; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-23559 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0003/

NetApp published this final advisory covering CVE-2023-23559; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-22602 Apache Shiro Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0001/

NetApp published this final advisory covering CVE-2023-22602; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0122 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0002/

NetApp published this final advisory covering CVE-2023-0122; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-48281 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0004/

NetApp published this final advisory covering CVE-2022-48281; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-33972 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0012/

NetApp published this interim advisory covering CVE-2022-33972; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23552 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0008/

NetApp published this interim advisory covering CVE-2022-23552; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2022 Net-SNMP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0011/

NetApp published this interim advisory covering CVE-2022-44792, CVE-2022-44793; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SMI-S Provider.

Open source
Advisory

January 2023 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0009/

NetApp published this final advisory covering CVE-2022-3094, CVE-2022-3488, CVE-2022-3736, CVE-2022-3924; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-4696 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0003/

NetApp published this final advisory covering CVE-2022-4696; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-4379 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0004/

NetApp published this final advisory covering CVE-2022-4379; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-42898 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0001/

NetApp published this final advisory covering CVE-2022-42898; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp E-Series Performance Analyzer; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-41858 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0006/

NetApp published this final advisory covering CVE-2022-41858; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3977 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0005/

NetApp published this final advisory covering CVE-2022-3977; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-31631 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0007/

NetApp published this final advisory covering CVE-2022-31631; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23491 Python-Certifi Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0010/

NetApp published this final advisory covering CVE-2022-23491; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp E-Series Performance Analyzer; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-2196 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0002/

NetApp published this final advisory covering CVE-2022-2196; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2018-14628 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0008/

NetApp published this final advisory covering CVE-2018-14628; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

January 2023 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0007/

NetApp published this final advisory covering CVE-2022-36760, CVE-2022-37436; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2022 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0004/

NetApp published this final advisory covering CVE-2022-41317, CVE-2022-41318; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2022 Heimdal Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0008/

NetApp published this final advisory covering CVE-2022-42898, CVE-2022-3437, CVE-2022-41916, CVE-2021-44758, CVE-2021-3671, CVE-2022-44640, CVE-2019-14870; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp E-Series Performance Analyzer; ONTAP Select Deploy administration utility.

Open source
Advisory

December 2015 PCRE Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0002/

NetApp published this final advisory covering CVE-2015-8391, CVE-2015-8383, CVE-2015-8386, CVE-2015-8387, CVE-2015-8389, CVE-2015-8390, CVE-2015-8393, CVE-2015-8394; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-47943 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0006/

NetApp published this final advisory covering CVE-2022-47943; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2022-45143 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0009/

NetApp published this final advisory covering CVE-2022-45143; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-4415 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0010/

NetApp published this final advisory covering CVE-2022-4415; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-41966 XStream Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0005/

NetApp published this final advisory covering CVE-2022-41966; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3176 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0003/

NetApp published this final advisory covering CVE-2022-3176; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2017-1000158 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0001/

NetApp published this final advisory covering CVE-2017-1000158; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2022 Linux Kernel 5.17 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0006/

NetApp published this final advisory covering CVE-2022-1729, CVE-2022-2977, CVE-2022-3239; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

February 2023 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0011/

NetApp published this interim advisory covering CVE-2023-0286, CVE-2022-4304, CVE-2022-4203, CVE-2023-0215, CVE-2022-4450, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; OnCommand Workflow Automation; SnapManager for Hyper-V; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

December 2022 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0002/

NetApp published this interim advisory covering CVE-2022-43551, CVE-2022-43552; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

CVE-2022-41222 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0008/

NetApp published this final advisory covering CVE-2022-41222; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-40897 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0001/

NetApp published this interim advisory covering CVE-2022-40897; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP Mediator; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-39189 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0007/

NetApp published this final advisory covering CVE-2022-39189; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3649 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0009/

NetApp published this final advisory covering CVE-2022-3649; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-35065 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0010/

NetApp published this final advisory covering CVE-2021-35065; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2022 Linux Kernel 5.19 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0004/

NetApp published this final advisory covering CVE-2022-2961, CVE-2022-3028, CVE-2022-2590; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

August 2022 Linux Kernel 5.18 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0005/

NetApp published this final advisory covering CVE-2022-1976, CVE-2022-2503, CVE-2022-2959; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

August 2022 Linux Kernel 5.17 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0003/

NetApp published this final advisory covering CVE-2022-1205, CVE-2022-1158; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

January 2023 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230208-0002/

NetApp published this final advisory covering CVE-2022-32221, CVE-2023-21836, CVE-2023-21840, CVE-2023-21860, CVE-2023-21863, CVE-2023-21864, CVE-2023-21865, CVE-2023-21866, CVE-2023-21867, CVE-2023-21868, CVE-2023-21869, CVE-2023-21870, CVE-2023-21871, CVE-2023-21872, CVE-2023-21873, CVE-2023-21874, CVE-2023-21875, CVE-2023-21876, CVE-2023-21877, CVE-2023-21878, CVE-2023-21879, CVE-2023-21880, CVE-2023-21881, CVE-2023-21882, CVE-2023-21883, CVE-2023-21887; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2023 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230208-0001/

NetApp published this interim advisory covering CVE-2023-21830, CVE-2023-21835, CVE-2023-21843; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav).

Open source
Advisory

October 2022 Linux Kernel 5.19.15 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0008/

NetApp published this final advisory covering CVE-2022-42719, CVE-2022-42720, CVE-2022-42721, CVE-2022-42722; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2022-46908 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0005/

NetApp published this final advisory covering CVE-2022-46908; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-4293 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0007/

NetApp published this interim advisory covering CVE-2022-4293; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3996 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0003/

NetApp published this final advisory covering CVE-2022-3996; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SMI-S Provider; ONTAP 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-37454 Keccak XKCP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0001/

NetApp published this interim advisory covering CVE-2022-37454; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-3570 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0002/

NetApp published this final advisory covering CVE-2022-3570; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32149 Golang Text Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0006/

NetApp published this final advisory covering CVE-2022-32149; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2601 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0004/

NetApp published this final advisory covering CVE-2022-2601; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2327 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0009/

NetApp published this final advisory covering CVE-2022-2327; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

December 2022 X.Org X Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230127-0011/

NetApp published this final advisory covering CVE-2022-4283, CVE-2022-46340, CVE-2022-46341, CVE-2022-46342, CVE-2022-46343, CVE-2022-46344; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22809 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230127-0015/

NetApp published this final advisory covering CVE-2023-22809; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-4172 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230127-0013/

NetApp published this final advisory covering CVE-2022-4172; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-4144 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230127-0012/

NetApp published this final advisory covering CVE-2022-4144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-33185 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0010/

NetApp published this final advisory covering CVE-2022-33185; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33184 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0009/

NetApp published this final advisory covering CVE-2022-33184; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33183 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0008/

NetApp published this final advisory covering CVE-2022-33183; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33182 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0007/

NetApp published this final advisory covering CVE-2022-33182; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33181 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0006/

NetApp published this final advisory covering CVE-2022-33181; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33180 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0005/

NetApp published this final advisory covering CVE-2022-33180; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33179 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0004/

NetApp published this final advisory covering CVE-2022-33179; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33178 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0003/

NetApp published this final advisory covering CVE-2022-33178; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-28170 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0002/

NetApp published this final advisory covering CVE-2022-28170; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-28169 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0001/

NetApp published this final advisory covering CVE-2022-28169; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

April 2022 OWASP Enterprise Security API Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230127-0014/

NetApp published this interim advisory covering CVE-2022-23457, CVE-2022-24891; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

October 2022 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0005/

NetApp published this final advisory covering CVE-2022-41741, CVE-2022-41742; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

October 2022 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0006/

NetApp published this final advisory covering CVE-2022-2879, CVE-2022-2880, CVE-2022-41715; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent.

Open source
Advisory

Linux Kernel 5.18 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0001/

NetApp published this final advisory covering CVE-2022-2318, CVE-2022-1973, CVE-2022-2873; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

December 2022 JsonWebToken Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0009/

NetApp published this final advisory covering CVE-2022-23529, CVE-2022-23539, CVE-2022-23540, CVE-2022-23541; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2022 Apache CXF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0002/

NetApp published this final advisory covering CVE-2022-46363, CVE-2022-46364; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

CVE-2022-43548 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0004/

NetApp published this final advisory covering CVE-2022-43548; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-41717 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0008/

NetApp published this final advisory covering CVE-2022-41717; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Astra Trident; NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2022-41296 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0003/

NetApp published this final advisory covering CVE-2022-41296; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2022 Linux Kernel 6.0.9 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0006/

NetApp published this final advisory covering CVE-2022-45884, CVE-2022-45885, CVE-2022-45886, CVE-2022-45887, CVE-2022-45888; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

November 2022 Linux Kernel 6.0.10 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0008/

NetApp published this final advisory covering CVE-2022-45919, CVE-2022-45934; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

December 2022 Linux Kernel 6.0.11 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0007/

NetApp published this final advisory covering CVE-2022-47518, CVE-2022-47519, CVE-2022-47520, CVE-2022-47521; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

December 2022 Apache Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0004/

NetApp published this final advisory covering CVE-2022-41881, CVE-2022-41915; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights and Data Secure Storage Workload Security Agent; E-Series SANtricity Unified Manager and Web Services Proxy; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter; SnapCenter.

Open source
Advisory

CVE-2022-4292 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0005/

NetApp published this final advisory covering CVE-2022-4292; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-35255 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0002/

NetApp published this final advisory covering CVE-2022-35255; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2964 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0001/

NetApp published this final advisory covering CVE-2022-2964; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

October 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0001/

NetApp published this final advisory covering CVE-2022-3626, CVE-2022-3627, CVE-2022-3597, CVE-2022-3598, CVE-2022-3599; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

Linux Kernel through 5.19.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0004/

NetApp published this final advisory covering CVE-2022-47939, CVE-2022-47938, CVE-2022-47941; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

Linux Kernel prior to 5.19.2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0005/

NetApp published this final advisory covering CVE-2022-47940, CVE-2022-47942; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

December 2022 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0006/

NetApp published this interim advisory covering CVE-2022-32221, CVE-2022-35260; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

December 2022 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0003/

NetApp published this final advisory covering CVE-2022-38023, CVE-2022-37966, CVE-2022-37967, CVE-2022-45141; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2021-22600 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0002/

NetApp published this final advisory covering CVE-2021-22600; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source