Content Library · Advisory

Advisory 2023

Browse 560 2023 NetApp advisory records in the NetApp Black Box content library. Page 2 of 5.

Library JSON API

Showing all 120 items on this page

Advisory

CVE-2023-40283 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0007/

NetApp published this final advisory covering CVE-2023-40283; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-39323 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0001/

NetApp published this final advisory covering CVE-2023-39323; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1260 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0010/

NetApp published this final advisory covering CVE-2023-1260; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1108 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231020-0002/

NetApp published this final advisory covering CVE-2023-1108; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-44487 HTTP/2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231016-0001/

NetApp published this final advisory covering CVE-2023-44487; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; OnCommand Insight; Trident; Trident Autosupport.

Open source
Advisory

CVE-2023-4911 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231013-0006/

NetApp published this interim advisory covering CVE-2023-4911; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-4236 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231013-0004/

NetApp published this final advisory covering CVE-2023-4236; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-41835 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231013-0001/

NetApp published this final advisory covering CVE-2023-41835; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38039 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231013-0005/

NetApp published this final advisory covering CVE-2023-38039; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; ONTAP 9; ONTAP Antivirus Connector.

Open source
Advisory

CVE-2023-3341 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231013-0003/

NetApp published this final advisory covering CVE-2023-3341; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

October 2023 curl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231011-0001/

NetApp published this interim advisory covering CVE-2023-38545, CVE-2023-38546; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-41105 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0015/

NetApp published this interim advisory covering CVE-2023-41105; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-40217 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0014/

NetApp published this interim advisory covering CVE-2023-40217; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-32559 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0006/

NetApp published this final advisory covering CVE-2023-32559; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-48566 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0013/

NetApp published this interim advisory covering CVE-2022-48566; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; NetApp Converged Systems Advisor Agent; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-48565 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0007/

NetApp published this interim advisory covering CVE-2022-48565; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); NetApp XCP NFS; NetApp XCP SMB.

Open source
Advisory

CVE-2022-45703 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0003/

NetApp published this final advisory covering CVE-2022-45703; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

CVE-2022-36648 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0004/

NetApp published this final advisory covering CVE-2022-36648; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-35205 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0010/

NetApp published this final advisory covering CVE-2022-35205; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

CVE-2021-32050 MongoDB Drivers Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0001/

NetApp published this final advisory covering CVE-2021-32050; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-35342 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0009/

NetApp published this final advisory covering CVE-2020-35342; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

CVE-2020-24165 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0012/

NetApp published this final advisory covering CVE-2020-24165; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-22218 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0002/

NetApp published this interim advisory covering CVE-2020-22218; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

August 2023 GNU Ncurses Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0005/

NetApp published this final advisory covering CVE-2020-19190, CVE-2020-19189, CVE-2020-19188, CVE-2020-19187, CVE-2020-19186, CVE-2020-19185; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2023 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20231006-0008/

NetApp published this final advisory covering CVE-2022-48063, CVE-2022-48064, CVE-2022-48065; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

CVE-2023-4863 Libwebp Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0011/

NetApp published this final advisory covering CVE-2023-4863; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-3212 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0005/

NetApp published this final advisory covering CVE-2023-3212; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-2898 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0002/

NetApp published this final advisory covering CVE-2023-2898; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-2269 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0004/

NetApp published this final advisory covering CVE-2023-2269; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1206 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0006/

NetApp published this interim advisory covering CVE-2023-1206; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-48564 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0009/

NetApp published this interim advisory covering CVE-2022-48564; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-48560 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0008/

NetApp published this final advisory covering CVE-2022-48560; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-4269 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0001/

NetApp published this final advisory covering CVE-2022-4269; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-32292 JSON-C Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0010/

NetApp published this final advisory covering CVE-2021-32292; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2020-21490 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0007/

NetApp published this final advisory covering CVE-2020-21490; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility; SRA Plugin for Linux.

Open source
Advisory

April 2023 Linux Kernel 6.2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230929-0003/

NetApp published this final advisory covering CVE-2023-31081, CVE-2023-31082, CVE-2023-31083, CVE-2023-31084, CVE-2023-31085; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-4807 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230921-0001/

NetApp published this interim advisory covering CVE-2023-4807; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-41080 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230921-0006/

NetApp published this interim advisory covering CVE-2023-41080; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-1409 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230921-0007/

NetApp published this final advisory covering CVE-2023-1409; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-35637 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230921-0003/

NetApp published this final advisory covering CVE-2022-35637; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-22483 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230921-0004/

NetApp published this final advisory covering CVE-2022-22483; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 Linux Kernel 6.3.9 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0011/

NetApp published this final advisory covering CVE-2023-32258, CVE-2023-32257, CVE-2023-32247; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4135 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0012/

NetApp published this final advisory covering CVE-2023-4135; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-40360 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0004/

NetApp published this final advisory covering CVE-2023-40360; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-39975 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0014/

NetApp published this final advisory covering CVE-2023-39975; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38426 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0010/

NetApp published this interim advisory covering CVE-2023-38426; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2023-32248 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0006/

NetApp published this final advisory covering CVE-2023-32248; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-25775 Intel Ethernet Controller Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0013/

NetApp published this final advisory covering CVE-2023-25775; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22276 Intel Ethernet Controller Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0007/

NetApp published this final advisory covering CVE-2023-22276; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-48522 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0008/

NetApp published this interim advisory covering CVE-2022-48522; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); OnCommand Workflow Automation; SRA Plugin for Linux.

Open source
Advisory

CVE-2022-41804 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0003/

NetApp published this interim advisory covering CVE-2022-41804; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2021-3236 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0001/

NetApp published this interim advisory covering CVE-2021-3236; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2023 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0002/

NetApp published this final advisory covering CVE-2023-39417, CVE-2023-39418; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2023 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230915-0009/

NetApp published this final advisory covering CVE-2023-32002, CVE-2023-32003, CVE-2023-32004, CVE-2023-32006; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3611 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0002/

NetApp published this final advisory covering CVE-2023-3611; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-36054 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0004/

NetApp published this interim advisory covering CVE-2023-36054; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP 9; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-3269 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0001/

NetApp published this final advisory covering CVE-2023-3269; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-1255 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0006/

NetApp published this interim advisory covering CVE-2023-1255; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-24999 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0005/

NetApp published this final advisory covering CVE-2022-24999; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-24963 Apache Portable Runtime (APR) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230908-0008/

NetApp published this final advisory covering CVE-2022-24963; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9.

Open source
Advisory

August 2023 Brocade Fabric OS Vulnerabilities

Source: https://security.netapp.com/advisory/NTAP-20230908-0007/

NetApp published this final advisory covering CVE-2023-31425, CVE-2023-31426, CVE-2023-31427, CVE-2023-31428, CVE-2023-31429, CVE-2023-31430, CVE-2023-31431, CVE-2023-31432, CVE-2023-31926, CVE-2023-31927, CVE-2023-31928; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

July 2023 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0005/

NetApp published this final advisory covering CVE-2023-1386, CVE-2023-3019; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0007/

NetApp published this final advisory covering CVE-2023-37903, CVE-2023-37466; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-4009 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0013/

NetApp published this final advisory covering CVE-2023-4009; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3896 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0012/

NetApp published this final advisory covering CVE-2023-3896; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-38633 GNOME Librsvg Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0011/

NetApp published this final advisory covering CVE-2023-38633; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38432 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0002/

NetApp published this final advisory covering CVE-2023-38432; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-38430 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0003/

NetApp published this final advisory covering CVE-2023-38430; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-38428 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0001/

NetApp published this final advisory covering CVE-2023-38428; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3494 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0006/

NetApp published this final advisory covering CVE-2023-3494; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3180 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0008/

NetApp published this final advisory covering CVE-2023-3180; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29409 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0010/

NetApp published this final advisory covering CVE-2023-29409; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); Trident.

Open source
Advisory

CVE-2023-26045 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0004/

NetApp published this final advisory covering CVE-2023-26045; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2023 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230831-0009/

NetApp published this final advisory covering CVE-2023-29407, CVE-2023-29408; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 Grub Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230825-0002/

NetApp published this final advisory covering CVE-2022-28733, CVE-2022-28734, CVE-2022-28735, CVE-2022-28736; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2023 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230825-0001/

NetApp published this final advisory covering CVE-2023-3823, CVE-2023-3824; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 Linux Kernel 6.4 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0004/

NetApp published this final advisory covering CVE-2023-32250, CVE-2023-32254; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

July 2023 Linux Kernel 6.3.7 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0011/

NetApp published this final advisory covering CVE-2023-38427, CVE-2023-38431; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

Intel SA-00813 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0001/

NetApp published this interim advisory covering CVE-2022-27879, CVE-2022-37343, CVE-2022-38083, CVE-2022-43505, CVE-2022-44611; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00783 CSME Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0002/

NetApp published this interim advisory covering CVE-2022-36392, CVE-2022-29871, CVE-2022-38102; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38325 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0010/

NetApp published this interim advisory covering CVE-2023-38325; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-3618 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0012/

NetApp published this final advisory covering CVE-2023-3618; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-35001 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0007/

NetApp published this final advisory covering CVE-2023-35001; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3338 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0005/

NetApp published this final advisory covering CVE-2023-3338; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3268 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0006/

NetApp published this final advisory covering CVE-2023-3268; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-23908 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0003/

NetApp published this interim advisory covering CVE-2023-23908; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2022-31693 VMware Tools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0009/

NetApp published this final advisory covering CVE-2022-31693; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-32256 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230824-0013/

NetApp published this interim advisory covering CVE-2021-32256; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); SRA Plugin for Linux.

Open source
Advisory

July 2023 Linux Kernel 6.3 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0005/

NetApp published this final advisory covering CVE-2023-3609, CVE-2023-3610; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

July 2023 JetBrains Kotlin Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0012/

NetApp published this final advisory covering CVE-2019-10101, CVE-2019-10102, CVE-2019-10103; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

February 2023 Werkzeug Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0003/

NetApp published this final advisory covering CVE-2023-23934, CVE-2023-25577; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2023-38403 iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0016/

NetApp published this final advisory covering CVE-2023-38403; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-3817 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0014/

NetApp published this interim advisory covering CVE-2023-3817; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-35012 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0013/

NetApp published this final advisory covering CVE-2023-35012; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3390 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0004/

NetApp published this final advisory covering CVE-2023-3390; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-30861 Flask Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0006/

NetApp published this final advisory covering CVE-2023-30861; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-2976 Guava Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0008/

NetApp published this interim advisory covering CVE-2023-2976; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); NetApp Manageability SDK; OnCommand Insight.

Open source
Advisory

CVE-2023-27558 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0017/

NetApp published this final advisory covering CVE-2023-27558; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23221 H2 Database Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0011/

NetApp published this final advisory covering CVE-2022-23221; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1471 SnakeYAML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0015/

NetApp published this interim advisory covering CVE-2022-1471; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS); Spot PC.

Open source
Advisory

CVE-2021-40690 Apache XML Security for Java Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0002/

NetApp published this final advisory covering CVE-2021-40690; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23463 H2 Database Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0010/

NetApp published this final advisory covering CVE-2021-23463; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-10650 FasterXML jackson-databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0007/

NetApp published this final advisory covering CVE-2020-10650; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2019-12402 Apache Commons Compress Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230818-0001/

NetApp published this final advisory covering CVE-2019-12402; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2023 MegaRAC BMC Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0004/

NetApp published this interim advisory covering CVE-2023-34329, CVE-2023-34330; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

CVE-2023-36824 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0009/

NetApp published this interim advisory covering CVE-2023-36824; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-34034 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230814-0008/

NetApp published this final advisory covering CVE-2023-34034; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source