Content Library · Advisory

Advisory 2023

Browse 560 2023 NetApp advisory records in the NetApp Black Box content library. Page 5 of 5.

Library JSON API

Showing all 80 items on this page

Advisory

January 2023 ISC BIND Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0009/

NetApp published this final advisory covering CVE-2022-3094, CVE-2022-3488, CVE-2022-3736, CVE-2022-3924; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-4696 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0003/

NetApp published this final advisory covering CVE-2022-4696; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-4379 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0004/

NetApp published this final advisory covering CVE-2022-4379; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-42898 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0001/

NetApp published this final advisory covering CVE-2022-42898; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp E-Series Performance Analyzer; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-41858 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0006/

NetApp published this final advisory covering CVE-2022-41858; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3977 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0005/

NetApp published this final advisory covering CVE-2022-3977; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-31631 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0007/

NetApp published this final advisory covering CVE-2022-31631; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23491 Python-Certifi Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0010/

NetApp published this final advisory covering CVE-2022-23491; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp E-Series Performance Analyzer; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-2196 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0002/

NetApp published this final advisory covering CVE-2022-2196; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2018-14628 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0008/

NetApp published this final advisory covering CVE-2018-14628; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

January 2023 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0007/

NetApp published this final advisory covering CVE-2022-36760, CVE-2022-37436; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2022 Squid Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0004/

NetApp published this final advisory covering CVE-2022-41317, CVE-2022-41318; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2022 Heimdal Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0008/

NetApp published this final advisory covering CVE-2022-42898, CVE-2022-3437, CVE-2022-41916, CVE-2021-44758, CVE-2021-3671, CVE-2022-44640, CVE-2019-14870; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp E-Series Performance Analyzer; ONTAP Select Deploy administration utility.

Open source
Advisory

December 2015 PCRE Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0002/

NetApp published this final advisory covering CVE-2015-8391, CVE-2015-8383, CVE-2015-8386, CVE-2015-8387, CVE-2015-8389, CVE-2015-8390, CVE-2015-8393, CVE-2015-8394; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-47943 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0006/

NetApp published this final advisory covering CVE-2022-47943; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2022-45143 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0009/

NetApp published this final advisory covering CVE-2022-45143; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-4415 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0010/

NetApp published this final advisory covering CVE-2022-4415; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-41966 XStream Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0005/

NetApp published this final advisory covering CVE-2022-41966; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3176 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0003/

NetApp published this final advisory covering CVE-2022-3176; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2017-1000158 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230216-0001/

NetApp published this final advisory covering CVE-2017-1000158; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2022 Linux Kernel 5.17 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0006/

NetApp published this final advisory covering CVE-2022-1729, CVE-2022-2977, CVE-2022-3239; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

February 2023 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0011/

NetApp published this interim advisory covering CVE-2023-0286, CVE-2022-4304, CVE-2022-4203, CVE-2023-0215, CVE-2022-4450, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; OnCommand Workflow Automation; SnapManager for Hyper-V; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

December 2022 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0002/

NetApp published this interim advisory covering CVE-2022-43551, CVE-2022-43552; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

CVE-2022-41222 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0008/

NetApp published this final advisory covering CVE-2022-41222; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-40897 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0001/

NetApp published this interim advisory covering CVE-2022-40897; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP Mediator; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-39189 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0007/

NetApp published this final advisory covering CVE-2022-39189; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3649 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0009/

NetApp published this final advisory covering CVE-2022-3649; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2021-35065 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0010/

NetApp published this final advisory covering CVE-2021-35065; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2022 Linux Kernel 5.19 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0004/

NetApp published this final advisory covering CVE-2022-2961, CVE-2022-3028, CVE-2022-2590; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

August 2022 Linux Kernel 5.18 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0005/

NetApp published this final advisory covering CVE-2022-1976, CVE-2022-2503, CVE-2022-2959; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

August 2022 Linux Kernel 5.17 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230214-0003/

NetApp published this final advisory covering CVE-2022-1205, CVE-2022-1158; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

January 2023 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230208-0002/

NetApp published this final advisory covering CVE-2022-32221, CVE-2023-21836, CVE-2023-21840, CVE-2023-21860, CVE-2023-21863, CVE-2023-21864, CVE-2023-21865, CVE-2023-21866, CVE-2023-21867, CVE-2023-21868, CVE-2023-21869, CVE-2023-21870, CVE-2023-21871, CVE-2023-21872, CVE-2023-21873, CVE-2023-21874, CVE-2023-21875, CVE-2023-21876, CVE-2023-21877, CVE-2023-21878, CVE-2023-21879, CVE-2023-21880, CVE-2023-21881, CVE-2023-21882, CVE-2023-21883, CVE-2023-21887; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2023 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230208-0001/

NetApp published this interim advisory covering CVE-2023-21830, CVE-2023-21835, CVE-2023-21843; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav).

Open source
Advisory

October 2022 Linux Kernel 5.19.15 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0008/

NetApp published this final advisory covering CVE-2022-42719, CVE-2022-42720, CVE-2022-42721, CVE-2022-42722; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

CVE-2022-46908 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0005/

NetApp published this final advisory covering CVE-2022-46908; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-4293 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0007/

NetApp published this interim advisory covering CVE-2022-4293; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3996 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0003/

NetApp published this final advisory covering CVE-2022-3996; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SMI-S Provider; ONTAP 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-37454 Keccak XKCP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0001/

NetApp published this interim advisory covering CVE-2022-37454; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-3570 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0002/

NetApp published this final advisory covering CVE-2022-3570; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32149 Golang Text Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0006/

NetApp published this final advisory covering CVE-2022-32149; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2601 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0004/

NetApp published this final advisory covering CVE-2022-2601; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2327 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230203-0009/

NetApp published this final advisory covering CVE-2022-2327; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

December 2022 X.Org X Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230127-0011/

NetApp published this final advisory covering CVE-2022-4283, CVE-2022-46340, CVE-2022-46341, CVE-2022-46342, CVE-2022-46343, CVE-2022-46344; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22809 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230127-0015/

NetApp published this final advisory covering CVE-2023-22809; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-4172 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230127-0013/

NetApp published this final advisory covering CVE-2022-4172; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-4144 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230127-0012/

NetApp published this final advisory covering CVE-2022-4144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-33185 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0010/

NetApp published this final advisory covering CVE-2022-33185; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33184 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0009/

NetApp published this final advisory covering CVE-2022-33184; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33183 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0008/

NetApp published this final advisory covering CVE-2022-33183; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33182 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0007/

NetApp published this final advisory covering CVE-2022-33182; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33181 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0006/

NetApp published this final advisory covering CVE-2022-33181; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33180 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0005/

NetApp published this final advisory covering CVE-2022-33180; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33179 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0004/

NetApp published this final advisory covering CVE-2022-33179; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-33178 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0003/

NetApp published this final advisory covering CVE-2022-33178; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-28170 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0002/

NetApp published this final advisory covering CVE-2022-28170; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2022-28169 Brocade Fabric OS Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20230127-0001/

NetApp published this final advisory covering CVE-2022-28169; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

April 2022 OWASP Enterprise Security API Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230127-0014/

NetApp published this interim advisory covering CVE-2022-23457, CVE-2022-24891; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

October 2022 NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0005/

NetApp published this final advisory covering CVE-2022-41741, CVE-2022-41742; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

October 2022 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0006/

NetApp published this final advisory covering CVE-2022-2879, CVE-2022-2880, CVE-2022-41715; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent.

Open source
Advisory

Linux Kernel 5.18 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0001/

NetApp published this final advisory covering CVE-2022-2318, CVE-2022-1973, CVE-2022-2873; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

December 2022 JsonWebToken Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0009/

NetApp published this final advisory covering CVE-2022-23529, CVE-2022-23539, CVE-2022-23540, CVE-2022-23541; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2022 Apache CXF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0002/

NetApp published this final advisory covering CVE-2022-46363, CVE-2022-46364; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

CVE-2022-43548 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0004/

NetApp published this final advisory covering CVE-2022-43548; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-41717 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0008/

NetApp published this final advisory covering CVE-2022-41717; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Astra Trident; NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2022-41296 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230120-0003/

NetApp published this final advisory covering CVE-2022-41296; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2022 Linux Kernel 6.0.9 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0006/

NetApp published this final advisory covering CVE-2022-45884, CVE-2022-45885, CVE-2022-45886, CVE-2022-45887, CVE-2022-45888; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

November 2022 Linux Kernel 6.0.10 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0008/

NetApp published this final advisory covering CVE-2022-45919, CVE-2022-45934; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

December 2022 Linux Kernel 6.0.11 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0007/

NetApp published this final advisory covering CVE-2022-47518, CVE-2022-47519, CVE-2022-47520, CVE-2022-47521; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

December 2022 Apache Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0004/

NetApp published this final advisory covering CVE-2022-41881, CVE-2022-41915; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights and Data Secure Storage Workload Security Agent; E-Series SANtricity Unified Manager and Web Services Proxy; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter; SnapCenter.

Open source
Advisory

CVE-2022-4292 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0005/

NetApp published this final advisory covering CVE-2022-4292; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-35255 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0002/

NetApp published this final advisory covering CVE-2022-35255; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-2964 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230113-0001/

NetApp published this final advisory covering CVE-2022-2964; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

October 2022 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0001/

NetApp published this final advisory covering CVE-2022-3626, CVE-2022-3627, CVE-2022-3597, CVE-2022-3598, CVE-2022-3599; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

Linux Kernel through 5.19.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0004/

NetApp published this final advisory covering CVE-2022-47939, CVE-2022-47938, CVE-2022-47941; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

Linux Kernel prior to 5.19.2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0005/

NetApp published this final advisory covering CVE-2022-47940, CVE-2022-47942; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.

Open source
Advisory

December 2022 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0006/

NetApp published this interim advisory covering CVE-2022-32221, CVE-2022-35260; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

December 2022 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0003/

NetApp published this final advisory covering CVE-2022-38023, CVE-2022-37966, CVE-2022-37967, CVE-2022-45141; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2021-22600 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230110-0002/

NetApp published this final advisory covering CVE-2021-22600; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source