Content Library · Advisory

Advisory 2024

Browse 532 2024 NetApp advisory records in the NetApp Black Box content library. Page 2 of 5.

Library JSON API

Showing all 120 items on this page

Advisory

CVE-2024-8088 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0010/

NetApp published this interim advisory covering CVE-2024-8088; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-7885 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0004/

NetApp published this interim advisory covering CVE-2024-7885; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-47850 CUPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0002/

NetApp published this final advisory covering CVE-2024-47850; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-47561 Apache Avro Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0003/

NetApp published this final advisory covering CVE-2024-47561; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2024-41909 Apache MINA SSHD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0006/

NetApp published this interim advisory covering CVE-2024-41909; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-27282 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0007/

NetApp published this final advisory covering CVE-2024-27282; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-6383 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0001/

NetApp published this interim advisory covering CVE-2024-6383; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45306 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0007/

NetApp published this interim advisory covering CVE-2024-45306; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-43802 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0008/

NetApp published this interim advisory covering CVE-2024-43802; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36946 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0002/

NetApp published this final advisory covering CVE-2024-36946; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-34158 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0003/

NetApp published this interim advisory covering CVE-2024-34158; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24791 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0004/

NetApp published this interim advisory covering CVE-2024-24791; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Provisioner; Trident; Trident Autosupport.

Open source
Advisory

CVE-2023-39333 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0006/

NetApp published this final advisory covering CVE-2023-39333; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2024 Node.js Elliptic Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0005/

NetApp published this final advisory covering CVE-2024-42459, CVE-2024-42460, CVE-2024-42461; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6923 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0003/

NetApp published this interim advisory covering CVE-2024-6923; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2024-45409 Ruby SAML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0008/

NetApp published this final advisory covering CVE-2024-45409; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2024-41721 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0009/

NetApp published this final advisory covering CVE-2024-41721; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-36902 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0002/

NetApp published this interim advisory covering CVE-2024-36902; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-34156 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0004/

NetApp published this final advisory covering CVE-2024-34156; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2024-34155 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0005/

NetApp published this interim advisory covering CVE-2024-34155; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2024-27399 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0001/

NetApp published this interim advisory covering CVE-2024-27399; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-30583 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0006/

NetApp published this final advisory covering CVE-2023-30583; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-30582 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0007/

NetApp published this final advisory covering CVE-2023-30582; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2024 FreeBSD ctl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0010/

NetApp published this final advisory covering CVE-2024-45063, CVE-2024-8178, CVE-2024-42416, CVE-2024-43110; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-8235 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0006/

NetApp published this interim advisory covering CVE-2024-8235; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-7006 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0001/

NetApp published this final advisory covering CVE-2024-7006; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-43790 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0005/

NetApp published this interim advisory covering CVE-2024-43790; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-43374 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0004/

NetApp published this interim advisory covering CVE-2024-43374; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-41928 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0009/

NetApp published this final advisory covering CVE-2024-41928; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-38809 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0003/

NetApp published this interim advisory covering CVE-2024-38809; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-38808 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0002/

NetApp published this interim advisory covering CVE-2024-38808; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-32668 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0007/

NetApp published this final advisory covering CVE-2024-32668; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-43102 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240916-0001/

NetApp published this final advisory covering CVE-2024-43102; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2024 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0005/

NetApp published this final advisory covering CVE-2024-28762, CVE-2024-31880, CVE-2024-31881; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00923 CSME Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0004/

NetApp published this interim advisory covering CVE-2023-28389, CVE-2023-32633; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2024-6119 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0001/

NetApp published this interim advisory covering CVE-2024-6119; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-36934 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0007/

NetApp published this interim advisory covering CVE-2024-36934; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36933 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0006/

NetApp published this interim advisory covering CVE-2024-36933; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9; SnapCenter Plug-in for VMware vSphere/BlueXP Backup and Recovery for Virtual Machine.

Open source
Advisory

CVE-2024-27398 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0012/

NetApp published this final advisory covering CVE-2024-27398; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-26900 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0011/

NetApp published this interim advisory covering CVE-2024-26900; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-52882 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0010/

NetApp published this interim advisory covering CVE-2023-52882; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-52585 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0009/

NetApp published this interim advisory covering CVE-2023-52585; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-37920 Certifi Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0002/

NetApp published this interim advisory covering CVE-2023-37920; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Mediator; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-48655 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0008/

NetApp published this final advisory covering CVE-2022-48655; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2024 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0003/

NetApp published this final advisory covering CVE-2024-37529, CVE-2024-35136, CVE-2024-35152, CVE-2024-31882; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-39684 RapidJSON Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0003/

NetApp published this final advisory covering CVE-2024-39684; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-38517 RapidJSON Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0001/

NetApp published this final advisory covering CVE-2024-38517; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2024-36929 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0010/

NetApp published this interim advisory covering CVE-2024-36929; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; SnapCenter Plug-in for VMware vSphere/BlueXP Backup and Recovery for Virtual Machine.

Open source
Advisory

CVE-2024-36919 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0009/

NetApp published this interim advisory covering CVE-2024-36919; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36916 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0006/

NetApp published this interim advisory covering CVE-2024-36916; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36905 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0005/

NetApp published this interim advisory covering CVE-2024-36905; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; SnapCenter Plug-in for VMware vSphere/BlueXP Backup and Recovery for Virtual Machine.

Open source
Advisory

CVE-2024-36904 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0004/

NetApp published this interim advisory covering CVE-2024-36904; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2024 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0007/

NetApp published this final advisory covering CVE-2024-41989, CVE-2024-41990, CVE-2024-41991, CVE-2024-42005; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2024 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0008/

NetApp published this final advisory covering CVE-2024-30260, CVE-2024-30261; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-7264 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0008/

NetApp published this interim advisory covering CVE-2024-7264; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-4693 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0007/

NetApp published this final advisory covering CVE-2024-4693; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-42154 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0010/

NetApp published this interim advisory covering CVE-2024-42154; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-38372 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0009/

NetApp published this final advisory covering CVE-2024-38372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-52433 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0003/

NetApp published this final advisory covering CVE-2023-52433; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-45744 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0006/

NetApp published this final advisory covering CVE-2023-45744; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-43491 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0005/

NetApp published this final advisory covering CVE-2023-43491; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29267 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0004/

NetApp published this final advisory covering CVE-2023-29267; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-7348 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0002/

NetApp published this final advisory covering CVE-2024-7348; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6874 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0004/

NetApp published this final advisory covering CVE-2024-6874; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-4467 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0005/

NetApp published this final advisory covering CVE-2024-4467; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-37891 urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0003/

NetApp published this interim advisory covering CVE-2024-37891; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-3596 RADIUS Protocol Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0001/

NetApp published this final advisory covering CVE-2024-3596; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2024-3567 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0007/

NetApp published this final advisory covering CVE-2024-3567; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-31870 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0006/

NetApp published this final advisory covering CVE-2024-31870; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-40146 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0008/

NetApp published this final advisory covering CVE-2023-40146; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-7589 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0002/

NetApp published this final advisory covering CVE-2024-7589; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6760 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0010/

NetApp published this final advisory covering CVE-2024-6760; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6759 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0009/

NetApp published this final advisory covering CVE-2024-6759; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6640 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0008/

NetApp published this final advisory covering CVE-2024-6640; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6505 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0006/

NetApp published this final advisory covering CVE-2024-6505; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-37280 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0003/

NetApp published this interim advisory covering CVE-2024-37280; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-34750 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0004/

NetApp published this interim advisory covering CVE-2024-34750; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-22018 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0007/

NetApp published this final advisory covering CVE-2024-22018; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-52340 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0005/

NetApp published this interim advisory covering CVE-2023-52340; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2020-15999 Freetype Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240812-0001/

NetApp published this final advisory covering CVE-2020-15999; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

July 2024 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0005/

NetApp published this final advisory covering CVE-2024-38875, CVE-2024-39329, CVE-2024-39330, CVE-2024-39614; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6716 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0010/

NetApp published this final advisory covering CVE-2024-6716; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-40898 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0006/

NetApp published this interim advisory covering CVE-2024-40898; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-32007 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0009/

NetApp published this interim advisory covering CVE-2024-32007; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 10; OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

CVE-2024-0684 GNU Coreutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0001/

NetApp published this interim advisory covering CVE-2024-0684; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-39333 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0004/

NetApp published this final advisory covering CVE-2023-39333; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23358 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0003/

NetApp published this final advisory covering CVE-2021-23358; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-41110 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240802-0001/

NetApp published this final advisory covering CVE-2024-41110; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2024 MySQL Server 8.0.37 and 8.4.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240801-0001/

NetApp published this interim advisory covering CVE-2024-20996, CVE-2024-21125, CVE-2024-21127, CVE-2024-21129, CVE-2024-21130, CVE-2024-21134, CVE-2024-21142, CVE-2024-21162, CVE-2024-21163, CVE-2024-21171, CVE-2024-21173, CVE-2024-21177, CVE-2024-21179; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2024 MySQL Server 8.0.36 and 8.3.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240801-0002/

NetApp published this interim advisory covering CVE-2024-21135, CVE-2024-21159, CVE-2024-21160, CVE-2024-21166; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-4076 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0001/

NetApp published this interim advisory covering CVE-2024-4076; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-21176 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0006/

NetApp published this interim advisory covering CVE-2024-21176; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-21165 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0007/

NetApp published this interim advisory covering CVE-2024-21165; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2024-21157 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0008/

NetApp published this interim advisory covering CVE-2024-21157; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-21137 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0009/

NetApp published this interim advisory covering CVE-2024-21137; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-1975 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0002/

NetApp published this interim advisory covering CVE-2024-1975; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-1737 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0003/

NetApp published this interim advisory covering CVE-2024-1737; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-0760 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0004/

NetApp published this final advisory covering CVE-2024-0760; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-5642 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240726-0005/

NetApp published this interim advisory covering CVE-2024-5642; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-5585 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240726-0002/

NetApp published this final advisory covering CVE-2024-5585; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-4032 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240726-0004/

NetApp published this interim advisory covering CVE-2024-4032; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

July 2024 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0008/

NetApp published this interim advisory covering CVE-2024-21131, CVE-2024-21138, CVE-2024-21140, CVE-2024-21145, CVE-2024-21147; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-37894 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0001/

NetApp published this final advisory covering CVE-2024-37894; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21144 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0007/

NetApp published this interim advisory covering CVE-2024-21144; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); OnCommand Workflow Automation.

Open source
Advisory

CVE-2019-17626 ReportLab Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0006/

NetApp published this final advisory covering CVE-2019-17626; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source