Content Library · Advisory

Advisory 2024

Browse 532 2024 NetApp advisory records in the NetApp Black Box content library. Page 3 of 5.

Library JSON API

Showing all 120 items on this page

Advisory

CVE-2016-3751 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0004/

NetApp published this final advisory covering CVE-2016-3751; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2015-0973 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0005/

NetApp published this final advisory covering CVE-2015-0973; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2014-9515 Dozer Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0002/

NetApp published this final advisory covering CVE-2014-9515; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2024 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240712-0001/

NetApp published this final advisory covering CVE-2024-36387, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9.

Open source
Advisory

CVE-2024-6409 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240712-0003/

NetApp published this interim advisory covering CVE-2024-6409; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-5535 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240712-0005/

NetApp published this interim advisory covering CVE-2024-5535; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-39894 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240712-0004/

NetApp published this interim advisory covering CVE-2024-39894; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-4030 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240705-0005/

NetApp published this final advisory covering CVE-2024-4030; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-37051 JetBrains IDE Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20240705-0004/

NetApp published this final advisory covering CVE-2024-37051; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-32962 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240705-0003/

NetApp published this final advisory covering CVE-2024-32962; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-27309 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240705-0002/

NetApp published this final advisory covering CVE-2024-27309; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1931 Unbound Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240705-0006/

NetApp published this final advisory covering CVE-2024-1931; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6387 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240701-0001/

NetApp published this interim advisory covering CVE-2024-6387; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-6240 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240628-0002/

NetApp published this interim advisory covering CVE-2023-6240; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-36665 Protobuf.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240628-0006/

NetApp published this final advisory covering CVE-2023-36665; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1227 Podman Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240628-0001/

NetApp published this final advisory covering CVE-2022-1227; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2024 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0007/

NetApp published this final advisory covering CVE-2023-44981, CVE-2023-44487, CVE-2023-5072, CVE-2023-34462, CVE-2024-25047, CVE-2022-23540, CVE-2022-23541, CVE-2022-23539, CVE-2023-31484, CVE-2020-15366, CVE-2021-28363; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

February 2024 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0006/

NetApp published this final advisory covering CVE-2021-31684, CVE-2023-1370, CVE-2023-0464, CVE-2021-35550, CVE-2021-35560, CVE-2021-35586, CVE-2021-35578, CVE-2021-35564, CVE-2021-35559, CVE-2021-35556, CVE-2021-35565, CVE-2021-35588, CVE-2021-41035, CVE-2021-44906, CVE-2021-28167, CVE-2023-38359, CVE-2023-32344, CVE-2022-21299, CVE-2023-30996, CVE-2022-21496, CVE-2022-21434, CVE-2022-21443, CVE-2023-3817, CVE-2023-39410, CVE-2020-28458, CVE-2021-23445, CVE-2023-26136, CVE-2021-3572, CVE-2023-21930, CVE-2023-21967, CVE-2023-21954, CVE-2023-21939, CVE-2023-21968, CVE-2023-21937, CVE-2023-21938, CVE-2023-2597, CVE-2018-8032, CVE-2019-0227, CVE-2022-34357, CVE-2023-30588, CVE-2023-30589, CVE-2019-1547, CVE-2020-1971, CVE-2021-23839, CVE-2021-23840, CVE-2021-23841, CVE-2021-3449, CVE-2021-3711, CVE-2021-3712, CVE-2021-4160, CVE-2022-0778, CVE-2022-2097, CVE-2021-35603, CVE-2023-26115, CVE-2021-43138, CVE-2022-1471, CVE-2023-36478, CVE-2023-44487, CVE-2022-40897, CVE-2022-34169, CVE-2022-41854, CVE-2023-0215, CVE-2023-43051, CVE-2023-22049, CVE-2023-45857; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2024-4741 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0004/

NetApp published this interim advisory covering CVE-2024-4741; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-4603 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0001/

NetApp published this interim advisory covering CVE-2024-4603; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-4577 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0008/

NetApp published this final advisory covering CVE-2024-4577; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3080 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0002/

NetApp published this interim advisory covering CVE-2022-3080; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

May 2024 Bouncy Castle Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0007/

NetApp published this interim advisory covering CVE-2024-34447, CVE-2024-30172; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Console; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2024-34069 Werkzeug Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0004/

NetApp published this final advisory covering CVE-2024-34069; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-30171 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0008/

NetApp published this interim advisory covering CVE-2024-30171; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Console; ONTAP tools for VMware vSphere 9; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-2877 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0002/

NetApp published this interim advisory covering CVE-2024-2877; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22233 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0005/

NetApp published this final advisory covering CVE-2024-22233; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1086 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0009/

NetApp published this final advisory covering CVE-2024-1086; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-52425 libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0003/

NetApp published this interim advisory covering CVE-2023-52425; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; OnCommand Workflow Automation; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2022-4967 strongSwan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0006/

NetApp published this final advisory covering CVE-2022-4967; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-33883 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0003/

NetApp published this final advisory covering CVE-2024-33883; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-32487 less Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0009/

NetApp published this interim advisory covering CVE-2024-32487; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-24806 libuv Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0008/

NetApp published this final advisory covering CVE-2024-24806; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-24788 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0002/

NetApp published this final advisory covering CVE-2024-24788; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Astra Control Provisioner; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator; Trident; Trident Autosupport.

Open source
Advisory

CVE-2023-32067 c-ares Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0004/

NetApp published this interim advisory covering CVE-2023-32067; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-31130 c-ares Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0005/

NetApp published this interim advisory covering CVE-2023-31130; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-23913 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0007/

NetApp published this final advisory covering CVE-2023-23913; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-20569 Debian Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0006/

NetApp published this interim advisory covering CVE-2023-20569; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-48624 less Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0010/

NetApp published this final advisory covering CVE-2022-48624; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-34397 Gnome Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0008/

NetApp published this final advisory covering CVE-2024-34397; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2961 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0002/

NetApp published this interim advisory covering CVE-2024-2961; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-28085 Util-linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0003/

NetApp published this interim advisory covering CVE-2024-28085; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24787 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0006/

NetApp published this final advisory covering CVE-2024-24787; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2379 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0001/

NetApp published this interim advisory covering CVE-2024-2379; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-6237 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0007/

NetApp published this interim advisory covering CVE-2023-6237; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-20593 Debian Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0004/

NetApp published this final advisory covering CVE-2023-20593; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-20588 Debian Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0005/

NetApp published this final advisory covering CVE-2023-20588; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-33602 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0012/

NetApp published this interim advisory covering CVE-2024-33602; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-33601 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0014/

NetApp published this interim advisory covering CVE-2024-33601; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-33600 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0013/

NetApp published this interim advisory covering CVE-2024-33600; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-33599 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0011/

NetApp published this interim advisory covering CVE-2024-33599; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-28863 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0005/

NetApp published this final advisory covering CVE-2024-28863; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-28834 GNU TLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0004/

NetApp published this interim advisory covering CVE-2024-28834; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Converged Systems Advisor Agent; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-2660 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0007/

NetApp published this interim advisory covering CVE-2024-2660; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22262 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0003/

NetApp published this final advisory covering CVE-2024-22262; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-22259 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0002/

NetApp published this final advisory covering CVE-2024-22259; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-22243 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0001/

NetApp published this final advisory covering CVE-2024-22243; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-2048 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0009/

NetApp published this final advisory covering CVE-2024-2048; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2004 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0006/

NetApp published this interim advisory covering CVE-2024-2004; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-1313 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0008/

NetApp published this final advisory covering CVE-2024-1313; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-20863 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0015/

NetApp published this final advisory covering CVE-2023-20863; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2024-28752 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0001/

NetApp published this final advisory covering CVE-2024-28752; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-25046 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0005/

NetApp published this final advisory covering CVE-2024-25046; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-25030 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0006/

NetApp published this final advisory covering CVE-2024-25030; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2494 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0009/

NetApp published this interim advisory covering CVE-2024-2494; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-23450 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0010/

NetApp published this interim advisory covering CVE-2024-23450; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22025 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0008/

NetApp published this final advisory covering CVE-2024-22025; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22017 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0007/

NetApp published this final advisory covering CVE-2024-22017; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2024 IBM DB2 11.5 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0003/

NetApp published this final advisory covering CVE-2024-22360, CVE-2023-52296; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2024 IBM DB2 10.5, 11.1, and 11.5 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0004/

NetApp published this final advisory covering CVE-2023-38729, CVE-2024-27254; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-3096 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0010/

NetApp published this final advisory covering CVE-2024-3096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2757 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0011/

NetApp published this final advisory covering CVE-2024-2757; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26146 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0006/

NetApp published this final advisory covering CVE-2024-26146; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26144 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0013/

NetApp published this final advisory covering CVE-2024-26144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26143 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0004/

NetApp published this final advisory covering CVE-2024-26143; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26141 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0007/

NetApp published this final advisory covering CVE-2024-26141; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-25941 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0003/

NetApp published this final advisory covering CVE-2024-25941; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-25126 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0005/

NetApp published this final advisory covering CVE-2024-25126; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24474 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0012/

NetApp published this final advisory covering CVE-2024-24474; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1874 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0009/

NetApp published this final advisory covering CVE-2024-1874; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26142 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0003/

NetApp published this final advisory covering CVE-2024-26142; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2511 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0013/

NetApp published this interim advisory covering CVE-2024-2511; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-2466 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0010/

NetApp published this final advisory covering CVE-2024-2466; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-2398 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0009/

NetApp published this interim advisory covering CVE-2024-2398; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-21885 X.Org X Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0004/

NetApp published this final advisory covering CVE-2024-21885; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-0853 MySQL Enterprise Backup Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0012/

NetApp published this final advisory covering CVE-2024-0853; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6516 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0008/

NetApp published this final advisory covering CVE-2023-6516; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-6129 MySQL Enterprise Backup Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0011/

NetApp published this final advisory covering CVE-2023-6129; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5680 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0005/

NetApp published this interim advisory covering CVE-2023-5680; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-5517 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0006/

NetApp published this final advisory covering CVE-2023-5517; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-5123 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0007/

NetApp published this final advisory covering CVE-2023-5123; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5122 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0002/

NetApp published this final advisory covering CVE-2023-5122; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3010 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0001/

NetApp published this final advisory covering CVE-2023-3010; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2312 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0003/

NetApp published this final advisory covering CVE-2024-2312; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-21015 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0010/

NetApp published this interim advisory covering CVE-2024-21015; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-0853 MySQL Cluster Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0009/

NetApp published this final advisory covering CVE-2024-0853; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5679 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0002/

NetApp published this interim advisory covering CVE-2023-5679; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-44487 MySQL Cluster Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0007/

NetApp published this final advisory covering CVE-2023-44487; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-4408 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0001/

NetApp published this final advisory covering CVE-2023-4408; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2023-32665 Gnome Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0006/

NetApp published this interim advisory covering CVE-2023-32665; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware.

Open source
Advisory

April 2024 MySQL Server 8.0.36 and 8.3.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0013/

NetApp published this interim advisory covering CVE-2023-6129, CVE-2024-20994, CVE-2024-20998, CVE-2024-21000, CVE-2024-21008, CVE-2024-21009, CVE-2024-21013, CVE-2024-21047, CVE-2024-21054, CVE-2024-21060, CVE-2024-21062, CVE-2024-21069, CVE-2024-21087, CVE-2024-21096, CVE-2024-21102; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2024 MySQL Server 8.0.35 and 8.2.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0014/

NetApp published this interim advisory covering CVE-2024-20993, CVE-2024-21061; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2024 MySQL Server 8.0.35 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0011/

NetApp published this interim advisory covering CVE-2024-21055, CVE-2024-21057; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source