Content Library · Advisory

Advisory 2024

Browse 532 2024 NetApp advisory records in the NetApp Black Box content library. Page 4 of 5.

Library JSON API

Showing all 120 items on this page

Advisory

April 2024 MySQL Server 8.0.34 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0012/

NetApp published this interim advisory covering CVE-2024-21049, CVE-2024-21050, CVE-2024-21051, CVE-2024-21052, CVE-2024-21053, CVE-2024-21056; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

April 2024 MySQL Cluster Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0015/

NetApp published this final advisory covering CVE-2024-21101, CVE-2024-21102; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2024 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0004/

NetApp published this interim advisory covering CVE-2023-41993, CVE-2024-21002, CVE-2024-21003, CVE-2024-21004, CVE-2024-21005, CVE-2024-21011, CVE-2024-21012, CVE-2024-21068, CVE-2024-21085, CVE-2024-21094; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

February 2024 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0010/

NetApp published this final advisory covering CVE-2024-26327, CVE-2024-26328; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-25940 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0004/

NetApp published this final advisory covering CVE-2024-25940; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24758 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0007/

NetApp published this interim advisory covering CVE-2024-24758; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24750 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0006/

NetApp published this interim advisory covering CVE-2024-24750; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22257 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0005/

NetApp published this final advisory covering CVE-2024-22257; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-1597 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0008/

NetApp published this final advisory covering CVE-2024-1597; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-51780 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0001/

NetApp published this final advisory covering CVE-2023-51780; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-45288 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0009/

NetApp published this final advisory covering CVE-2023-45288; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Provisioner; Trident; Trident Autosupport.

Open source
Advisory

CVE-2022-23086 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0002/

NetApp published this final advisory covering CVE-2022-23086; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23084 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0003/

NetApp published this final advisory covering CVE-2022-23084; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26462 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0012/

NetApp published this interim advisory covering CVE-2024-26462; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-26461 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0011/

NetApp published this interim advisory covering CVE-2024-26461; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-26458 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0010/

NetApp published this interim advisory covering CVE-2024-26458; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-6536 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0001/

NetApp published this final advisory covering CVE-2023-6536; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-6535 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0003/

NetApp published this interim advisory covering CVE-2023-6535; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-6356 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0002/

NetApp published this final advisory covering CVE-2023-6356; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2022-4289 GitLab Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0004/

NetApp published this interim advisory covering CVE-2022-4289; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23092 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0009/

NetApp published this final advisory covering CVE-2022-23092; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23091 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0008/

NetApp published this final advisory covering CVE-2022-23091; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23090 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0007/

NetApp published this final advisory covering CVE-2022-23090; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23089 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0006/

NetApp published this final advisory covering CVE-2022-23089; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23087 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0005/

NetApp published this final advisory covering CVE-2022-23087; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2024 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0013/

NetApp published this final advisory covering CVE-2024-27316, CVE-2024-24795, CVE-2023-38709; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-35191 Intel SPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240405-0005/

NetApp published this interim advisory covering CVE-2023-35191; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Advisory

March 2024 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240402-0002/

NetApp published this final advisory covering CVE-2024-23672, CVE-2024-24549; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-3094 XZ Utils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240402-0001/

NetApp published this final advisory covering CVE-2024-3094; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24785 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0008/

NetApp published this final advisory covering CVE-2024-24785; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24784 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0007/

NetApp published this final advisory covering CVE-2024-24784; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24783 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0005/

NetApp published this final advisory covering CVE-2024-24783; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2024-22201 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0001/

NetApp published this interim advisory covering CVE-2024-22201; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-21896 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0002/

NetApp published this final advisory covering CVE-2024-21896; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-45290 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0004/

NetApp published this final advisory covering CVE-2023-45290; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-41946 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0003/

NetApp published this final advisory covering CVE-2022-41946; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-28757 libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0001/

NetApp published this interim advisory covering CVE-2024-28757; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; OnCommand Workflow Automation; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2024-21892 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0003/

NetApp published this final advisory covering CVE-2024-21892; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1635 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0007/

NetApp published this interim advisory covering CVE-2024-1635; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-6660 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0002/

NetApp published this final advisory covering CVE-2023-6660; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29153 Intel SPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0005/

NetApp published this interim advisory covering CVE-2023-29153; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2022-23085 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0004/

NetApp published this final advisory covering CVE-2022-23085; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

SnakeYAML 1.32 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0009/

NetApp published this interim advisory covering CVE-2022-38752, CVE-2022-41854; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

SnakeYAML 1.31 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0010/

NetApp published this interim advisory covering CVE-2022-38749, CVE-2022-38751, CVE-2022-38750, CVE-2022-25857; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-22234 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0003/

NetApp published this interim advisory covering CVE-2024-22234; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21891 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0005/

NetApp published this final advisory covering CVE-2024-21891; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21890 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0002/

NetApp published this interim advisory covering CVE-2024-21890; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-0232 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0007/

NetApp published this interim advisory covering CVE-2024-0232; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-42282 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0008/

NetApp published this final advisory covering CVE-2023-42282; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-25147 Apache Portable Runtime (APR) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0001/

NetApp published this final advisory covering CVE-2022-25147; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

October 2023 Ingress nginx Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0012/

NetApp published this final advisory covering CVE-2023-5043, CVE-2023-5044; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 X.Org X Server 21.1.11 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0006/

NetApp published this final advisory covering CVE-2024-0408, CVE-2024-0409, CVE-2023-6816; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 Tianocore EDK2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0011/

NetApp published this final advisory covering CVE-2023-45229, CVE-2023-45230, CVE-2023-45231, CVE-2023-45232, CVE-2023-45233, CVE-2023-45234, CVE-2023-45235, CVE-2023-45236, CVE-2023-45237; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 IBM DB2 11.5 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0001/

NetApp published this final advisory covering CVE-2023-47141, CVE-2023-47152, CVE-2023-45193, CVE-2023-50308; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 IBM DB2 10.5, 11.1, 11.5 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0003/

NetApp published this final advisory covering CVE-2023-47145, CVE-2023-47746; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 IBM DB2 10.1, 10.5, 11.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0002/

NetApp published this final advisory covering CVE-2023-27859, CVE-2023-47158, CVE-2023-47747; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26308 Apache Commons Compress Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0009/

NetApp published this interim advisory covering CVE-2024-26308; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); NetApp Console.

Open source
Advisory

CVE-2024-25710 Apache Commons Compress Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0010/

NetApp published this interim advisory covering CVE-2024-25710; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); NetApp Console.

Open source
Advisory

CVE-2024-0853 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0004/

NetApp published this interim advisory covering CVE-2024-0853; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; ONTAP 9.

Open source
Advisory

CVE-2023-52426 libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0005/

NetApp published this interim advisory covering CVE-2023-52426; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); OnCommand Workflow Automation; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2023-50868 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0008/

NetApp published this interim advisory covering CVE-2023-50868; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-50387 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0007/

NetApp published this interim advisory covering CVE-2023-50387; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-4886 Ingress nginx Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0013/

NetApp published this final advisory covering CVE-2022-4886; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46672 Logstash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240229-0001/

NetApp published this final advisory covering CVE-2023-46672; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2861 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240229-0002/

NetApp published this final advisory covering CVE-2023-2861; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22667 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0008/

NetApp published this final advisory covering CVE-2024-22667; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-1048 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0007/

NetApp published this final advisory covering CVE-2024-1048; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-0831 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0005/

NetApp published this interim advisory covering CVE-2024-0831; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-0565 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0002/

NetApp published this interim advisory covering CVE-2024-0565; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-6779 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0006/

NetApp published this interim advisory covering CVE-2023-6779; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-6683 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0001/

NetApp published this final advisory covering CVE-2023-6683; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6004 libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0004/

NetApp published this interim advisory covering CVE-2023-6004; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-41056 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0003/

NetApp published this final advisory covering CVE-2023-41056; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2024-22207 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0002/

NetApp published this interim advisory covering CVE-2024-22207; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21733 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0005/

NetApp published this interim advisory covering CVE-2024-21733; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6246 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0007/

NetApp published this interim advisory covering CVE-2023-6246; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-6129 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0009/

NetApp published this interim advisory covering CVE-2023-6129; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-49238 Gradle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0003/

NetApp published this final advisory covering CVE-2023-49238; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4001 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0006/

NetApp published this final advisory covering CVE-2023-4001; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-45047 Apache MINA SSHD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0008/

NetApp published this final advisory covering CVE-2022-45047; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-41678 Apache ActiveMQ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0004/

NetApp published this interim advisory covering CVE-2022-41678; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; E-Series SANtricity Unified Manager and Web Services Proxy; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2020-1745 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0011/

NetApp published this final advisory covering CVE-2020-1745; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Service Level Manager; OnCommand Workflow Automation.

Open source
Advisory

CVE-2015-7501 Redhat JBoss Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0010/

NetApp published this interim advisory covering CVE-2015-7501; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-23638 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0010/

NetApp published this final advisory covering CVE-2024-23638; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21312 .NET Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0008/

NetApp published this final advisory covering CVE-2024-21312; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-0727 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0006/

NetApp published this interim advisory covering CVE-2024-0727; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; ONTAP 9; ONTAP Select Deploy administration utility; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-0057 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0007/

NetApp published this final advisory covering CVE-2024-0057; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-7090 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0001/

NetApp published this final advisory covering CVE-2023-7090; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-6693 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0004/

NetApp published this final advisory covering CVE-2023-6693; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-47039 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0005/

NetApp published this final advisory covering CVE-2023-47039; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); SRA Plugin for Linux.

Open source
Advisory

CVE-2023-42465 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0002/

NetApp published this final advisory covering CVE-2023-42465; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2021-44528 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0003/

NetApp published this final advisory covering CVE-2021-44528; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 GnuTLS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0011/

NetApp published this interim advisory covering CVE-2024-0567, CVE-2024-0553; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-3863 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0002/

NetApp published this interim advisory covering CVE-2023-3863; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3776 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0003/

NetApp published this final advisory covering CVE-2023-3776; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-34319 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0001/

NetApp published this final advisory covering CVE-2023-34319; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-28120 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0006/

NetApp published this final advisory covering CVE-2023-28120; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source