Content Library · Advisory

Advisory 2024

Browse 532 2024 NetApp advisory records in the NetApp Black Box content library. Page 5 of 5.

Library JSON API

Showing all 52 items on this page

Advisory

CVE-2023-22796 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0009/

NetApp published this final advisory covering CVE-2023-22796; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22795 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0010/

NetApp published this final advisory covering CVE-2023-22795; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22794 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0008/

NetApp published this final advisory covering CVE-2023-22794; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22792 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0007/

NetApp published this final advisory covering CVE-2023-22792; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2002 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0004/

NetApp published this interim advisory covering CVE-2023-2002; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-22942 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0005/

NetApp published this final advisory covering CVE-2021-22942; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 MySQL Server 8.0.35 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0003/

NetApp published this final advisory covering CVE-2023-5363, CVE-2024-20960, CVE-2024-20961, CVE-2024-20962, CVE-2024-20963, CVE-2024-20964, CVE-2024-20965, CVE-2024-20966, CVE-2024-20967, CVE-2024-20969, CVE-2024-20970, CVE-2024-20971, CVE-2024-20972, CVE-2024-20973, CVE-2024-20974, CVE-2024-20976, CVE-2024-20977, CVE-2024-20978, CVE-2024-20981, CVE-2024-20982, CVE-2024-20984, CVE-2024-20985; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2024 MySQL Server 8.0.34 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0008/

NetApp published this final advisory covering CVE-2023-39975, CVE-2024-20968; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2024 MySQL Cluster Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0005/

NetApp published this final advisory covering CVE-2023-2283, CVE-2023-28484, CVE-2023-38545, CVE-2023-39975; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0002/

NetApp published this interim advisory covering CVE-2024-20918, CVE-2024-20919, CVE-2024-20921, CVE-2024-20922, CVE-2024-20923, CVE-2024-20925, CVE-2024-20926, CVE-2024-20932, CVE-2024-20945, CVE-2024-20952; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2024-20983 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0009/

NetApp published this interim advisory covering CVE-2024-20983; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2024-20965 MySQL Cluster Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0006/

NetApp published this final advisory covering CVE-2024-20965; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-31248 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0001/

NetApp published this final advisory covering CVE-2023-31248; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

December 2023 X.Org X Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0003/

NetApp published this final advisory covering CVE-2023-6377, CVE-2023-6478; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2023 Infinispan Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0004/

NetApp published this interim advisory covering CVE-2023-5236, CVE-2023-3629, CVE-2023-5384, CVE-2023-3628; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-51767 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0006/

NetApp published this final advisory covering CVE-2023-51767; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4806 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0008/

NetApp published this interim advisory covering CVE-2023-4806; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-46672 Logstash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0002/

NetApp published this final advisory covering CVE-2023-46672; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46218 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0007/

NetApp published this interim advisory covering CVE-2023-46218; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-33202 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0001/

NetApp published this interim advisory covering CVE-2023-33202; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp Console; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2023-2861 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0005/

NetApp published this interim advisory covering CVE-2023-2861; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2023 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0003/

NetApp published this final advisory covering CVE-2023-5868, CVE-2023-5869, CVE-2023-5870; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

December 2023 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0001/

NetApp published this final advisory covering CVE-2023-38003, CVE-2023-38727, CVE-2023-40687, CVE-2023-40692, CVE-2023-47701; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6277 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0002/

NetApp published this interim advisory covering CVE-2023-6277; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5528 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0009/

NetApp published this final advisory covering CVE-2023-5528; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-50495 GNU Ncurses Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0008/

NetApp published this interim advisory covering CVE-2023-50495; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-50269 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0005/

NetApp published this final advisory covering CVE-2023-50269; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-49288 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0006/

NetApp published this final advisory covering CVE-2023-49288; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46219 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0007/

NetApp published this interim advisory covering CVE-2023-46219; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-21400 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0012/

NetApp published this interim advisory covering CVE-2023-21400; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-21255 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0010/

NetApp published this final advisory covering CVE-2023-21255; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-2007 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0011/

NetApp published this final advisory covering CVE-2023-2007; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-23633 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0013/

NetApp published this final advisory covering CVE-2022-23633; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-7104 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0008/

NetApp published this interim advisory covering CVE-2023-7104; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-6534 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0007/

NetApp published this final advisory covering CVE-2023-6534; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6337 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0006/

NetApp published this final advisory covering CVE-2023-6337; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46167 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0003/

NetApp published this final advisory covering CVE-2023-46167; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-45287 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0005/

NetApp published this final advisory covering CVE-2023-45287; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident Autosupport; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-45178 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0004/

NetApp published this final advisory covering CVE-2023-45178; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29258 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0002/

NetApp published this final advisory covering CVE-2023-29258; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-26031 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0001/

NetApp published this final advisory covering CVE-2023-26031; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 OpenSSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240105-0005/

NetApp published this interim advisory covering CVE-2023-51384, CVE-2023-51385; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-48795 SSH Protocol Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240105-0004/

NetApp published this interim advisory covering CVE-2023-48795; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; Element Plug-in for vCenter Server; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; StorageGRID (formerly StorageGRID Webscale); Terraform Provider for ONTAP.

Open source
Advisory

CVE-2023-48706 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240105-0001/

NetApp published this interim advisory covering CVE-2023-48706; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-40238 InsydeH2O Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240105-0002/

NetApp published this final advisory covering CVE-2023-40238; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

AMI AptioV SA-2023009 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240105-0003/

NetApp published this final advisory covering CVE-2023-39538, CVE-2023-39539; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source