Content Library · Advisory

Advisory 2025

Browse 615 2025 NetApp advisory records in the NetApp Black Box content library.

Library JSON API

Advisory

CVE-2025-66471 Urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0009/

NetApp published this interim advisory covering CVE-2025-66471; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Data Classification; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-66418 Urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0008/

NetApp published this interim advisory covering CVE-2025-66418; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Data Classification; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-66412 Angular Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0006/

NetApp published this interim advisory covering CVE-2025-66412; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-66035 Angular Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0007/

NetApp published this interim advisory covering CVE-2025-66035; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-62408 C-ares Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0014/

NetApp published this interim advisory covering CVE-2025-62408; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-40281 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0011/

NetApp published this interim advisory covering CVE-2025-40281; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-39828 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0013/

NetApp published this interim advisory covering CVE-2025-39828; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-39823 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0012/

NetApp published this interim advisory covering CVE-2025-39823; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-38734 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0010/

NetApp published this interim advisory covering CVE-2025-38734; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-23366 Wildfly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0004/

NetApp published this final advisory covering CVE-2025-23366; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-2251 Wildfly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0003/

NetApp published this interim advisory covering CVE-2025-2251; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2025-13601 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0001/

NetApp published this interim advisory covering CVE-2025-13601; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2025-10966 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0002/

NetApp published this interim advisory covering CVE-2025-10966; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-0620 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0005/

NetApp published this interim advisory covering CVE-2025-0620; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2023-2283 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251224-0015/

NetApp published this interim advisory covering CVE-2023-2283; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-67779 React Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0014/

NetApp published this interim advisory covering CVE-2025-67779; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Data Classification; NetApp Shift Toolkit.

Open source
Advisory

CVE-2025-66675 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0013/

NetApp published this final advisory covering CVE-2025-66675; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-58181 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0003/

NetApp published this interim advisory covering CVE-2025-58181; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Data Infrastructure Insights Telegraf Agent.

Open source
Advisory

CVE-2025-55184 React Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0015/

NetApp published this interim advisory covering CVE-2025-55184; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Data Classification; NetApp Shift Toolkit.

Open source
Advisory

CVE-2025-47912 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0004/

NetApp published this interim advisory covering CVE-2025-47912; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Trident; Trident Autosupport.

Open source
Advisory

CVE-2025-22874 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0001/

NetApp published this interim advisory covering CVE-2025-22874; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent.

Open source
Advisory

CVE-2025-14769 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0006/

NetApp published this final advisory covering CVE-2025-14769; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-14558 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0005/

NetApp published this final advisory covering CVE-2025-14558; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-13837 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0008/

NetApp published this interim advisory covering CVE-2025-13837; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2025-13836 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251219-0007/

NetApp published this interim advisory covering CVE-2025-13836; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2025-8851 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0007/

NetApp published this interim advisory covering CVE-2025-8851; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8225 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0011/

NetApp published this interim advisory covering CVE-2025-8225; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8224 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0010/

NetApp published this interim advisory covering CVE-2025-8224; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-66200 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0003/

NetApp published this interim advisory covering CVE-2025-66200; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-65082 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0001/

NetApp published this final advisory covering CVE-2025-65082; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-59775 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0005/

NetApp published this final advisory covering CVE-2025-59775; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-58098 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0004/

NetApp published this final advisory covering CVE-2025-58098; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-55753 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0002/

NetApp published this final advisory covering CVE-2025-55753; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-11839 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0015/

NetApp published this interim advisory covering CVE-2025-11839; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-11083 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0012/

NetApp published this interim advisory covering CVE-2025-11083; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-11082 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0014/

NetApp published this interim advisory covering CVE-2025-11082; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-11081 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0013/

NetApp published this interim advisory covering CVE-2025-11081; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-13978 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0008/

NetApp published this interim advisory covering CVE-2024-13978; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6228 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0009/

NetApp published this interim advisory covering CVE-2023-6228; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-50164 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251212-0006/

NetApp published this interim advisory covering CVE-2025-64775; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-9390 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0008/

NetApp published this interim advisory covering CVE-2025-9390; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-55182 React Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0001/

NetApp published this interim advisory covering CVE-2025-55182; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Data Classification; NetApp Shift Toolkit.

Open source
Advisory

CVE-2025-53906 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0006/

NetApp published this interim advisory covering CVE-2025-53906; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-53905 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0007/

NetApp published this interim advisory covering CVE-2025-53905; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48041 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0014/

NetApp published this final advisory covering CVE-2025-48041; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48040 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0013/

NetApp published this interim advisory covering CVE-2025-48040; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48038 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0012/

NetApp published this interim advisory covering CVE-2025-48038; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-47279 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0010/

NetApp published this final advisory covering CVE-2025-47279; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-46712 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0011/

NetApp published this interim advisory covering CVE-2025-46712; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-39839 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0015/

NetApp published this interim advisory covering CVE-2025-39839; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1390 Libcap Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0002/

NetApp published this interim advisory covering CVE-2025-1390; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-10911 Libxslt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0003/

NetApp published this interim advisory covering CVE-2025-10911; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46809 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251205-0009/

NetApp published this final advisory covering CVE-2023-46809; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-60753 Libarchive Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0013/

NetApp published this final advisory covering CVE-2025-60753; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6075 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0014/

NetApp published this interim advisory covering CVE-2025-6075; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5372 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0005/

NetApp published this final advisory covering CVE-2025-5372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-41115 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0004/

NetApp published this final advisory covering CVE-2025-41115; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-37997 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0011/

NetApp published this interim advisory covering CVE-2025-37997; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-37973 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0010/

NetApp published this interim advisory covering CVE-2025-37973; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-37894 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0009/

NetApp published this interim advisory covering CVE-2025-37894; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-37820 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0008/

NetApp published this interim advisory covering CVE-2025-37820; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-23367 Wildfly Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0012/

NetApp published this final advisory covering CVE-2025-23367; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-2336 AngularJS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0015/

NetApp published this interim advisory covering CVE-2025-2336; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-12818 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0007/

NetApp published this interim advisory covering CVE-2025-12818; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-12817 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251128-0006/

NetApp published this interim advisory covering CVE-2025-12817; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-52881 Runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0003/

NetApp published this interim advisory covering CVE-2025-52881; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-36186 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0010/

NetApp published this final advisory covering CVE-2025-36186; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36185 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0006/

NetApp published this final advisory covering CVE-2025-36185; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36131 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0008/

NetApp published this final advisory covering CVE-2025-36131; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36006 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0011/

NetApp published this final advisory covering CVE-2025-36006; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-33012 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0009/

NetApp published this final advisory covering CVE-2025-33012; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-31133 Runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0001/

NetApp published this interim advisory covering CVE-2025-31133; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-27209 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0013/

NetApp published this final advisory covering CVE-2025-27209; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-23165 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0012/

NetApp published this final advisory covering CVE-2025-23165; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-4068 Micromatch Braces Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0014/

NetApp published this final advisory covering CVE-2024-4068; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-3566 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0015/

NetApp published this final advisory covering CVE-2024-3566; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5981 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251121-0004/

NetApp published this interim advisory covering CVE-2023-5981; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

2026-09-01-ntap-20251121-0002

Source: https://security.netapp.com/advisory/NTAP-20251121-0002/

NetApp security advisory NTAP-20251121-0002. CVEs: CVE-2025-52565. Multiple NetApp products incorporate runc. Runc versions prior to 1.2.8, prior to 1.3.3, and prior to 1.4.0-rc.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2025-37944 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0010/

NetApp published this final advisory covering CVE-2025-37944; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-31498 C-ares Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0006/

NetApp published this final advisory covering CVE-2025-31498; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-27152 Axios Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0004/

NetApp published this final advisory covering CVE-2025-27152; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Shift Toolkit.

Open source
Advisory

CVE-2025-26646 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0001/

NetApp published this final advisory covering CVE-2025-26646; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-26597 X.Org Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0002/

NetApp published this final advisory covering CVE-2025-26597; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45782 Grub Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0008/

NetApp published this final advisory covering CVE-2024-45782; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-52522 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0011/

NetApp published this interim advisory covering CVE-2023-52522; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A320; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-34241 CUPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0007/

NetApp published this final advisory covering CVE-2023-34241; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-25434 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251114-0009/

NetApp published this final advisory covering CVE-2023-25434; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61795 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0014/

NetApp published this interim advisory covering CVE-2025-61795; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-55752 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0013/

NetApp published this final advisory covering CVE-2025-55752; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-54410 Docker Moby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0009/

NetApp published this interim advisory covering CVE-2025-54410; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-52099 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0015/

NetApp published this final advisory covering CVE-2025-52099; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48976 Apache Commons FileUpload Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0004/

NetApp published this final advisory covering CVE-2025-48976; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Snap Creator Framework.

Open source
Advisory

CVE-2025-41254 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0010/

NetApp published this interim advisory covering CVE-2025-41254; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Snap Creator Framework.

Open source
Advisory

CVE-2025-26596 Xorg-server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0007/

NetApp published this final advisory covering CVE-2025-26596; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-26595 Xorg-server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0006/

NetApp published this final advisory covering CVE-2025-26595; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24934 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0012/

NetApp published this final advisory covering CVE-2025-24934; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-23167 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0005/

NetApp published this final advisory covering CVE-2025-23167; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-11731 Libxslt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0011/

NetApp published this interim advisory covering CVE-2025-11731; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-21490 AngularJS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251107-0001/

NetApp published this interim advisory covering CVE-2024-21490; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

October 2025 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0013/

NetApp published this interim advisory covering CVE-2025-53042, CVE-2025-53062, CVE-2025-53053, CVE-2025-53040, CVE-2025-53054, CVE-2025-53045, CVE-2025-53044, CVE-2025-53069; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

October 2025 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0006/

NetApp published this interim advisory covering CVE-2025-53057, CVE-2025-53066; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); E-Series SANtricity Unified Manager and Web Services Proxy; OnCommand Insight; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2025-9086 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0007/

NetApp published this interim advisory covering CVE-2025-9086; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-8677 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0003/

NetApp published this interim advisory covering CVE-2025-8677; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-8277 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0010/

NetApp published this interim advisory covering CVE-2025-8277; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-7545 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0005/

NetApp published this interim advisory covering CVE-2025-7545; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-55754 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0011/

NetApp published this interim advisory covering CVE-2025-55754; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-40780 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0002/

NetApp published this interim advisory covering CVE-2025-40780; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-40778 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0001/

NetApp published this interim advisory covering CVE-2025-40778; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-1182 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0004/

NetApp published this interim advisory covering CVE-2025-1182; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-10148 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0008/

NetApp published this interim advisory covering CVE-2025-10148; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2023-5156 Glibc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0009/

NetApp published this interim advisory covering CVE-2023-5156; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2025-9640 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0002/

NetApp published this final advisory covering CVE-2025-9640; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-47906 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0005/

NetApp published this interim advisory covering CVE-2025-47906; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; NetApp Console Agent; NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2025-31257 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0009/

NetApp published this interim advisory covering CVE-2025-31257; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27819 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0008/

NetApp published this final advisory covering CVE-2025-27819; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27818 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0007/

NetApp published this final advisory covering CVE-2025-27818; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27817 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0006/

NetApp published this final advisory covering CVE-2025-27817; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-10230 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0001/

NetApp published this final advisory covering CVE-2025-10230; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-51744 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0003/

NetApp published this interim advisory covering CVE-2024-51744; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2025 OpenSSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0010/

NetApp published this interim advisory covering CVE-2025-61984, CVE-2025-61985; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400.

Open source
Advisory

July 2025 LuaJIT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0013/

NetApp published this interim advisory covering CVE-2024-25176, CVE-2024-25177, CVE-2024-25178; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6170 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0002/

NetApp published this interim advisory covering CVE-2025-6170; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Manageability SDK; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-49795 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0001/

NetApp published this interim advisory covering CVE-2025-49795; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-47273 Pypi/Setuptools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0007/

NetApp published this interim advisory covering CVE-2025-47273; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-6345 Pypi/Setuptools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0006/

NetApp published this interim advisory covering CVE-2024-6345; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-29217 PyJWT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0005/

NetApp published this interim advisory covering CVE-2022-29217; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-24801 Twisted Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0009/

NetApp published this final advisory covering CVE-2022-24801; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-21716 Twisted Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0008/

NetApp published this final advisory covering CVE-2022-21716; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-42771 Babel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0003/

NetApp published this final advisory covering CVE-2021-42771; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-24372 LuaJIT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0012/

NetApp published this interim advisory covering CVE-2020-24372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-15890 LuaJIT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0011/

NetApp published this interim advisory covering CVE-2020-15890; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-19391 LuaJIT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0014/

NetApp published this interim advisory covering CVE-2019-19391; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-7709 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0011/

NetApp published this interim advisory covering CVE-2025-7709; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-7039 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0009/

NetApp published this interim advisory covering CVE-2025-7039; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2025-6197 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0003/

NetApp published this final advisory covering CVE-2025-6197; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6023 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0002/

NetApp published this final advisory covering CVE-2025-6023; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-49844 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0012/

NetApp published this interim advisory covering CVE-2025-49844; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4056 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0010/

NetApp published this final advisory covering CVE-2025-4056; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-3580 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0006/

NetApp published this final advisory covering CVE-2025-3580; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-3454 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0005/

NetApp published this final advisory covering CVE-2025-3454; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6322 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0004/

NetApp published this final advisory covering CVE-2024-6322; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-35200 Nginx Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0008/

NetApp published this interim advisory covering CVE-2024-35200; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-34161 Nginx Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0007/

NetApp published this interim advisory covering CVE-2024-34161; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-11612 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0001/

NetApp published this interim advisory covering CVE-2024-11612; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-9784 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0007/

NetApp published this interim advisory covering CVE-2025-9784; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; OnCommand Insight.

Open source
Advisory

CVE-2025-9232 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0013/

NetApp published this interim advisory covering CVE-2025-9232; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-9231 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0012/

NetApp published this interim advisory covering CVE-2025-9231; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-9230 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0011/

NetApp published this interim advisory covering CVE-2025-9230; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Antivirus Connector; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-8671 HTTP/2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0004/

NetApp published this final advisory covering CVE-2025-8671; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Snap Creator Framework.

Open source
Advisory

CVE-2025-55668 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0003/

NetApp published this final advisory covering CVE-2025-55668; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-55163 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0005/

NetApp published this final advisory covering CVE-2025-55163; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5115 Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0006/

NetApp published this interim advisory covering CVE-2025-5115; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Snap Creator Framework.

Open source
Advisory

CVE-2025-32462 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0001/

NetApp published this interim advisory covering CVE-2025-32462; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27427 Apache ActiveMQ Artemis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0009/

NetApp published this interim advisory covering CVE-2025-27427; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-6931 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0002/

NetApp published this interim advisory covering CVE-2023-6931; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820.

Open source
Advisory

CVE-2023-50780 Apache ActiveMQ Artemis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0010/

NetApp published this interim advisory covering CVE-2023-50780; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-39810 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0008/

NetApp published this interim advisory covering CVE-2023-39810; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-01139 UEFI Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0004/

NetApp published this interim advisory covering CVE-2024-39279, CVE-2024-31157; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - 2820; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2025-22853 Intel TDX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0006/

NetApp published this interim advisory covering CVE-2025-22853; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-21096 Intel TDX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0005/

NetApp published this interim advisory covering CVE-2025-21096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20613 Intel TDX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0007/

NetApp published this interim advisory covering CVE-2025-20613; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-57360 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0001/

NetApp published this interim advisory covering CVE-2024-57360; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-31155 Intel UEFI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0003/

NetApp published this interim advisory covering CVE-2024-31155; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22185 Intel ACTM Module Software Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0010/

NetApp published this interim advisory covering CVE-2024-22185; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4373 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0009/

NetApp published this interim advisory covering CVE-2025-4373; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820.

Open source
Advisory

CVE-2025-36071 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0007/

NetApp published this final advisory covering CVE-2025-36071; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36010 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0004/

NetApp published this final advisory covering CVE-2025-36010; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-3360 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0010/

NetApp published this interim advisory covering CVE-2025-3360; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2025-33143 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0008/

NetApp published this final advisory covering CVE-2025-33143; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-33114 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0006/

NetApp published this final advisory covering CVE-2025-33114; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-33092 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0005/

NetApp published this final advisory covering CVE-2025-33092; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-36293 Intel SGX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0012/

NetApp published this interim advisory covering CVE-2024-36293; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-31068 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0015/

NetApp published this interim advisory covering CVE-2024-31068; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-28047 Intel UEFI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0011/

NetApp published this interim advisory covering CVE-2024-28047; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24985 Intel ACTM Module Software Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0013/

NetApp published this interim advisory covering CVE-2024-24985; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21859 Intel UEFI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0014/

NetApp published this interim advisory covering CVE-2024-21859; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6481 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0001/

NetApp published this interim advisory covering CVE-2023-6481; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-45322 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0003/

NetApp published this interim advisory covering CVE-2023-45322; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP 9.

Open source
Advisory

CVE-2021-36368 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0002/

NetApp published this interim advisory covering CVE-2021-36368; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-8916 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0011/

NetApp published this interim advisory covering CVE-2025-8916; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2025-54351 Iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0004/

NetApp published this final advisory covering CVE-2025-54351; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-54349 Iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0003/

NetApp published this final advisory covering CVE-2025-54349; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48913 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0001/

NetApp published this interim advisory covering CVE-2025-48913; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Snap Creator Framework.

Open source
Advisory

CVE-2025-41242 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0002/

NetApp published this interim advisory covering CVE-2025-41242; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Snap Creator Framework.

Open source
Advisory

CVE-2025-24305 Intel Xeon Processors Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0010/

NetApp published this interim advisory covering CVE-2025-24305; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22392 Intel AMT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0005/

NetApp published this interim advisory covering CVE-2025-22392; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-21090 Intel Xeon Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0009/

NetApp published this interim advisory covering CVE-2025-21090; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20067 Intel CSME Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0007/

NetApp published this interim advisory covering CVE-2025-20067; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20053 Intel Xeon Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0008/

NetApp published this interim advisory covering CVE-2025-20053; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20037 Intel CSME Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0006/

NetApp published this interim advisory covering CVE-2025-20037; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20250912-0012

Source: https://security.netapp.com/advisory/NTAP-20250912-0012/

NetApp security advisory NTAP-20250912-0012. CVEs: CVE-2025-8885. Multiple NetApp products incorporate Bouncy Castle. Certain versions of Bouncy Castle are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2025-5244 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0005/

NetApp published this interim advisory covering CVE-2025-5244; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4674 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0010/

NetApp published this final advisory covering CVE-2025-4674; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2025-3198 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0004/

NetApp published this interim advisory covering CVE-2025-3198; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-30258 GnuPG Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0002/

NetApp published this interim advisory covering CVE-2025-30258; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-23419 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0007/

NetApp published this interim advisory covering CVE-2025-23419; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-52979 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0003/

NetApp published this interim advisory covering CVE-2024-52979; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2240 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20250904-0001/

NetApp published this final advisory covering CVE-2024-2240; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2024-12718 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0008/

NetApp published this interim advisory covering CVE-2024-12718; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-54090 Apache Http Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0014/

NetApp published this interim advisory covering CVE-2025-54090; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-53817 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0002/

NetApp published this final advisory covering CVE-2025-53817; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2025-47907 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0001/

NetApp published this interim advisory covering CVE-2025-47907; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent.

Open source
Advisory

CVE-2025-2533 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0010/

NetApp published this final advisory covering CVE-2025-2533; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-52894 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0011/

NetApp published this final advisory covering CVE-2024-52894; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-51473 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0012/

NetApp published this final advisory covering CVE-2024-51473; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-49828 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0013/

NetApp published this final advisory covering CVE-2024-49828; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3749 Axios Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0009/

NetApp published this interim advisory covering CVE-2021-3749; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Shift Toolkit.

Open source
Advisory

CVE-2025-4673 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0009/

NetApp published this interim advisory covering CVE-2025-4673; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent; Trident; Trident Autosupport; Trident Protect.

Open source
Advisory

CVE-2025-32442 Fastify Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0001/

NetApp published this final advisory covering CVE-2025-32442; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-2703 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0004/

NetApp published this final advisory covering CVE-2025-2703; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22868 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0008/

NetApp published this interim advisory covering CVE-2025-22868; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; NetApp Console Agent; NetApp Kubernetes Monitoring Operator; Trident.

Open source
Advisory

CVE-2023-42365 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0006/

NetApp published this interim advisory covering CVE-2023-42365; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2023-42364 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0005/

NetApp published this interim advisory covering CVE-2023-42364; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-8194 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0001/

NetApp published this interim advisory covering CVE-2025-8194; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-1735 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0009/

NetApp published this final advisory covering CVE-2025-1735; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1180 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0008/

NetApp published this interim advisory covering CVE-2025-1180; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-7347 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0003/

NetApp published this interim advisory covering CVE-2024-7347; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-47220 Webrick Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0010/

NetApp published this final advisory covering CVE-2024-47220; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-32760 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0004/

NetApp published this interim advisory covering CVE-2024-32760; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-2496 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0005/

NetApp published this interim advisory covering CVE-2024-2496; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6597 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0002/

NetApp published this final advisory covering CVE-2023-6597; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-52356 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0006/

NetApp published this final advisory covering CVE-2023-52356; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2025 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0007/

NetApp published this interim advisory covering CVE-2025-1151, CVE-2025-1149, CVE-2025-1150, CVE-2025-1152; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-8058 Glibc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0002/

NetApp published this interim advisory covering CVE-2025-8058; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-6297 Dpkg Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0008/

NetApp published this interim advisory covering CVE-2025-6297; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-50200 Rabbitmq-Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0001/

NetApp published this interim advisory covering CVE-2025-50200; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-50063 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0006/

NetApp published this interim advisory covering CVE-2025-50063; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4748 Erlang-OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0005/

NetApp published this interim advisory covering CVE-2025-4748; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-46701 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0004/

NetApp published this interim advisory covering CVE-2025-46701; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27144 Go-Jose Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0009/

NetApp published this final advisory covering CVE-2025-27144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-8118 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0011/

NetApp published this final advisory covering CVE-2024-8118; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-28180 Go-Jose Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0010/

NetApp published this interim advisory covering CVE-2024-28180; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-47108 OpenTelemetry-Go Contrib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0003/

NetApp published this final advisory covering CVE-2023-47108; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-7783 Form-Data Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0002/

NetApp published this interim advisory covering CVE-2025-7783; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Astra Control Center; NetApp Shift Toolkit.

Open source
Advisory

CVE-2025-6491 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0008/

NetApp published this final advisory covering CVE-2025-6491; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5372 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0005/

NetApp published this interim advisory covering CVE-2025-5372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5351 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0006/

NetApp published this interim advisory covering CVE-2025-5351; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27210 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0001/

NetApp published this final advisory covering CVE-2025-27210; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-35962 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0007/

NetApp published this final advisory covering CVE-2024-35962; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-12905 tar-fs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0003/

NetApp published this final advisory covering CVE-2024-12905; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Shift Toolkit.

Open source
Advisory

CVE-2023-39615 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0009/

NetApp published this interim advisory covering CVE-2023-39615; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-38655 Intel AMT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0004/

NetApp published this interim advisory covering CVE-2023-38655; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6395 GNUTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0007/

NetApp published this interim advisory covering CVE-2025-6395; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-53506 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0003/

NetApp published this interim advisory covering CVE-2025-53506; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48734 Apache Commons Beanutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0004/

NetApp published this interim advisory covering CVE-2025-48734; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-40777 ISC Bind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0002/

NetApp published this interim advisory covering CVE-2025-40777; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-40776 ISC Bind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0001/

NetApp published this final advisory covering CVE-2025-40776; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-32990 GNUTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0006/

NetApp published this interim advisory covering CVE-2025-32990; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-32989 GNUTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0008/

NetApp published this interim advisory covering CVE-2025-32989; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-32988 GNUTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0009/

NetApp published this interim advisory covering CVE-2025-32988; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-25809 Runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0010/

NetApp published this interim advisory covering CVE-2023-25809; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center.

Open source
Advisory

CVE-2019-10086 Apache Commons Beanutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0005/

NetApp published this interim advisory covering CVE-2019-10086; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; OnCommand Insight; SnapCenter; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

July 2025 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250724-0008/

NetApp published this interim advisory covering CVE-2025-50102, CVE-2025-50093, CVE-2025-50085, CVE-2025-50083, CVE-2025-50084, CVE-2025-50096, CVE-2025-50080, CVE-2025-50097, CVE-2025-50101, CVE-2025-50099, CVE-2025-50082, CVE-2025-50077, CVE-2025-50092, CVE-2025-5399, CVE-2025-50100, CVE-2025-50078, CVE-2025-50104, CVE-2025-50091, CVE-2025-50098, CVE-2025-50087, CVE-2025-50079, CVE-2025-50086; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

CVE-2025-53023 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250724-0001/

NetApp published this interim advisory covering CVE-2025-53023; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

CVE-2025-50088 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250724-0003/

NetApp published this interim advisory covering CVE-2025-50088; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

CVE-2025-50081 MySQL Client Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250724-0005/

NetApp published this interim advisory covering CVE-2025-50081; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

CVE-2025-30752 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250724-0011/

NetApp published this interim advisory covering CVE-2025-30752; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2025 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0013/

NetApp published this final advisory covering CVE-2025-53020, CVE-2025-49812, CVE-2025-49630, CVE-2025-23048, CVE-2024-47252, CVE-2024-43394, CVE-2024-43204, CVE-2024-42516; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9.

Open source
Advisory

Intel SA-00756 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0012/

NetApp published this interim advisory covering CVE-2021-33141, CVE-2021-33162, CVE-2021-33157, CVE-2021-33161, CVE-2022-37341, CVE-2021-33145, CVE-2021-33158, CVE-2021-33142, CVE-2021-33146; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6069 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0005/

NetApp published this interim advisory covering CVE-2025-6069; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-52520 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0015/

NetApp published this interim advisory covering CVE-2025-52520; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5245 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0010/

NetApp published this interim advisory covering CVE-2025-5245; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-52434 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0014/

NetApp published this final advisory covering CVE-2025-52434; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-49796 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0004/

NetApp published this interim advisory covering CVE-2025-49796; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-49794 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0003/

NetApp published this interim advisory covering CVE-2025-49794; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-4598 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0001/

NetApp published this interim advisory covering CVE-2025-4598; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4517 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0009/

NetApp published this interim advisory covering CVE-2025-4517; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-4435 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0008/

NetApp published this interim advisory covering CVE-2025-4435; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-4330 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0007/

NetApp published this interim advisory covering CVE-2025-4330; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-4138 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0006/

NetApp published this interim advisory covering CVE-2025-4138; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-40909 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0002/

NetApp published this interim advisory covering CVE-2025-40909; the API labels exploitation information as **Public**. The API currently lists affected products as: Snap Creator Framework.

Open source
Advisory

CVE-2025-6021 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0009/

NetApp published this interim advisory covering CVE-2025-6021; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-5399 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0010/

NetApp published this final advisory covering CVE-2025-5399; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4516 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0004/

NetApp published this final advisory covering CVE-2025-4516; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2025-30065 Apache Parquet Avro Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0001/

NetApp published this final advisory covering CVE-2025-30065; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-56128 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0005/

NetApp published this final advisory covering CVE-2024-56128; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3750 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0006/

NetApp published this interim advisory covering CVE-2023-3750; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22799 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0007/

NetApp published this final advisory covering CVE-2023-22799; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-46392 Apache Commons Configuration Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0009/

NetApp published this interim advisory covering CVE-2025-46392; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-32463 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0010/

NetApp published this final advisory covering CVE-2025-32463; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-29087 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0003/

NetApp published this interim advisory covering CVE-2025-29087; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-22233 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0008/

NetApp published this interim advisory covering CVE-2025-22233; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-1179 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0006/

NetApp published this interim advisory covering CVE-2025-1179; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-0840 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0005/

NetApp published this interim advisory covering CVE-2025-0840; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-9622 Resteasy Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0004/

NetApp published this final advisory covering CVE-2024-9622; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-12801 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0001/

NetApp published this interim advisory covering CVE-2024-12801; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; E-Series SANtricity Unified Manager and Web Services Proxy; Management Services for Element Software and NetApp HCI; ONTAP tools for VMware vSphere 10; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2024-12798 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0002/

NetApp published this interim advisory covering CVE-2024-12798; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; E-Series SANtricity Unified Manager and Web Services Proxy; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2025-4802 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0010/

NetApp published this interim advisory covering CVE-2025-4802; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-26618 Erlang OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0009/

NetApp published this final advisory covering CVE-2025-26618; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-50076 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0003/

NetApp published this interim advisory covering CVE-2024-50076; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2024-49997 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0005/

NetApp published this interim advisory covering CVE-2024-49997; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-47693 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0002/

NetApp published this interim advisory covering CVE-2024-47693; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-47689 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0001/

NetApp published this interim advisory covering CVE-2024-47689; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-45778 Grub Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0007/

NetApp published this interim advisory covering CVE-2024-45778; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-42256 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0004/

NetApp published this interim advisory covering CVE-2024-42256; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-5025 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0008/

NetApp published this interim advisory covering CVE-2025-5025; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-4947 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0009/

NetApp published this interim advisory covering CVE-2025-4947; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-49125 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0006/

NetApp published this interim advisory covering CVE-2025-49125; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-49124 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0005/

NetApp published this interim advisory covering CVE-2025-49124; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4123 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0001/

NetApp published this final advisory covering CVE-2025-4123; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-3050 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0002/

NetApp published this final advisory covering CVE-2025-3050; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-2518 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0003/

NetApp published this final advisory covering CVE-2025-2518; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-53846 Erlang OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0010/

NetApp published this interim advisory covering CVE-2024-53846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-49350 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0004/

NetApp published this final advisory covering CVE-2024-49350; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4575 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0009/

NetApp published this interim advisory covering CVE-2025-4575; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-27610 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0003/

NetApp published this final advisory covering CVE-2025-27610; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27363 Freetype Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0008/

NetApp published this interim advisory covering CVE-2025-27363; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-27111 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0002/

NetApp published this final advisory covering CVE-2025-27111; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-25184 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0001/

NetApp published this final advisory covering CVE-2025-25184; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24855 Libxslt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0006/

NetApp published this final advisory covering CVE-2025-24855; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-23061 Mongoose Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0004/

NetApp published this final advisory covering CVE-2025-23061; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-56406 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0010/

NetApp published this final advisory covering CVE-2024-56406; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-53900 Mongoose Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0005/

NetApp published this final advisory covering CVE-2024-53900; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-47685 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0011/

NetApp published this interim advisory covering CVE-2024-47685; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; SnapCenter Plug-in for VMware vSphere; StorageGRID (formerly StorageGRID Webscale); StorageGRID Baseboard Management Controller (BMC) - SG6060/SGF6024/SG100/SG1000; StorageGRID Baseboard Management Controller (BMC) - SG6160/SGF6112/SG110/SG1100.

Open source
Advisory

CVE-2023-1192 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0012/

NetApp published this interim advisory covering CVE-2023-1192; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-32415 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0003/

NetApp published this interim advisory covering CVE-2025-32415; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; ONTAP 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-32414 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0004/

NetApp published this interim advisory covering CVE-2025-32414; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-29088 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0010/

NetApp published this interim advisory covering CVE-2025-29088; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-52981 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0009/

NetApp published this interim advisory covering CVE-2024-52981; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-47611 XZ Utils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0006/

NetApp published this interim advisory covering CVE-2024-47611; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21664 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0005/

NetApp published this final advisory covering CVE-2024-21664; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2022-37026 Erlang-otp Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0008/

NetApp published this final advisory covering CVE-2022-37026; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32224 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0007/

NetApp published this final advisory covering CVE-2022-32224; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-3576 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0008/

NetApp published this final advisory covering CVE-2025-3576; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

CVE-2025-3277 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0005/

NetApp published this interim advisory covering CVE-2025-3277; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-31115 XZ Utils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0001/

NetApp published this interim advisory covering CVE-2025-31115; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-30211 Erlang/OTP Vulnerability NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0006/

NetApp published this interim advisory covering CVE-2025-30211; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-22871 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0004/

NetApp published this final advisory covering CVE-2025-22871; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; Astra Control Provisioner; Data Infrastructure Insights Telegraf Agent; NetApp Console Agent; NetApp Kubernetes Monitoring Operator; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-29937 FREEBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0007/

NetApp published this final advisory covering CVE-2024-29937; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5379 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0003/

NetApp published this interim advisory covering CVE-2023-5379; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-40775 ISC Bind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0001/

NetApp published this final advisory covering CVE-2025-40775; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-31672 Apache POI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0004/

NetApp published this interim advisory covering CVE-2025-31672; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-1861 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0005/

NetApp published this final advisory covering CVE-2025-1861; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1734 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0009/

NetApp published this final advisory covering CVE-2025-1734; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1217 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0008/

NetApp published this final advisory covering CVE-2025-1217; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-50083 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0010/

NetApp published this interim advisory covering CVE-2024-50083; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2024-12243 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0002/

NetApp published this interim advisory covering CVE-2024-12243; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

May 2025 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250516-0002/

NetApp published this final advisory covering CVE-2025-0915, CVE-2025-1000, CVE-2025-1992; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1493 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250516-0001/

NetApp published this final advisory covering CVE-2025-1493; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-0624 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250516-0006/

NetApp published this interim advisory covering CVE-2025-0624; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-22870 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0007/

NetApp published this final advisory covering CVE-2025-22870; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Trident; Trident Autosupport; Trident Protect.

Open source
Advisory

CVE-2024-38828 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0009/

NetApp published this interim advisory covering CVE-2024-38828; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-35890 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0008/

NetApp published this final advisory covering CVE-2024-35890; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-11741 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0006/

NetApp published this final advisory covering CVE-2024-11741; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24626 GNU Screen Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0003/

NetApp published this final advisory covering CVE-2023-24626; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-28831 BusyBox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0005/

NetApp published this final advisory covering CVE-2021-28831; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-26937 GNU Screen Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0004/

NetApp published this final advisory covering CVE-2021-26937; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-8165 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0002/

NetApp published this final advisory covering CVE-2020-8165; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2015-0240 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0001/

NetApp published this final advisory covering CVE-2015-0240; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-29768 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0001/

NetApp published this final advisory covering CVE-2025-29768; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-27423 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0002/

NetApp published this final advisory covering CVE-2025-27423; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-7409 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0008/

NetApp published this final advisory covering CVE-2024-7409; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-37372 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0010/

NetApp published this final advisory covering CVE-2024-37372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-3446 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0007/

NetApp published this final advisory covering CVE-2024-3446; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-3219 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0004/

NetApp published this interim advisory covering CVE-2024-3219; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-27280 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0003/

NetApp published this final advisory covering CVE-2024-27280; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-28362 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0009/

NetApp published this final advisory covering CVE-2023-28362; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2025 MySQL 8.0.41, 8.4.4 and 9.2.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0006/

NetApp published this interim advisory covering CVE-2025-21577, CVE-2025-30682, CVE-2025-30687, CVE-2025-30688, CVE-2025-21574, CVE-2025-21575, CVE-2025-30693, CVE-2025-30695, CVE-2025-30689, CVE-2025-30696, CVE-2025-30715, CVE-2025-21584, CVE-2025-21580, CVE-2025-21581, CVE-2025-21585, CVE-2025-21579, CVE-2025-30705, CVE-2025-30683, CVE-2025-30684, CVE-2025-30685, CVE-2025-30699, CVE-2025-30704, CVE-2024-13176, CVE-2025-30721, CVE-2025-30703, CVE-2025-30681; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

April 2025 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0005/

NetApp published this interim advisory covering CVE-2025-30698, CVE-2025-21587; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp Console; NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight.

Open source
Advisory

CVE-2025-32728 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0002/

NetApp published this interim advisory covering CVE-2025-32728; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-32433 Erlang OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0001/

NetApp published this final advisory covering CVE-2025-32433; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22228 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0009/

NetApp published this interim advisory covering CVE-2025-22228; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-9287 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0006/

NetApp published this final advisory covering CVE-2024-9287; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2024-6096 Progress Telerik Reporting Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0003/

NetApp published this final advisory covering CVE-2024-6096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-3447 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0005/

NetApp published this final advisory covering CVE-2024-3447; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-10846 compose-go Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0008/

NetApp published this final advisory covering CVE-2024-10846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-5733 ISC DHCP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0010/

NetApp published this final advisory covering CVE-2018-5733; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-30722 MySQL Client Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250418-0005/

NetApp published this final advisory covering CVE-2025-30722; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

CVE-2025-30706 MySQL Connector/J Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250418-0007/

NetApp published this final advisory covering CVE-2025-30706; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-7254 MySQL Connector/J Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250418-0006/

NetApp published this final advisory covering CVE-2024-7254; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-27982 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250418-0001/

NetApp published this final advisory covering CVE-2024-27982; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-13176 MySQL Connector/ODBC Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250418-0010/

NetApp published this final advisory covering CVE-2024-13176; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1178 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0008/

NetApp published this interim advisory covering CVE-2025-1178; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-1176 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0007/

NetApp published this interim advisory covering CVE-2025-1176; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-47814 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0009/

NetApp published this final advisory covering CVE-2024-47814; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-4418 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0002/

NetApp published this interim advisory covering CVE-2024-4418; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1441 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0003/

NetApp published this interim advisory covering CVE-2024-1441; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-11168 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0004/

NetApp published this interim advisory covering CVE-2024-11168; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Mediator; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-0450 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0005/

NetApp published this interim advisory covering CVE-2024-0450; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2024-0397 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0006/

NetApp published this interim advisory covering CVE-2024-0397; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Mediator; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2021-47001 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0001/

NetApp published this interim advisory covering CVE-2021-47001; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-1153 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0005/

NetApp published this interim advisory covering CVE-2025-1153; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-1148 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0004/

NetApp published this interim advisory covering CVE-2025-1148; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-1147 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0003/

NetApp published this interim advisory covering CVE-2025-1147; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-53580 Iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0009/

NetApp published this final advisory covering CVE-2024-53580; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2024-50602 Libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0008/

NetApp published this interim advisory covering CVE-2024-50602; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SAN Host Utilities for Windows.

Open source
Advisory

CVE-2024-36958 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0007/

NetApp published this interim advisory covering CVE-2024-36958; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-36945 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0006/

NetApp published this interim advisory covering CVE-2024-36945; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2024-23444 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0001/

NetApp published this interim advisory covering CVE-2024-23444; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-12254 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0010/

NetApp published this final advisory covering CVE-2024-12254; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

March 2025 Ingress NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0008/

NetApp published this final advisory covering CVE-2025-24513, CVE-2025-24514, CVE-2025-1097, CVE-2025-1098, CVE-2025-1974; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-29927 Next.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0002/

NetApp published this final advisory covering CVE-2025-29927; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-8176 Libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0009/

NetApp published this interim advisory covering CVE-2024-8176; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2024-56171 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0010/

NetApp published this interim advisory covering CVE-2024-56171; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9.

Open source
Advisory

CVE-2024-54085 AMI MegaRAC Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0003/

NetApp published this final advisory covering CVE-2024-54085; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; StorageGRID Baseboard Management Controller (BMC) - SG6160/SGF6112/SG110/SG1100.

Open source
Advisory

CVE-2024-43484 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0007/

NetApp published this final advisory covering CVE-2024-43484; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-20672 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0006/

NetApp published this final advisory covering CVE-2024-20672; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24531 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0005/

NetApp published this final advisory covering CVE-2023-24531; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Trident; Trident Autosupport.

Open source
Advisory

CVE-2021-3773 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0004/

NetApp published this final advisory covering CVE-2021-3773; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

January 2025 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0003/

NetApp published this final advisory covering CVE-2025-23084, CVE-2025-23085; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24928 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0006/

NetApp published this interim advisory covering CVE-2025-24928; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; ONTAP 9.

Open source
Advisory

CVE-2025-1215 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0005/

NetApp published this final advisory covering CVE-2025-1215; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-35896 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0004/

NetApp published this interim advisory covering CVE-2024-35896; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-35894 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0002/

NetApp published this final advisory covering CVE-2024-35894; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-2408 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0008/

NetApp published this final advisory covering CVE-2024-2408; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-10524 Wget Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0007/

NetApp published this interim advisory covering CVE-2024-10524; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2021-4207 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0009/

NetApp published this final advisory covering CVE-2021-4207; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2021-4206 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0010/

NetApp published this final advisory covering CVE-2021-4206; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-25293 Ruby SAML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0008/

NetApp published this final advisory covering CVE-2025-25293; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-25292 Ruby SAML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0009/

NetApp published this final advisory covering CVE-2025-25292; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2025-25291 Ruby SAML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0010/

NetApp published this final advisory covering CVE-2025-25291; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2025-24014 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0005/

NetApp published this final advisory covering CVE-2025-24014; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-22134 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0004/

NetApp published this final advisory covering CVE-2025-22134; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-0938 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0002/

NetApp published this interim advisory covering CVE-2025-0938; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Mediator.

Open source
Advisory

CVE-2024-9264 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0007/

NetApp published this final advisory covering CVE-2024-9264; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-3220 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0001/

NetApp published this interim advisory covering CVE-2024-3220; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-27113 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0004/

NetApp published this interim advisory covering CVE-2025-27113; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9.

Open source
Advisory

CVE-2025-26603 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0003/

NetApp published this final advisory covering CVE-2025-26603; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-0725 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0009/

NetApp published this interim advisory covering CVE-2025-0725; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-0665 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0007/

NetApp published this final advisory covering CVE-2025-0665; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-0167 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0008/

NetApp published this interim advisory covering CVE-2025-0167; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-9823 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0006/

NetApp published this interim advisory covering CVE-2024-9823; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-6763 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0005/

NetApp published this interim advisory covering CVE-2024-6763; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-54133 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0010/

NetApp published this final advisory covering CVE-2024-54133; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-35176 Ruby REXML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0001/

NetApp published this interim advisory covering CVE-2024-35176; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1298 Tianocore EDK Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0002/

NetApp published this final advisory covering CVE-2024-1298; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-26466 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0002/

NetApp published this interim advisory covering CVE-2025-26466; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2025-26465 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0003/

NetApp published this interim advisory covering CVE-2025-26465; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2025-23083 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0008/

NetApp published this final advisory covering CVE-2025-23083; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-0395 glibc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0006/

NetApp published this interim advisory covering CVE-2025-0395; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-40896 libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0004/

NetApp published this interim advisory covering CVE-2024-40896; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-26306 iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0007/

NetApp published this final advisory covering CVE-2024-26306; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-34188 Mongoose Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0001/

NetApp published this final advisory covering CVE-2023-34188; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3929 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0010/

NetApp published this final advisory covering CVE-2021-3929; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2021-3735 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0009/

NetApp published this final advisory covering CVE-2021-3735; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2021-3549 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0005/

NetApp published this interim advisory covering CVE-2021-3549; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-25193 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0006/

NetApp published this interim advisory covering CVE-2025-25193; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2025-24970 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0005/

NetApp published this interim advisory covering CVE-2025-24970; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2025-22866 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0002/

NetApp published this final advisory covering CVE-2025-22866; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1094 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0010/

NetApp published this final advisory covering CVE-2025-1094; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-0306 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0009/

NetApp published this final advisory covering CVE-2025-0306; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-45341 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0004/

NetApp published this final advisory covering CVE-2024-45341; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2024-45338 golang.org/x/net Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0001/

NetApp published this interim advisory covering CVE-2024-45338; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45336 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0003/

NetApp published this final advisory covering CVE-2024-45336; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator; Trident.

Open source
Advisory

CVE-2024-45310 runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0008/

NetApp published this interim advisory covering CVE-2024-45310; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-43709 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0007/

NetApp published this final advisory covering CVE-2024-43709; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24860 Apache Cassandra Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0005/

NetApp published this final advisory covering CVE-2025-24860; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24814 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0002/

NetApp published this final advisory covering CVE-2025-24814; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-23184 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0003/

NetApp published this interim advisory covering CVE-2025-23184; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2025-23015 Apache Cassandra Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0006/

NetApp published this final advisory covering CVE-2025-23015; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-27137 Apache Cassandra Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0004/

NetApp published this final advisory covering CVE-2024-27137; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-12797 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0001/

NetApp published this interim advisory covering CVE-2024-12797; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-11477 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0007/

NetApp published this final advisory covering CVE-2024-11477; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Trident Autosupport.

Open source
Advisory

CVE-2023-6918 libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0009/

NetApp published this interim advisory covering CVE-2023-6918; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6152 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0008/

NetApp published this final advisory covering CVE-2023-6152; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38037 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0010/

NetApp published this final advisory covering CVE-2023-38037; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2024 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0008/

NetApp published this final advisory covering CVE-2024-51562, CVE-2024-51563, CVE-2024-51564, CVE-2024-51565, CVE-2024-51566; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2021 SELinux Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0004/

NetApp published this interim advisory covering CVE-2021-36084, CVE-2021-36085, CVE-2021-36086, CVE-2021-36087; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-0662 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0006/

NetApp published this final advisory covering CVE-2025-0662; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-0411 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0005/

NetApp published this final advisory covering CVE-2025-0411; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2025-0374 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0007/

NetApp published this final advisory covering CVE-2025-0374; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-0373 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0009/

NetApp published this final advisory covering CVE-2025-0373; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-12705 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0003/

NetApp published this final advisory covering CVE-2024-12705; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-11187 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0002/

NetApp published this interim advisory covering CVE-2024-11187; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-6780 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0010/

NetApp published this interim advisory covering CVE-2023-6780; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4639 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0001/

NetApp published this interim advisory covering CVE-2023-4639; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

January 2025 rsync Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0002/

NetApp published this interim advisory covering CVE-2024-12084, CVE-2024-12085, CVE-2024-12086, CVE-2024-12087, CVE-2024-12088, CVE-2024-12747; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

January 2025 MySQL 8.0.40, 8.4.3, and 9.1.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0004/

NetApp published this interim advisory covering CVE-2024-11053, CVE-2025-21500, CVE-2025-21501, CVE-2025-21518, CVE-2025-21522, CVE-2025-21497, CVE-2025-21555, CVE-2025-21559, CVE-2025-21540, CVE-2025-21490, CVE-2025-21491, CVE-2025-21503, CVE-2025-21523, CVE-2025-21531, CVE-2025-21505, CVE-2025-21529, CVE-2025-21543, CVE-2025-21519, CVE-2025-21546, CVE-2025-21520; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2024-52318 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0009/

NetApp published this final advisory covering CVE-2024-52318; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-49766 Werkzeug Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0005/

NetApp published this final advisory covering CVE-2024-49766; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-47554 Apache Commons IO Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0010/

NetApp published this interim advisory covering CVE-2024-47554; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp BlueXP; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9; SANtricity Storage Plugin for vCenter; SnapCenter.

Open source
Advisory

CVE-2024-45337 golang.org/x/crypto Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0007/

NetApp published this interim advisory covering CVE-2024-45337; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Data Infrastructure Insights Telegraf Agent; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-31141 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0001/

NetApp published this final advisory covering CVE-2024-31141; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24789 Golang Go Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0008/

NetApp published this final advisory covering CVE-2024-24789; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-11053 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0003/

NetApp published this interim advisory covering CVE-2024-11053; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

January 2025 MySQL 9.1.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0014/

NetApp published this interim advisory covering CVE-2025-21566, CVE-2025-21567; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

January 2025 MySQL 8.4.3 and 9.1.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0013/

NetApp published this interim advisory covering CVE-2025-21499, CVE-2025-21493; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

January 2025 MySQL 8.0.39, 8.4.2, and 9.0.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0010/

NetApp published this interim advisory covering CVE-2024-37371, CVE-2025-21521, CVE-2025-21525, CVE-2025-21504, CVE-2025-21536, CVE-2025-21534, CVE-2025-21494; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2025-21502 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0009/

NetApp published this interim advisory covering CVE-2025-21502; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2025-21492 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0011/

NetApp published this interim advisory covering CVE-2025-21492; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-52798 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0002/

NetApp published this final advisory covering CVE-2024-52798; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-52317 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0004/

NetApp published this final advisory covering CVE-2024-52317; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-52316 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0003/

NetApp published this final advisory covering CVE-2024-52316; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45296 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0001/

NetApp published this final advisory covering CVE-2024-45296; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-38827 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0007/

NetApp published this interim advisory covering CVE-2024-38827; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-38821 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0006/

NetApp published this final advisory covering CVE-2024-38821; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-13176 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0005/

NetApp published this interim advisory covering CVE-2024-13176; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 9; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-11053 MySQL Enterprise Backup Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0012/

NetApp published this final advisory covering CVE-2024-11053; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-41946 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0007/

NetApp published this final advisory covering CVE-2024-41946; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-39908 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0008/

NetApp published this interim advisory covering CVE-2024-39908; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-38807 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0006/

NetApp published this interim advisory covering CVE-2024-38807; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-29415 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0010/

NetApp published this final advisory covering CVE-2024-29415; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21409 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0002/

NetApp published this final advisory covering CVE-2024-21409; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-0690 Ansible Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0001/

NetApp published this interim advisory covering CVE-2024-0690; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-52434 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0009/

NetApp published this final advisory covering CVE-2023-52434; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-41913 strongSwan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0003/

NetApp published this final advisory covering CVE-2023-41913; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0049 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0005/

NetApp published this final advisory covering CVE-2023-0049; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2021-3918 Json-schema Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0004/

NetApp published this final advisory covering CVE-2021-3918; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Astra Control Center.

Open source
Advisory

CVE-2024-8929 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250110-0008/

NetApp published this final advisory covering CVE-2024-8929; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45289 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250110-0001/

NetApp published this final advisory covering CVE-2024-45289; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-39281 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250110-0002/

NetApp published this final advisory covering CVE-2024-39281; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-10979 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250110-0003/

NetApp published this final advisory covering CVE-2024-10979; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-53677 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250103-0005/

NetApp published this final advisory covering CVE-2024-53677; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-49767 Werkzeug Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250103-0007/

NetApp published this final advisory covering CVE-2024-49767; the API labels exploitation information as **Public**. The API currently lists affected products as: BlueXP Classification; Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2024-43398 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250103-0006/

NetApp published this interim advisory covering CVE-2024-43398; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-38429 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250103-0009/

NetApp published this final advisory covering CVE-2023-38429; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2017-18017 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250103-0010/

NetApp published this interim advisory covering CVE-2017-18017; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A320; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2016-10229 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250103-0008/

NetApp published this final advisory covering CVE-2016-10229; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source