Content Library · Advisory

Advisory 2025

Browse 613 2025 NetApp advisory records in the NetApp Black Box content library. Page 3 of 6.

Library JSON API

Showing all 120 items on this page

Advisory

CVE-2024-52894 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0011/

NetApp published this final advisory covering CVE-2024-52894; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-51473 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0012/

NetApp published this final advisory covering CVE-2024-51473; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-49828 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0013/

NetApp published this final advisory covering CVE-2024-49828; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3749 Axios Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0009/

NetApp published this interim advisory covering CVE-2021-3749; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Shift Toolkit.

Open source
Advisory

CVE-2025-4673 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0009/

NetApp published this interim advisory covering CVE-2025-4673; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent; Trident; Trident Autosupport; Trident Protect.

Open source
Advisory

CVE-2025-32442 Fastify Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0001/

NetApp published this final advisory covering CVE-2025-32442; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-2703 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0004/

NetApp published this final advisory covering CVE-2025-2703; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22868 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0008/

NetApp published this interim advisory covering CVE-2025-22868; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; NetApp Console Agent; NetApp Kubernetes Monitoring Operator; Trident.

Open source
Advisory

CVE-2023-42365 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0006/

NetApp published this interim advisory covering CVE-2023-42365; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2023-42364 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250822-0005/

NetApp published this interim advisory covering CVE-2023-42364; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-8194 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0001/

NetApp published this interim advisory covering CVE-2025-8194; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-1735 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0009/

NetApp published this final advisory covering CVE-2025-1735; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1180 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0008/

NetApp published this interim advisory covering CVE-2025-1180; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-7347 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0003/

NetApp published this interim advisory covering CVE-2024-7347; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-47220 Webrick Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0010/

NetApp published this final advisory covering CVE-2024-47220; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-32760 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0004/

NetApp published this interim advisory covering CVE-2024-32760; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-2496 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0005/

NetApp published this interim advisory covering CVE-2024-2496; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6597 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0002/

NetApp published this final advisory covering CVE-2023-6597; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-52356 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250814-0006/

NetApp published this final advisory covering CVE-2023-52356; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2025 GNU Binutils Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0007/

NetApp published this interim advisory covering CVE-2025-1151, CVE-2025-1149, CVE-2025-1150, CVE-2025-1152; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-8058 Glibc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0002/

NetApp published this interim advisory covering CVE-2025-8058; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-6297 Dpkg Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0008/

NetApp published this interim advisory covering CVE-2025-6297; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-50200 Rabbitmq-Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0001/

NetApp published this interim advisory covering CVE-2025-50200; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-50063 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0006/

NetApp published this interim advisory covering CVE-2025-50063; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4748 Erlang-OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0005/

NetApp published this interim advisory covering CVE-2025-4748; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-46701 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0004/

NetApp published this interim advisory covering CVE-2025-46701; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27144 Go-Jose Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0009/

NetApp published this final advisory covering CVE-2025-27144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-8118 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0011/

NetApp published this final advisory covering CVE-2024-8118; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-28180 Go-Jose Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0010/

NetApp published this interim advisory covering CVE-2024-28180; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-47108 OpenTelemetry-Go Contrib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250808-0003/

NetApp published this final advisory covering CVE-2023-47108; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-7783 Form-Data Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0002/

NetApp published this interim advisory covering CVE-2025-7783; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Astra Control Center; NetApp Shift Toolkit.

Open source
Advisory

CVE-2025-6491 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0008/

NetApp published this final advisory covering CVE-2025-6491; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5372 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0005/

NetApp published this interim advisory covering CVE-2025-5372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5351 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0006/

NetApp published this interim advisory covering CVE-2025-5351; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27210 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0001/

NetApp published this final advisory covering CVE-2025-27210; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-35962 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0007/

NetApp published this final advisory covering CVE-2024-35962; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-12905 tar-fs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0003/

NetApp published this final advisory covering CVE-2024-12905; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Shift Toolkit.

Open source
Advisory

CVE-2023-39615 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0009/

NetApp published this interim advisory covering CVE-2023-39615; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-38655 Intel AMT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250801-0004/

NetApp published this interim advisory covering CVE-2023-38655; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6395 GNUTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0007/

NetApp published this interim advisory covering CVE-2025-6395; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-53506 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0003/

NetApp published this interim advisory covering CVE-2025-53506; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48734 Apache Commons Beanutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0004/

NetApp published this interim advisory covering CVE-2025-48734; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-40777 ISC Bind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0002/

NetApp published this interim advisory covering CVE-2025-40777; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-40776 ISC Bind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0001/

NetApp published this final advisory covering CVE-2025-40776; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-32990 GNUTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0006/

NetApp published this interim advisory covering CVE-2025-32990; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-32989 GNUTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0008/

NetApp published this interim advisory covering CVE-2025-32989; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-32988 GNUTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0009/

NetApp published this interim advisory covering CVE-2025-32988; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-25809 Runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0010/

NetApp published this interim advisory covering CVE-2023-25809; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center.

Open source
Advisory

CVE-2019-10086 Apache Commons Beanutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250725-0005/

NetApp published this interim advisory covering CVE-2019-10086; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; OnCommand Insight; SnapCenter; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

July 2025 MySQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250724-0008/

NetApp published this interim advisory covering CVE-2025-50102, CVE-2025-50093, CVE-2025-50085, CVE-2025-50083, CVE-2025-50084, CVE-2025-50096, CVE-2025-50080, CVE-2025-50097, CVE-2025-50101, CVE-2025-50099, CVE-2025-50082, CVE-2025-50077, CVE-2025-50092, CVE-2025-5399, CVE-2025-50100, CVE-2025-50078, CVE-2025-50104, CVE-2025-50091, CVE-2025-50098, CVE-2025-50087, CVE-2025-50079, CVE-2025-50086; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

CVE-2025-53023 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250724-0001/

NetApp published this interim advisory covering CVE-2025-53023; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

CVE-2025-50088 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250724-0003/

NetApp published this interim advisory covering CVE-2025-50088; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

CVE-2025-50081 MySQL Client Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250724-0005/

NetApp published this interim advisory covering CVE-2025-50081; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

CVE-2025-30752 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250724-0011/

NetApp published this interim advisory covering CVE-2025-30752; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2025 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0013/

NetApp published this final advisory covering CVE-2025-53020, CVE-2025-49812, CVE-2025-49630, CVE-2025-23048, CVE-2024-47252, CVE-2024-43394, CVE-2024-43204, CVE-2024-42516; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9.

Open source
Advisory

Intel SA-00756 Ethernet Controller Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0012/

NetApp published this interim advisory covering CVE-2021-33141, CVE-2021-33162, CVE-2021-33157, CVE-2021-33161, CVE-2022-37341, CVE-2021-33145, CVE-2021-33158, CVE-2021-33142, CVE-2021-33146; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6069 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0005/

NetApp published this interim advisory covering CVE-2025-6069; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-52520 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0015/

NetApp published this interim advisory covering CVE-2025-52520; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5245 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0010/

NetApp published this interim advisory covering CVE-2025-5245; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-52434 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0014/

NetApp published this final advisory covering CVE-2025-52434; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-49796 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0004/

NetApp published this interim advisory covering CVE-2025-49796; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-49794 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0003/

NetApp published this interim advisory covering CVE-2025-49794; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-4598 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0001/

NetApp published this interim advisory covering CVE-2025-4598; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4517 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0009/

NetApp published this interim advisory covering CVE-2025-4517; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-4435 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0008/

NetApp published this interim advisory covering CVE-2025-4435; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-4330 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0007/

NetApp published this interim advisory covering CVE-2025-4330; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-4138 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0006/

NetApp published this interim advisory covering CVE-2025-4138; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-40909 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250718-0002/

NetApp published this interim advisory covering CVE-2025-40909; the API labels exploitation information as **Public**. The API currently lists affected products as: Snap Creator Framework.

Open source
Advisory

CVE-2025-6021 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0009/

NetApp published this interim advisory covering CVE-2025-6021; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-5399 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0010/

NetApp published this final advisory covering CVE-2025-5399; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4516 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0004/

NetApp published this final advisory covering CVE-2025-4516; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2025-30065 Apache Parquet Avro Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0001/

NetApp published this final advisory covering CVE-2025-30065; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-56128 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0005/

NetApp published this final advisory covering CVE-2024-56128; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3750 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0006/

NetApp published this interim advisory covering CVE-2023-3750; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22799 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250711-0007/

NetApp published this final advisory covering CVE-2023-22799; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-46392 Apache Commons Configuration Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0009/

NetApp published this interim advisory covering CVE-2025-46392; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-32463 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0010/

NetApp published this final advisory covering CVE-2025-32463; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-29087 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0003/

NetApp published this interim advisory covering CVE-2025-29087; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-22233 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0008/

NetApp published this interim advisory covering CVE-2025-22233; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-1179 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0006/

NetApp published this interim advisory covering CVE-2025-1179; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-0840 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0005/

NetApp published this interim advisory covering CVE-2025-0840; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-9622 Resteasy Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0004/

NetApp published this final advisory covering CVE-2024-9622; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-12801 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0001/

NetApp published this interim advisory covering CVE-2024-12801; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; E-Series SANtricity Unified Manager and Web Services Proxy; Management Services for Element Software and NetApp HCI; ONTAP tools for VMware vSphere 10; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2024-12798 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250704-0002/

NetApp published this interim advisory covering CVE-2024-12798; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; E-Series SANtricity Unified Manager and Web Services Proxy; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2025-4802 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0010/

NetApp published this interim advisory covering CVE-2025-4802; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-26618 Erlang OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0009/

NetApp published this final advisory covering CVE-2025-26618; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-50076 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0003/

NetApp published this interim advisory covering CVE-2024-50076; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2024-49997 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0005/

NetApp published this interim advisory covering CVE-2024-49997; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-47693 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0002/

NetApp published this interim advisory covering CVE-2024-47693; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-47689 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0001/

NetApp published this interim advisory covering CVE-2024-47689; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-45778 Grub Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0007/

NetApp published this interim advisory covering CVE-2024-45778; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-42256 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250627-0004/

NetApp published this interim advisory covering CVE-2024-42256; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-5025 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0008/

NetApp published this interim advisory covering CVE-2025-5025; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-4947 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0009/

NetApp published this interim advisory covering CVE-2025-4947; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-49125 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0006/

NetApp published this interim advisory covering CVE-2025-49125; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-49124 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0005/

NetApp published this interim advisory covering CVE-2025-49124; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source