Content Library · Advisory

Advisory 2025

Browse 613 2025 NetApp advisory records in the NetApp Black Box content library. Page 4 of 6.

Library JSON API

Showing all 120 items on this page

Advisory

CVE-2025-4123 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0001/

NetApp published this final advisory covering CVE-2025-4123; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-3050 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0002/

NetApp published this final advisory covering CVE-2025-3050; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-2518 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0003/

NetApp published this final advisory covering CVE-2025-2518; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-53846 Erlang OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0010/

NetApp published this interim advisory covering CVE-2024-53846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-49350 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250620-0004/

NetApp published this final advisory covering CVE-2024-49350; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4575 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0009/

NetApp published this interim advisory covering CVE-2025-4575; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-27610 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0003/

NetApp published this final advisory covering CVE-2025-27610; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27363 Freetype Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0008/

NetApp published this interim advisory covering CVE-2025-27363; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-27111 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0002/

NetApp published this final advisory covering CVE-2025-27111; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-25184 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0001/

NetApp published this final advisory covering CVE-2025-25184; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24855 Libxslt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0006/

NetApp published this final advisory covering CVE-2025-24855; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-23061 Mongoose Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0004/

NetApp published this final advisory covering CVE-2025-23061; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-56406 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0010/

NetApp published this final advisory covering CVE-2024-56406; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-53900 Mongoose Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0005/

NetApp published this final advisory covering CVE-2024-53900; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-47685 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0011/

NetApp published this interim advisory covering CVE-2024-47685; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; SnapCenter Plug-in for VMware vSphere; StorageGRID (formerly StorageGRID Webscale); StorageGRID Baseboard Management Controller (BMC) - SG6060/SGF6024/SG100/SG1000; StorageGRID Baseboard Management Controller (BMC) - SG6160/SGF6112/SG110/SG1100.

Open source
Advisory

CVE-2023-1192 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250613-0012/

NetApp published this interim advisory covering CVE-2023-1192; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-32415 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0003/

NetApp published this interim advisory covering CVE-2025-32415; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; ONTAP 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-32414 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0004/

NetApp published this interim advisory covering CVE-2025-32414; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-29088 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0010/

NetApp published this interim advisory covering CVE-2025-29088; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-52981 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0009/

NetApp published this interim advisory covering CVE-2024-52981; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-47611 XZ Utils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0006/

NetApp published this interim advisory covering CVE-2024-47611; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21664 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0005/

NetApp published this final advisory covering CVE-2024-21664; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2022-37026 Erlang-otp Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0008/

NetApp published this final advisory covering CVE-2022-37026; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-32224 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250605-0007/

NetApp published this final advisory covering CVE-2022-32224; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-3576 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0008/

NetApp published this final advisory covering CVE-2025-3576; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

CVE-2025-3277 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0005/

NetApp published this interim advisory covering CVE-2025-3277; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-31115 XZ Utils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0001/

NetApp published this interim advisory covering CVE-2025-31115; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-30211 Erlang/OTP Vulnerability NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0006/

NetApp published this interim advisory covering CVE-2025-30211; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-22871 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0004/

NetApp published this final advisory covering CVE-2025-22871; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; Astra Control Provisioner; Data Infrastructure Insights Telegraf Agent; NetApp Console Agent; NetApp Kubernetes Monitoring Operator; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-29937 FREEBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0007/

NetApp published this final advisory covering CVE-2024-29937; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5379 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250530-0003/

NetApp published this interim advisory covering CVE-2023-5379; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-40775 ISC Bind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0001/

NetApp published this final advisory covering CVE-2025-40775; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-31672 Apache POI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0004/

NetApp published this interim advisory covering CVE-2025-31672; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-1861 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0005/

NetApp published this final advisory covering CVE-2025-1861; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1734 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0009/

NetApp published this final advisory covering CVE-2025-1734; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1217 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0008/

NetApp published this final advisory covering CVE-2025-1217; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-50083 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0010/

NetApp published this interim advisory covering CVE-2024-50083; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2024-12243 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250523-0002/

NetApp published this interim advisory covering CVE-2024-12243; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

May 2025 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250516-0002/

NetApp published this final advisory covering CVE-2025-0915, CVE-2025-1000, CVE-2025-1992; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1493 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250516-0001/

NetApp published this final advisory covering CVE-2025-1493; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-0624 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250516-0006/

NetApp published this interim advisory covering CVE-2025-0624; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-22870 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0007/

NetApp published this final advisory covering CVE-2025-22870; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Trident; Trident Autosupport; Trident Protect.

Open source
Advisory

CVE-2024-38828 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0009/

NetApp published this interim advisory covering CVE-2024-38828; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-35890 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0008/

NetApp published this final advisory covering CVE-2024-35890; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-11741 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0006/

NetApp published this final advisory covering CVE-2024-11741; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24626 GNU Screen Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0003/

NetApp published this final advisory covering CVE-2023-24626; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-28831 BusyBox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0005/

NetApp published this final advisory covering CVE-2021-28831; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2021-26937 GNU Screen Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0004/

NetApp published this final advisory covering CVE-2021-26937; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2020-8165 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0002/

NetApp published this final advisory covering CVE-2020-8165; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2015-0240 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250509-0001/

NetApp published this final advisory covering CVE-2015-0240; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-29768 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0001/

NetApp published this final advisory covering CVE-2025-29768; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-27423 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0002/

NetApp published this final advisory covering CVE-2025-27423; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-7409 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0008/

NetApp published this final advisory covering CVE-2024-7409; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-37372 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0010/

NetApp published this final advisory covering CVE-2024-37372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-3446 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0007/

NetApp published this final advisory covering CVE-2024-3446; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-3219 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0004/

NetApp published this interim advisory covering CVE-2024-3219; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-27280 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0003/

NetApp published this final advisory covering CVE-2024-27280; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-28362 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0009/

NetApp published this final advisory covering CVE-2023-28362; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2025 MySQL 8.0.41, 8.4.4 and 9.2.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0006/

NetApp published this interim advisory covering CVE-2025-21577, CVE-2025-30682, CVE-2025-30687, CVE-2025-30688, CVE-2025-21574, CVE-2025-21575, CVE-2025-30693, CVE-2025-30695, CVE-2025-30689, CVE-2025-30696, CVE-2025-30715, CVE-2025-21584, CVE-2025-21580, CVE-2025-21581, CVE-2025-21585, CVE-2025-21579, CVE-2025-30705, CVE-2025-30683, CVE-2025-30684, CVE-2025-30685, CVE-2025-30699, CVE-2025-30704, CVE-2024-13176, CVE-2025-30721, CVE-2025-30703, CVE-2025-30681; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

April 2025 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250502-0005/

NetApp published this interim advisory covering CVE-2025-30698, CVE-2025-21587; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp Console; NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight.

Open source
Advisory

CVE-2025-32728 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0002/

NetApp published this interim advisory covering CVE-2025-32728; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-32433 Erlang OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0001/

NetApp published this final advisory covering CVE-2025-32433; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22228 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0009/

NetApp published this interim advisory covering CVE-2025-22228; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-9287 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0006/

NetApp published this final advisory covering CVE-2024-9287; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2024-6096 Progress Telerik Reporting Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0003/

NetApp published this final advisory covering CVE-2024-6096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-3447 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0005/

NetApp published this final advisory covering CVE-2024-3447; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-10846 compose-go Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0008/

NetApp published this final advisory covering CVE-2024-10846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-5733 ISC DHCP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250425-0010/

NetApp published this final advisory covering CVE-2018-5733; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-30722 MySQL Client Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250418-0005/

NetApp published this final advisory covering CVE-2025-30722; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

CVE-2025-30706 MySQL Connector/J Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250418-0007/

NetApp published this final advisory covering CVE-2025-30706; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-7254 MySQL Connector/J Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250418-0006/

NetApp published this final advisory covering CVE-2024-7254; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-27982 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250418-0001/

NetApp published this final advisory covering CVE-2024-27982; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-13176 MySQL Connector/ODBC Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250418-0010/

NetApp published this final advisory covering CVE-2024-13176; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1178 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0008/

NetApp published this interim advisory covering CVE-2025-1178; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-1176 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0007/

NetApp published this interim advisory covering CVE-2025-1176; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-47814 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0009/

NetApp published this final advisory covering CVE-2024-47814; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-4418 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0002/

NetApp published this interim advisory covering CVE-2024-4418; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1441 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0003/

NetApp published this interim advisory covering CVE-2024-1441; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-11168 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0004/

NetApp published this interim advisory covering CVE-2024-11168; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Mediator; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-0450 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0005/

NetApp published this interim advisory covering CVE-2024-0450; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2024-0397 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0006/

NetApp published this interim advisory covering CVE-2024-0397; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Mediator; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2021-47001 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250411-0001/

NetApp published this interim advisory covering CVE-2021-47001; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-1153 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0005/

NetApp published this interim advisory covering CVE-2025-1153; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-1148 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0004/

NetApp published this interim advisory covering CVE-2025-1148; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-1147 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0003/

NetApp published this interim advisory covering CVE-2025-1147; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-53580 Iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0009/

NetApp published this final advisory covering CVE-2024-53580; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2024-50602 Libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0008/

NetApp published this interim advisory covering CVE-2024-50602; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SAN Host Utilities for Windows.

Open source
Advisory

CVE-2024-36958 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0007/

NetApp published this interim advisory covering CVE-2024-36958; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-36945 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0006/

NetApp published this interim advisory covering CVE-2024-36945; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2024-23444 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0001/

NetApp published this interim advisory covering CVE-2024-23444; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-12254 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250404-0010/

NetApp published this final advisory covering CVE-2024-12254; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

March 2025 Ingress NGINX Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0008/

NetApp published this final advisory covering CVE-2025-24513, CVE-2025-24514, CVE-2025-1097, CVE-2025-1098, CVE-2025-1974; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-29927 Next.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0002/

NetApp published this final advisory covering CVE-2025-29927; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source