Vulnerability index

Browse CVEs

192 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ontap Mediator MEDIUM 5.3
CVE-2023-27319

ONTAP Mediator versions prior to 1.7 are susceptible to a vulnerability that can allow an unauthenticated attacker to enumerate URLs via REST API.

Fix: 1.7+
Fix from $1,600 2023-12-21
Snapcenter HIGH 7.8
CVE-2023-27316

SnapCenter versions 4.8 through 4.9 are susceptible to a vulnerability which may allow an authenticated SnapCenter Server user to become an admin u…

Fix: after 4.9
Fix from $1,950 2023-10-12
Snapcenter HIGH 8.8
CVE-2023-27313

SnapCenter versions 3.x and 4.x prior to 4.9 are susceptible to a vulnerability which may allow an authenticated unprivileged user to gain access a…

Fix: 4.9+
Fix from $1,950 2023-10-12
Clustered Data Ontap HIGH 7.5
CVE-2023-27314

ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow a remote …

Fix: 9.8+
Fix from $1,950 2023-10-12
Snapgathers MEDIUM 5.5
CVE-2023-27315

SnapGathers versions prior to 4.9 are susceptible to a vulnerability which could allow a local authenticated attacker to discover plaintext domain …

Fix: 4.9+
Fix from $1,600 2023-10-12
Active Iq Unified Manager CRITICAL 9.8
CVE-2021-32292

An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sa…

No fix yet
Fix from $2,300 2023-08-22
Blue Xp Connector MEDIUM 5.3
CVE-2023-27311

NetApp Blue XP Connector versions prior to 3.9.25 expose information via a directory listing. A new Connector architecture resolves this issue - obta…

Fix: 3.9.25+
Fix from $1,600 2023-05-26
Snapcenter CRITICAL 9.8
CVE-2023-1096

SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker …

Mitigation only
Fix from $2,300 2023-05-12
Active Iq Unified Manager MEDIUM 5.3
CVE-2023-21971

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. D…

Fix: after 8.0.32
Fix from $1,600 2023-04-18
Storagegrid HIGH 7.5
CVE-2022-38734

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successful explo…

Fix: 11.6.0.8+
Fix from $1,950 2023-03-02
Active Iq Unified Manager MEDIUM 6.5
CVE-2022-23240

Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows u…

Fix: 9.11p1+
Fix from $1,600 2023-02-28
Oncommand Insight HIGH 8.6
CVE-2022-38733

OnCommand Insight versions 7.3.1 through 7.3.14 are susceptible to an authentication bypass vulnerability in the Data Warehouse component.

Fix: after 7.3.14
Fix from $1,950 2022-12-20
Clustered Data Ontap HIGH 8.1
CVE-2022-23241

Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerability which could allow an aut…

Mitigation only
Fix from $1,950 2022-10-19
Snapcenter HIGH 7.5
CVE-2022-38732

SnapCenter versions prior to 4.7 shipped without Content Security Policy (CSP) implemented which could allow certain types of attacks that otherwise …

Fix: 4.7+
Fix from $1,950 2022-09-29
Active Iq Unified Manager MEDIUM 5.3
CVE-2022-23235

Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.10P1 are susceptible to a vulnerability which could al…

Fix: 9.10+
Fix from $1,600 2022-08-25
Storagegrid MEDIUM 6.5
CVE-2022-23238

Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.…

Fix: 11.6.0.3+
Fix from $1,600 2022-08-10
E Series Santricity Os Controller MEDIUM 6.1
CVE-2022-23237

E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker…

Fix: after 11.70.2
Fix from $1,600 2022-06-02
Active Iq Unified Manager MEDIUM 5.5
CVE-2022-24823

Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Fin…

Fix: 4.1.77+
Fix from $1,600 2022-05-06
Active Iq Unified Manager MEDIUM 6.1
CVE-2022-24891

ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, there is a pote…

Fix: 2.3.0.0+
Fix from $1,600 2022-04-27
Active Iq Unified Manager CRITICAL 9.8
CVE-2022-23457

ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default imp…

Fix: 2.3.0.0+
Fix from $2,300 2022-04-25
Snapcenter MEDIUM 5.5
CVE-2022-23234

SnapCenter versions prior to 4.5 are susceptible to a vulnerability which could allow a local authenticated attacker to discover plaintext HANA crede…

Fix: 4.5+
Fix from $1,600 2022-03-16
Storagegrid HIGH 7.5
CVE-2022-23233

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could lead …

Fix: 11.6.0+
Fix from $1,950 2022-03-04
Cloud Backup HIGH 7.8
CVE-2021-0116

Out-of-bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via loc…

Mitigation only
Fix from $1,950 2022-02-09
Cloud Backup HIGH 7.8
CVE-2021-0117

Pointer issues in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local ac…

Mitigation only
Fix from $1,950 2022-02-09
Cloud Backup HIGH 7.8
CVE-2021-0156

Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privile…

Mitigation only
Fix from $1,950 2022-02-09
Cloud Backup MEDIUM 6.7
CVE-2021-0118

Out-of-bounds read in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via loca…

Mitigation only
Fix from $1,600 2022-02-09
Cloud Backup MEDIUM 6.6
CVE-2021-0124

Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via ph…

No fix yet
Fix from $1,600 2022-02-09
Cloud Backup MEDIUM 6.6
CVE-2021-0125

Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via ph…

Mitigation only
Fix from $1,600 2022-02-09
Cloud Backup MEDIUM 6.2
CVE-2021-0119

Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via ph…

Mitigation only
Fix from $1,600 2022-02-09
Clustered Data Ontap MEDIUM 5.5
CVE-2021-0127

Insufficient control flow management in some Intel(R) Processors may allow an authenticated user to potentially enable a denial of service via local …

Mitigation only
Fix from $1,600 2022-02-09