Vulnerability index

Browse CVEs

192 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Data Ontap HIGH 7.5
CVE-2019-5501

Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 may disclose sensitive LDAP account information to unauthenticated remote attackers.

Fix: 8.2.5+
Fix from $1,950 2019-08-02
Active Iq Unified Manager CRITICAL 9.1
CVE-2019-10744EPSS 5%

Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying prop…

Fix: 12.1.5.2 / 13.1.3.4+
Fix from $2,300 2019-07-26
Aff A700s Firmware CRITICAL 9.8
CVE-2019-5497

NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that could allow…

Mitigation only
Fix from $2,300 2019-07-01
Oncommand Unified Manager HIGH 7.5
CVE-2019-5495

OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security headers configured which could all…

Fix: 9.5+
Fix from $1,950 2019-05-10
Oncommand Insight HIGH 7.5
CVE-2019-5496

Oncommand Insight versions prior to 7.3.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive …

Fix: 7.3.5+
Fix from $1,950 2019-05-10
Oncommand Unified Manager HIGH 7.5
CVE-2019-5494

OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which could allow an attacker to obt…

Fix: 5.2.4+
Fix from $1,950 2019-05-10
Hyper Converged Infrastructure Compute Node HIGH 7.5
CVE-2019-5492

Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthenticated attacker. NetApp HCI Comp…

Fix: 4.2.3+
Fix from $1,950 2019-04-29
Service Processor CRITICAL 9.8
CVE-2019-5490

Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that cou…

Mitigation only
Fix from $2,300 2019-03-21
Snapcenter Server MEDIUM 5.3
CVE-2018-5482

NetApp SnapCenter Server prior to 4.1 does not set the secure flag for a sensitive cookie in an HTTPS session which can allow the transmission of the…

Fix: 4.1+
Fix from $1,600 2019-03-04
Clustered Data Ontap HIGH 7.5
CVE-2019-5491

Clustered Data ONTAP versions prior to 9.1P15 and 9.3 prior to 9.3P7 are susceptible to a vulnerability which discloses sensitive information to an u…

Fix: 9.1+
Fix from $1,950 2019-02-27
Oncommand Unified Manager HIGH 7.4
CVE-2018-5481

OnCommand Unified Manager for 7-Mode (core package) prior to 5.2.4 uses cookies that lack the secure attribute in certain circumstances making it vul…

Fix: 5.2.4+
Fix from $1,950 2019-01-07
Active Iq Unified Manager MEDIUM 6.5
CVE-2018-1000873

Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes …

Fix: 2.9.8 / 11.2.0.3.23+
Fix from $1,600 2018-12-20
Storagegrid Webscale CRITICAL 9.8
CVE-2018-5495

All StorageGRID Webscale versions are susceptible to a vulnerability which could permit an unauthenticated attacker to communicate with systems on th…

Mitigation only
Fix from $2,300 2018-11-14
E Series Santricity Os Controller CRITICAL 9.8
CVE-2018-5492

NetApp E-Series SANtricity OS Controller Software 11.30 and later version 11.30.5 is susceptible to unauthenticated remote code execution.

Fix: after 11.40
Fix from $2,300 2018-10-04
Clustered Data Ontap HIGH 8.8
CVE-2018-5490

Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "re…

Fix: 8.3+
Fix from $1,950 2018-08-03
7 Mode Transition Tool MEDIUM 6.5
CVE-2018-5489

NetApp 7-Mode Transition Tool allows users with valid credentials to access functions and information which may have been intended to be restricted t…

Fix: 2.0+
Fix from $1,600 2018-08-03
Oncommand Insight MEDIUM 6.5
CVE-2017-13652

NetApp OnCommand Insight version 7.3.0 and versions prior to 7.2.0 are susceptible to clickjacking attacks which could cause a user to perform an uni…

Fix: 7.2.0+
Fix from $1,600 2018-07-31
Oncommand Unified Manager MEDIUM 5.3
CVE-2017-7568

NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account information to authenticated u…

Fix: 5.2.3+
Fix from $1,600 2018-06-22
Santricity Storage Manager CRITICAL 9.8
CVE-2018-5488

NetApp SANtricity Web Services Proxy versions 1.10.x000.0002 through 2.12.X000.0002 and SANtricity Storage Manager 11.30.0X00.0004 through 11.42.0X00…

Fix: after 11.42.0x00.0001
Fix from $2,300 2018-06-13
Active Iq Unified Manager MEDIUM 6.5
CVE-2018-3721

lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith fu…

Fix: 4.17.5+
Fix from $1,600 2018-06-07
Oncommand Unified Manager CRITICAL 9.8
CVE-2018-5487

NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Method Invocation (JMX RMI) servic…

Fix: after 7.3
Fix from $2,300 2018-05-24
Oncommand Unified Manager HIGH 7.8
CVE-2018-5485

NetApp OnCommand Unified Manager for Windows versions 7.2 through 7.3 are susceptible to a vulnerability which could lead to a privilege escalation a…

Fix: after 7.3
Fix from $1,950 2018-05-24
Oncommand Unified Manager HIGH 7.8
CVE-2018-5486

NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled which allows unauthorized lo…

Fix: after 7.3
Fix from $1,950 2018-04-25
Snapcenter Server HIGH 7.2
CVE-2017-15519

Versions of SnapCenter 2.0 through 3.0.1 allow unauthenticated remote attackers to view and modify backup related data via the Plug-in for NAS File S…

Fix: after 3.0.1
Fix from $1,950 2018-03-06
Oncommand Api Services HIGH 7.8
CVE-2017-15518

All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password.…

Fix: after 2.0
Fix from $1,950 2018-02-23
Clustered Data Ontap MEDIUM 6.5
CVE-2017-14583

NetApp Clustered Data ONTAP versions 9.x prior to 9.1P10 and 9.2P2 are susceptible to a vulnerability which allows an attacker to cause a Denial of S…

Fix: after 9.1
Fix from $1,600 2017-12-18
Vasa Provider HIGH 8.1
CVE-2016-6904

Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentication. This could allow an un…

Fix: after 7.0
Fix from $1,950 2017-12-11
Altavault Ost Plug In MEDIUM 5.5
CVE-2017-15517

AltaVault OST Plug-in versions prior to 1.2.2 may allow attackers to obtain sensitive information via unspecified vectors. All users are urged to mov…

Fix: 1.2.2+
Fix from $1,600 2017-11-17
Snapcenter Server HIGH 8.8
CVE-2017-15516

NetApp SnapCenter Server versions 1.1 through 2.x are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability which could be used to cause a…

Patch available
Fix from $1,950 2017-11-16
Clustered Data Ontap MEDIUM 5.7
CVE-2017-5201

NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allow remote authenticated users to obtain sensitive cluster and tenant information via …

Fix: 8.3.2+
Fix from $1,600 2017-11-10