Vulnerability index

Browse CVEs

192 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Clustered Data Ontap HIGH 8.8
CVE-2017-12421

NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to execute arbitrary code on the storage controller via unspecifi…

Mitigation only
Fix from $1,950 2017-09-01
Clustered Data Ontap HIGH 7.7
CVE-2017-12423

NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to read data on other Storage Virtual Machines (SVMs) via unspeci…

Mitigation only
Fix from $1,950 2017-09-01
Oncommand Unified Manager For Clustered Data Ontap HIGH 7.5
CVE-2017-14053

NetApp OnCommand Unified Manager for Clustered Data ONTAP before 7.2P1 does not set the secure flag for an unspecified cookie in an HTTPS session, wh…

Fix: after 7.2
Fix from $1,950 2017-09-01
Data Ontap MEDIUM 6.5
CVE-2016-1895

NetApp Data ONTAP before 8.2.5 and 8.3.x before 8.3.2P12 allow remote authenticated users to cause a denial of service via vectors related to unsafe …

Fix: after 8.2.4
Fix from $1,600 2017-09-01
Data Ontap CRITICAL 9.8
CVE-2015-7746

NetApp Data ONTAP before 8.2.4, when operating in 7-Mode, allows remote attackers to bypass authentication and (1) obtain sensitive information from …

Fix: after 8.2.3
Fix from $2,300 2017-09-01
Storagegrid Webscale MEDIUM 6.5
CVE-2017-12422

NetApp StorageGRID Webscale 10.2.x before 10.2.2.3, 10.3.x before 10.3.0.4, and 10.4.x before 10.4.0.2 allow remote authenticated users to delete arb…

Mitigation only
Fix from $1,600 2017-08-29
Clustered Data Ontap HIGH 8.8
CVE-2017-12420

Heap-based buffer overflow in the SMB implementation in NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allows remote authenticated user…

Fix: after 9.0
Fix from $1,950 2017-08-18
Data Ontap MEDIUM 5.9
CVE-2017-12859

NetApp Data ONTAP before 8.2.5, when operating in 7-Mode in NFS environments, allows remote attackers to cause a denial of service via unspecified ve…

Fix: after 8.2.4
Fix from $1,600 2017-08-18
Snapcenter Server HIGH 8.1
CVE-2015-7887

NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups.

Patch available
Fix from $1,950 2017-08-07
Oncommand Api Services MEDIUM 6.5
CVE-2017-8919

NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API, which allows remote authent…

Fix: after 1.2
Fix from $1,600 2017-07-25
Clustered Data Ontap MEDIUM 6.5
CVE-2017-7947

NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging …

Mitigation only
Fix from $1,600 2017-07-17
Altavault HIGH 8.1
CVE-2016-3998

NetApp AltaVault 4.1 and earlier allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service vi…

Fix: after 4.1
Fix from $1,950 2017-07-03
Oncommand System Manager HIGH 8.1
CVE-2016-5045

NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup.

Mitigation only
Fix from $1,950 2017-07-03
Data Ontap HIGH 7.5
CVE-2016-3400

NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or caus…

No fix yet
Fix from $1,950 2017-07-03
Clustered Data Ontap HIGH 7.5
CVE-2016-3997

NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leve…

Mitigation only
Fix from $1,950 2017-07-03
Oncommand Unified Manager Core Package HIGH 7.5
CVE-2017-7236

SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL comm…

Patch available
Fix from $1,950 2017-05-26
Oncommand Unified Manager Core Package HIGH 7.5
CVE-2017-7439

NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving e…

Patch available
Fix from $1,950 2017-05-26
Clustered Data Ontap HIGH 7.5
CVE-2017-5988

NetApp Clustered Data ONTAP 8.1 through 9.1P1, when NFS or SMB is enabled, allows remote attackers to cause a denial of service via unspecified vecto…

No fix yet
Fix from $1,950 2017-04-10
Clustered Data Ontap MEDIUM 5.3
CVE-2017-7345

NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7.1P1 improperly bind the Java Management Extensio…

Fix: after 7.1
Fix from $1,600 2017-04-10
Data Ontap HIGH 8.8
CVE-2016-5374

NetApp Data ONTAP 9.0 and 9.1 before 9.1P1 allows remote authenticated users that own SMB-hosted data to bypass intended sharing restrictions by leve…

Patch available
Fix from $1,950 2017-03-01
Ontap Select Deploy Administration Utility HIGH 7.5
CVE-2017-5995

The NetApp ONTAP Select Deploy administration utility 2.0 through 2.2.1 might allow remote attackers to obtain sensitive information via unspecified …

Mitigation only
Fix from $1,950 2017-03-01
Virtual Storage Console For Vmware Vsphere CRITICAL 9.8
CVE-2016-5711

NetApp Virtual Storage Console for VMware vSphere before 6.2.1 uses a non-unique certificate, which allows remote attackers to conduct man-in-the-mid…

Fix: after 6.2
Fix from $2,300 2017-02-07
Oncommand Unified Manager For Clustered Data Ontap CRITICAL 9.8
CVE-2016-6667

NetApp OnCommand Unified Manager for Clustered Data ONTAP 6.3 through 6.4P1 contain a default privileged account, which allows remote attackers to ex…

Patch available
Fix from $2,300 2017-02-07
Data Ontap HIGH 8.8
CVE-2015-8322

NetApp OnCommand System Manager 8.3.x before 8.3.2 allows remote authenticated users to execute arbitrary code via unspecified vectors.

Patch available
Fix from $1,950 2017-02-07
Oncommand Workflow Automation HIGH 8.1
CVE-2016-1894

NetApp OnCommand Workflow Automation before 3.1P2 allows remote attackers to bypass authentication via unspecified vectors.

Fix: after 3.1
Fix from $1,950 2017-02-07
Snapdrive HIGH 7.5
CVE-2015-8544

NetApp SnapDrive for Windows before 7.0.2P4, 7.0.3, and 7.1 before 7.1.3P1 allows remote attackers to obtain sensitive information via unspecified ve…

Fix: after 7.1.3
Fix from $1,950 2017-02-07
Oncommand System Manager HIGH 7.5
CVE-2016-3063

Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users…

Fix: after 8.3.1
Fix from $1,950 2017-02-07
Clustered Data Ontap HIGH 7.5
CVE-2016-4341

NetApp Clustered Data ONTAP before 8.3.2P7 allows remote attackers to obtain SMB share information via unspecified vectors.

Fix: after 8.3.2
Fix from $1,950 2017-02-07
Snapcenter Server HIGH 7.3
CVE-2016-1502

NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and delete backups via unspecified ve…

Patch available
Fix from $1,950 2017-02-07
Snap Creator Framework MEDIUM 6.3
CVE-2016-5372

Cross-site request forgery (CSRF) vulnerability in NetApp Snap Creator Framework before 4.3.0P1 allows remote attackers to hijack the authentication …

Fix: after 4.3.0
Fix from $1,600 2017-02-07