Vulnerability index

Browse CVEs

192 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Data Ontap MEDIUM 5.9
CVE-2016-6495

NetApp Data ONTAP before 8.2.4P5, when operating in 7-Mode, allows remote attackers to obtain information about the volumes configured for HTTP acces…

Fix: after 8.2.4
Fix from $1,600 2017-02-07
Oncommand Insight CRITICAL 9.8
CVE-2017-5600

The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default…

Fix: after 7.2.2
Fix from $2,300 2017-02-02
Metrocluster Tiebreaker HIGH 7.5
CVE-2016-6820

MetroCluster Tiebreaker for clustered Data ONTAP in versions before 1.2 discloses sensitive information in cleartext which may be viewed by an unauth…

Fix: after 1.1
Fix from $1,950 2017-01-11
Clustered Data Ontap HIGH 7.5
CVE-2015-7848EPSS 6%

An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode pa…

Fix: 4.2.8 / 4.3.77+
Fix from $1,950 2017-01-06
Snap Creator Framework HIGH 7.5
CVE-2016-7172

NetApp Snap Creator Framework before 4.3.1 discloses sensitive information which could be viewed by an unauthorized user.

Fix: after 4.3.0
Fix from $1,950 2016-12-21
Netapp Plug In MEDIUM 5.6
CVE-2016-7171

NetApp Plug-in for Symantec NetBackup prior to version 2.0.1 makes use of a non-unique server certificate, making it vulnerable to impersonation.

Fix: after 2.0
Fix from $1,600 2016-12-05
Oncommand System Manager MEDIUM 6.5
CVE-2016-5047

NetApp OnCommand System Manager 8.3.x before 8.3.2P5 allows remote authenticated users to cause a denial of service via unspecified vectors.

Patch available
Fix from $1,600 2016-09-01
Clustered Data Ontap MEDIUM 6.5
CVE-2016-3064

NetApp Clustered Data ONTAP before 8.2.4P4 and 8.3.x before 8.3.2P2 allows remote authenticated users to obtain sensitive cluster and tenant informat…

Fix: after 8.2.4
Fix from $1,600 2016-09-01
Clustered Data Ontap MEDIUM 6.8
CVE-2016-1563

NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof ser…

Mitigation only
Fix from $1,600 2016-04-07
Oncommand Workflow Automation HIGH 10.0
CVE-2015-3292EPSS 12%

The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, wh…

Fix: after 2.2.1
Fix from $1,950 2015-05-31
Oncommand Balance HIGH 10.0
CVE-2014-9353

NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain privileges via unspecified vecto…

Fix: after 4.2
Fix from $1,950 2015-02-06
Data Ontap HIGH 10.0
CVE-2008-3349

Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2008-07-28