Netapp
netapp
2,507 CVEs • 371 products
Products (371)
Click to collapseToggle
Products (371)
Click to collapse
CVEs (2,507)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Netapp Oracle15Active Iq Unified Manager Cloud BackupE Series Santricity Os Controller+12 moreNov 21, 2024 Jul 18, 2018 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attack...Show more |
6Canonical DebianMariadb+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreNov 21, 2024 Jul 18, 2018 N/A· v4 3.1 LOW· v3 3.5 LOW· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Difficult to exp...Show more |
7Arm FujitsuIntel+4 more225Atom C Atom EAtom X3+222 moreNov 21, 2024 Jul 10, 2018 N/A· v4 5.6 MEDIUM· v3 4.7 MEDIUM· v2 Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel...Show more |
2Intel Netapp2Converged Security Management Engine Firmware Element Software Management NodeNov 21, 2024 Jul 10, 2018 N/A· v4 8.2 HIGH· v3 4.6 MEDIUM· v2 Logic bug in Intel Converged Security Management Engine 11.x may allow an attacker to execute arbitrary code via local privileged access. |
4Bouncycastle NetappOpensuse+1 more24Api Gateway Banking PlatformBc Java+21 moreMay 12, 2025 Jul 9, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vuln...Show more |
2Apache Netapp3Snapcenter SolrStorage Automation StoreNov 21, 2024 Jul 5, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIKA parsecontext config...Show more |
5Debian EclipseHp+2 more19Debian Linux E Series Santricity ManagementE Series Santricity Os Controller+16 moreNov 21, 2024 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When present...Show more |
5Debian EclipseHp+2 more17Debian Linux E Series Santricity ManagementE Series Santricity Os Controller+14 moreNov 21, 2024 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vul...Show more |
3Canonical NetappPhp3Php Storage Automation StoreUbuntu LinuxNov 21, 2024 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a stream that it is not responsible for closing. The vulnerable co...Show more |
2Eclipse Netapp12E Series Santricity Management Plug Ins E Series Santricity Os ControllerE Series Santricity Web Services Proxy+9 moreNov 21, 2024 Jun 22, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSes...Show more |
1Netapp 1Oncommand Unified Manager Nov 21, 2024 Jun 22, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account information to authenticated users when the LDAP authentication configuration is tested via the user...Show more |
4Apache CanonicalNetapp+1 more5Cloud Backup Http ServerJboss Core Services+2 moreNov 21, 2024 Jun 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33)...Show more |
1Netapp 2Santricity Storage Manager Santricity Web Services ProxyNov 21, 2024 Jun 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 NetApp SANtricity Web Services Proxy versions 1.10.x000.0002 through 2.12.X000.0002 and SANtricity Storage Manager 11.30.0X00.0004 through 11.42.0X00.0001 ship with the Java Management Extension Remote Method Invocation...Show more |
2Grafana Netapp3Active Iq Performance Analytics Services GrafanaStoragegrid Webscale Nas BridgeNov 21, 2024 Jun 11, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links. |
6Apple Archive\Canonical+3 more9\ Data Ontap EdgeDebian Linux+6 moreNov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file wit...Show more |
2Lodash Netapp3Active Iq Unified Manager LodashSystem ManagerNov 21, 2024 Jun 7, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Obje...Show more |
5Bouncycastle DebianNetapp+2 more20Api Gateway Bc JavaBusiness Process Management Suite+17 moreMay 12, 2025 Jun 5, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have l...Show more |
4Bouncycastle CanonicalNetapp+1 more57 Mode Transition Tool Legion Of The Bouncy Castle Java Crytography ApiSatellite+2 moreMay 5, 2025 Jun 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and stil...Show more |
1Netapp 1Oncommand Unified Manager Nov 21, 2024 May 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service bound to the network, and are susceptible to unauthenticated remote c...Show more |
1Netapp 1Oncommand Unified Manager Nov 21, 2024 May 24, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 NetApp OnCommand Unified Manager for Windows versions 7.2 through 7.3 are susceptible to a vulnerability which could lead to a privilege escalation attack. |