NetappCVEs & Vulnerabilities

2,507 CVEs affecting Netapp products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

2,507 CVEs→ All vendors

Most Affected Products

oncommand insight 972active iq unified manager 851oncommand workflow automation 744snapcenter 579e-series santricity os controller 403cloud backup 345h700s 315h500s 315
CVE-2016-3064MEDIUM

NetApp Clustered Data ONTAP before 8.2.4P4 and 8.3.x before 8.3.2P2 allows remote authenticated users to obtain sensitive cluster and tenant information via unspecified vectors.

1 Sep 2016
6.5
CVSS
CVE-2016-1563MEDIUM

NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

7 Apr 2016
6.8
CVSS
CVE-2015-7974HIGH

NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."

26 Jan 2016
7.7
CVSS
CVE-2015-7886LOW

NetApp Data ONTAP before 8.2.4P1, when 7-Mode and HTTP access are enabled, allows remote attackers to obtain sensitive volume information via unspecified vectors.

18 Jan 2016
3.7
CVSS
CVE-2015-3292CRITICALpoc

The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.

31 May 2015
10.0
CVSS
CVE-2014-9354MEDIUM

NetApp OnCommand Balance before 4.2P3 allows local users to obtain sensitive information via unspecified vectors related to cleartext storage.

6 Feb 2015
4.0
CVSS
CVE-2014-9353CRITICAL

NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain privileges via unspecified vectors.

6 Feb 2015
10.0
CVSS
CVE-2010-5312MEDIUM

Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.

24 Nov 2014
6.1
CVSS
CVE-2008-3349CRITICAL

Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, cause a denial of service (system crash), or obtain sensitive information, probably related to insufficient access control for HTTP requests. NOTE: this may overlap CVE-2008-3160.

28 Jul 2008
10.0
CVSS
CVE-2007-2768MEDIUM

OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.

21 May 2007
4.3
CVSS
CVE-2007-2379MEDIUM

The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

1 May 2007
5.0
CVSS
← PrevPage 53 / 53Next →