netapp
108 known vulnerabilities affecting netapp products.
Products
h300s 33
h500s 33
h500s_firmware 32
h300s_firmware 32
h410s 32
h700s 32
h700s_firmware 31
h410s_firmware 31
h410c 31
h410c_firmware 30
h300e 25
h300e_firmware 25
h500e 25
h500e_firmware 25
active_iq_unified_manager 25
h700e 23
h700e_firmware 23
cloud_backup 21
service_level_manager 16
steelstore_cloud_integrated_storage 13
solidfire_baseboard_management_controller 8
solidfire_baseboard_management_controller_firmware 8
hci_compute_node 6
oncommand_insight 5
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-40438 | Act now | 100.0% | 9.0 | ● | A crafted request uri-path can cause mod_proxy to forward the request to an orig… |
| CVE-2017-12617 | Act now | 100.0% | 8.1 | ● | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC… |
| CVE-2017-12615 | Act now | 99.6% | 8.1 | ● | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.… |
| CVE-2020-1938 | Act now | 99.3% | 9.8 | ● | When using the Apache JServ Protocol (AJP), care must be taken when trusting inc… |
| CVE-2016-8735 | Act now | 90.3% | 9.8 | ● | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7… |
| CVE-2024-1086 | Act now | 28.1% | 7.8 | ● | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables compon… |
| CVE-2022-0995 | Act now | 9.5% | 7.8 | ● | An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_q… |
| CVE-2021-45105 | High | 100.0% | 5.9 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) di… | |
| CVE-2024-6387 | High | 99.5% | 8.1 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd).… | |
| CVE-2020-13935 | High | 86.6% | 7.5 | The payload length in a WebSocket frame was not correctly validated in Apache To… | |
| CVE-2020-13934 | High | 64.1% | 7.5 | An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.… | |
| CVE-2021-41184 | Medium | 40.8% | 6.5 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0… | |
| CVE-2021-41182 | Medium | 39.4% | 6.5 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0… | |
| CVE-2020-36179 | Medium | 21.0% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2020-9548 | Medium | 18.3% | 9.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee… | |
| CVE-2020-25649 | Medium | 17.8% | 7.5 | A flaw was found in FasterXML Jackson Databind, where it did not have entity exp… | |
| CVE-2023-1380 | Medium | 16.5% | 7.1 | A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net… | |
| CVE-2020-35728 | Medium | 12.5% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2022-23437 | Medium | 11.6% | 6.5 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when … | |
| CVE-2020-36188 | Medium | 10.9% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2020-36184 | Medium | 10.4% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2020-35491 | Medium | 9.6% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2020-24616 | Medium | 9.4% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction betwee… | |
| CVE-2020-14060 | Medium | 8.6% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee… | |
| CVE-2020-14062 | Medium | 8.1% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee… | |
| CVE-2020-10673 | Medium | 8.0% | 8.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee… | |
| CVE-2020-35490 | Medium | 7.8% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2021-20190 | Medium | 7.5% | 8.1 | A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the i… | |
| CVE-2020-10683 | Medium | 7.3% | 9.8 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Enti… | |
| CVE-2021-20322 | Medium | 6.8% | 7.4 | A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP … | |
| CVE-2020-11113 | Medium | 6.3% | 8.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee… | |
| CVE-2022-27666 | Medium | 5.5% | 7.8 | A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ip… | |
| CVE-2020-36185 | Medium | 5.2% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2020-36186 | Medium | 5.2% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2020-36187 | Medium | 5.2% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2020-36180 | Medium | 5.0% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2020-36181 | Medium | 5.0% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2020-36182 | Medium | 5.0% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2020-36183 | Medium | 4.9% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2020-36189 | Medium | 4.9% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2020-9546 | Medium | 4.6% | 9.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee… | |
| CVE-2024-1635 | Medium | 4.6% | 7.5 | A vulnerability was found in Undertow. This vulnerability impacts a server that … | |
| CVE-2020-14195 | Medium | 4.5% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee… | |
| CVE-2020-14061 | Medium | 4.5% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee… | |
| CVE-2022-37967 | Medium | 4.1% | 7.2 | Windows Kerberos Elevation of Privilege Vulnerability | |
| CVE-2020-11619 | Medium | 3.7% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee… | |
| CVE-2020-11112 | Medium | 3.7% | 8.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee… | |
| CVE-2020-10968 | Medium | 3.6% | 8.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee… | |
| CVE-2021-45485 | Medium | 3.6% | 7.5 | In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_co… | |
| CVE-2020-11111 | Medium | 3.6% | 8.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee… |
Page 1 of 3
Next →