Netapp
Netapp Clustered Data Ontap: vulnerabilidades y CVE
Netapp Clustered Data Ontap tiene 187 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 28 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE187
Últimos 12 meses0
Críticas28
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-40438 | Crítica (9) | 100% | ⚠ Explotación activa | 16 sept 2021 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-38477 | Alta (7.5) | 3.2% | — | 1 jul 2024 | null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue. |
| CVE-2024-38476 | Crítica (9.8) | 42% | — | 1 jul 2024 | Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users… |
| CVE-2024-38474 | Crítica (9.8) | 2.5% | — | 1 jul 2024 | Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source… |
| CVE-2024-21985 | Alta (7.6) | 0.33% | — | 26 ene 2024 | ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authenticated user with multiple remote accounts with differing roles to perform… |
| CVE-2024-21982 | Media (6.5) | 0.37% | — | 12 ene 2024 | ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when the object-store profiler command is… |
| CVE-2023-27314 | Alta (7.5) | 0.64% | — | 12 oct 2023 | ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to cause a crash of the HTTP service. |
| CVE-2023-36054 | Media (6.5) | 2.8% | — | 7 ago 2023 | lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because… |
| CVE-2023-3107 | Alta (7.5) | 0.65% | — | 1 ago 2023 | A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a… |
| CVE-2023-38403 | Alta (7.5) | 2.0% | — | 17 jul 2023 | iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. |
| CVE-2023-2953 | Alta (7.5) | 1.9% | — | 30 may 2023 | A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. |
| CVE-2023-28322 | Baja (3.7) | 2.2% | — | 26 may 2023 | An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the… |
| CVE-2023-28321 | Media (5.9) | 1.8% | — | 26 may 2023 | An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use… |
| CVE-2023-28320 | Media (5.9) | 2.7% | — | 26 may 2023 | A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows… |
| CVE-2023-28319 | Alta (7.5) | 2.5% | — | 26 may 2023 | A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the… |
| CVE-2023-27538 | Media (5.5) | 1.3% | — | 30 mar 2023 | An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse.… |
| CVE-2023-27537 | Media (5.9) | 1.9% | — | 30 mar 2023 | A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no… |
| CVE-2023-27533 | Alta (8.8) | 2.0% | — | 30 mar 2023 | A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The… |
| CVE-2023-23916 | Media (6.5) | 1.7% | — | 23 feb 2023 | An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and… |
| CVE-2023-23915 | Media (6.5) | 0.86% | — | 23 feb 2023 | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support,… |
| CVE-2023-23914 | Crítica (9.1) | 0.86% | — | 23 feb 2023 | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed… |
| CVE-2022-35260 | Media (6.5) | 1.8% | — | 5 dic 2022 | curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the… |
| CVE-2022-32221 | Crítica (9.8) | 4.4% | — | 5 dic 2022 | When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was… |
| CVE-2022-40304 | Alta (7.8) | 5.8% | — | 23 nov 2022 | An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. |
| CVE-2022-40303 | Alta (7.5) | 41% | — | 23 nov 2022 | An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an… |
| CVE-2022-3602 | Alta (7.5) | 91% | — | 1 nov 2022 | A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed… |
| CVE-2022-23241 | Alta (8.1) | 0.75% | — | 19 oct 2022 | Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerability which could allow an authenticated remote attacker to arbitrarily modify or delete WORM data… |
| CVE-2022-35252 | Baja (3.7) | 2.4% | — | 23 sept 2022 | When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing… |
| CVE-2022-32208 | Media (5.9) | 7.5% | — | 7 jul 2022 | When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to… |
| CVE-2022-32207 | Crítica (9.8) | 7.7% | — | 7 jul 2022 | When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename… |
| CVE-2022-32206 | Media (6.5) | 33% | — | 7 jul 2022 | curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this… |
Otros productos de Netapp
Oncommand Insight · 971Active IQ Unified Manager · 848Oncommand Workflow Automation · 743Snapcenter · 575Cloud Backup · 349H700s Firmware · 293H300s Firmware · 292H410s Firmware · 292H500s Firmware · 292E-series Santricity OS Controller · 242H410c Firmware · 240Steelstore Cloud Integrated Storage · 211