« Back to list

Netapp

Netapp Ontap 9: vulnerabilities and CVEs

Netapp Ontap 9 has 7 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 1 are listed by CISA as actively exploited.

CVEs7
Last 12 months0
Critical1
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-38475Critical (9.1)100%⚠ Active exploitationJul 1, 2024
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-53580High (7.5)0.92%—Dec 18, 2024
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
CVE-2024-6119High (7.5)67%—Sep 3, 2024
Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process.…
CVE-2024-38475Critical (9.1)100%⚠ Active exploitationJul 1, 2024
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly…
CVE-2024-26461High (7.5)1.1%—Feb 29, 2024
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
CVE-2024-26458Medium (5.3)0.81%—Feb 29, 2024
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
CVE-2023-27535Medium (5.9)1.6%—Mar 30, 2023
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in…
CVE-2022-42915High (8.1)3.1%—Oct 29, 2022
curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then…

Other products by Netapp