Latest netapp storagegrid Vulnerabilities

Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)
Netapp Storagegrid>=11.6.0<=11.6.0.13
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to to a crash of the Local Distributi...
Netapp Storagegrid<11.6.0.8
Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerability which could al...
Netapp Storagegrid>=11.6.0<11.6.0.3
Canonical Ubuntu Linux=16.04
CentOS CentOS=7.9
Linux Linux kernel<4.7
Redhat Enterprise Linux Server=7.9
A security vulnerability was found in zlib. The flaw triggered a heap-based buffer in inflate in the inflate.c function via a large gzip header extra field. This flaw is only applicable in the call in...
redhat/zlib<0:1.2.7-21.el7_9
redhat/zlib<0:1.2.11-19.el8_6
redhat/rsync<0:3.1.3-19.el8
redhat/zlib<0:1.2.11-32.el9_0
redhat/rsync<0:3.2.3-18.el9
debian/zlib<=1:1.2.11.dfsg-1<=1:1.2.11.dfsg-4<=1:1.2.11.dfsg-2+deb11u1
and 63 more
An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients.
Linux Linux kernel>=4.18<=4.19
Netapp Active Iq Unified Manager Vmware Vsphere
Netapp Cloud Volumes Ontap Mediator
NetApp E-Series SANtricity OS Controller>=11.0<=11.70.2
Netapp Element Software
Netapp Hci Management Node
and 20 more
A flaw was found in OpenSSL. It is possible to trigger an infinite loop by crafting a certificate that has invalid elliptic curve parameters. Since certificate parsing happens before verification of t...
redhat/jbcs-httpd24-apr-util<0:1.6.1-91.el8
redhat/jbcs-httpd24-curl<0:7.78.0-3.el8
redhat/jbcs-httpd24-httpd<0:2.4.37-80.el8
redhat/jbcs-httpd24-nghttp2<0:1.39.2-41.el8
redhat/jbcs-httpd24-openssl<1:1.1.1g-11.el8
redhat/jbcs-httpd24-openssl-chil<0:1.0.0-11.el8
and 84 more
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS) of the Local Distributio...
Netapp Storagegrid<11.6.0
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could allow disabled, expired, or locked external user account...
Netapp Storagegrid<11.6.0
A flaw was found in the elliptic package of the crypto library in golang when the IsOnCurve function could return true for invalid field elements. This flaw allows an attacker to take advantage of thi...
redhat/go<1.17.7
redhat/go<1.16.14
redhat/openshift-serverless-clients<0:1.1.0-3.el8
redhat/servicemesh<0:2.1.3-1.el8
redhat/servicemesh-operator<0:2.1.3-2.el8
redhat/servicemesh-prometheus<0:2.23.0-7.el8
and 21 more
An unspecified error with not treating branches with semantic-version names as releases in cmd/go in Golang Go has an unknown impact and attack vector.
Golang Go<1.16.14
Golang Go>=1.17.0<1.17.7
Netapp Beegfs Csi Driver
Netapp Cloud Insights Telegraf Agent
Netapp Kubernetes Monitoring Operator
Netapp Storagegrid
and 17 more
A flaw was found in the big package of the math library in golang. The Rat.SetString could cause an overflow, and if left unhandled, it could lead to excessive memory use. This issue could allow a rem...
IBM Cloud Pak for Security<=1.10.0.0 - 1.10.11.0
IBM QRadar Suite Software<=1.10.12.0 - 1.10.16.0
Golang Go<1.16.14
Golang Go>=1.17.0<1.17.7
Netapp Beegfs Csi Driver
Netapp Cloud Insights Telegraf Agent
and 14 more
StorageGRID (formerly StorageGRID Webscale) versions 11.5 prior to 11.5.0.5 are susceptible to a vulnerability which may allow an administrative user to escalate their privileges and modify settings i...
Netapp Storagegrid>=11.5.0<11.5.0.5
Apache HTTP Server-Side Request Forgery (SSRF)
Apache HTTP server<=2.4.48
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Debian Debian Linux=9.0
Debian Debian Linux=10.0
and 27 more
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).
redhat/httpd<2.4.49
redhat/jbcs-httpd24-httpd<0:2.4.51-28.el8
redhat/jbcs-httpd24-httpd<0:2.4.51-28.el7
redhat/httpd24-httpd<0:2.4.34-23.el7.5
debian/apache2
debian/uwsgi<=2.0.18-1<=2.0.19.1-7.1<=2.0.21-5.1<=2.0.22-4
and 20 more
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affec...
Apache HTTP server<=2.4.48
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
and 16 more
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
redhat/jbcs-httpd24-apr<0:1.6.3-107.el8
redhat/jbcs-httpd24-apr-util<0:1.6.1-84.el8
redhat/jbcs-httpd24-curl<0:7.78.0-2.el8
redhat/jbcs-httpd24-httpd<0:2.4.37-78.el8
redhat/jbcs-httpd24-nghttp2<0:1.39.2-39.el8
redhat/jbcs-httpd24-openssl<1:1.1.1g-8.el8
and 38 more
Golang Go is vulnerable to a denial of service, caused by the failure to properly assert that the type of public key in an X.509 certificate matches the expected type in the crypto/tls package. By per...
Golang Go<1.15.14
Golang Go>=1.16.0<1.16.6
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Netapp Cloud Insights Telegraf
Netapp Storagegrid
and 30 more
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it...
rust/openssl-src<111.15.0
debian/openssl
IBM Cognos Analytics<=12.0.0-12.0.1
IBM Cognos Analytics<=11.2.0-11.2.4 FP2
IBM Cognos Analytics<=11.1.1-11.1.7 FP7
OpenSSL OpenSSL>=1.1.1<1.1.1k
and 202 more
OpenSSL could allow a remote attacker to bypass security restrictions, caused by a missing check in the validation logic of X.509 certificate chains by the X509_V_FLAG_X509_STRICT flag. By using any v...
rust/openssl-src>=111.11.0<111.15.0
IBM Security Verify Access<=10.0.0
OpenSSL OpenSSL>=1.1.1h<1.1.1k
FreeBSD FreeBSD=12.2
FreeBSD FreeBSD=12.2-p1
FreeBSD FreeBSD=12.2-p2
and 52 more
Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, c...
redhat/openshift-serverless-clients<0:0.20.0-6.el8
redhat/openshift-serverless-clients<0:0.20.0-7.el8
Golang Go<1.14.14
Golang Go>=1.15<1.15.7
Microsoft Windows
Fedoraproject Fedora=33
and 2 more
An unspecified error with the P224() Curve implementation can generate incorrect outputs in Golang Go has an unknown impact and attack vector.
debian/golang-1.11
debian/golang-1.15
redhat/go<1.15.7
redhat/go<1.14.14
redhat/heketi<0:10.4.0-2.el7
redhat/openshift-serverless-clients<0:0.20.0-6.el8
and 20 more
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is relate...
redhat/kernel-alt<0:4.14.0-115.32.1.el7a
redhat/kernel-rt<0:4.18.0-240.8.1.rt7.62.el8_3
redhat/kernel<0:4.18.0-240.8.1.el8_3
redhat/kernel<0:4.18.0-147.38.1.el8_1
redhat/kernel-rt<0:4.18.0-193.37.1.rt13.87.el8_2
redhat/kernel<0:4.18.0-193.37.1.el8_2
and 122 more
Oracle Java Runtime Environment HTML Rendering Out-Of-Bounds Write Remote Code Execution Vulnerability
Oracle Java Runtime Environment
Oracle JDK=1.8.0-update251
Oracle JRE=1.8.0-update251
NetApp 7-Mode Transition Tool
Netapp Active Iq Unified Manager Windows>=7.3
Netapp Active Iq Unified Manager Vsphere>=9.5
and 13 more
A flaw was found in the way the JSSE component of OpenJDK performed TLS server name verification. The HostnameChecker class did not check if names stored in TLS server's X.509 certificate are in the ...
redhat/java<1.8.0-openjdk-1:1.8.0.262.b10-0.el6_10
redhat/java<1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el6_10
redhat/java<1.8.0-openjdk-1:1.8.0.262.b10-0.el7_8
redhat/java<11-openjdk-1:11.0.8.10-0.el7_8
redhat/java<1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el7
redhat/java<1.8.0-ibm-1:1.8.0.6.20-1jpp.1.el7
and 56 more
An unspecified vulnerability in Oracle Java SE and Java SE Embedded related to the 2D component could allow an unauthenticated attacker to obtain sensitive information resulting in a low confidentiali...
ubuntu/openjdk-8<8
ubuntu/openjdk-8<8
ubuntu/openjdk-8<8
ubuntu/openjdk-8<8
ubuntu/openjdk-8<8
ubuntu/openjdk-8<8
and 54 more
A flaw was found in the way the ForkJoinPool class in the Libraries component of OpenJDK handled its access control context. This could possibly lead to code being executed with incorrect permissions...
redhat/java<1.8.0-openjdk-1:1.8.0.262.b10-0.el6_10
redhat/java<1.8.0-openjdk-1:1.8.0.262.b10-0.el7_8
redhat/java<11-openjdk-1:11.0.8.10-0.el7_8
redhat/java<1.8.0-ibm-1:1.8.0.6.20-1jpp.1.el7
redhat/java<11-openjdk-1:11.0.8.10-0.el8_2
redhat/java<1.8.0-openjdk-1:1.8.0.262.b10-0.el8_2
and 53 more
A flaw was found in the DerValue class in the Libraries component of OpenJDK. An incorrect implementation of the DerValue.equals() method could cause the class to raise an exception not declared to b...
redhat/java<1.8.0-openjdk-1:1.8.0.262.b10-0.el6_10
redhat/java<1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el6_10
redhat/java<1.8.0-openjdk-1:1.8.0.262.b10-0.el7_8
redhat/java<1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el7
redhat/java<1.8.0-ibm-1:1.8.0.6.20-1jpp.1.el7
redhat/java<1.8.0-openjdk-1:1.8.0.262.b10-0.el8_2
and 46 more
A flaw was found in the way the imaging library in the 2D component of OpenJDK performed affine transformations of images. An untrusted Java application or applet could use this flaw to bypass certai...
redhat/java<1.8.0-openjdk-1:1.8.0.262.b10-0.el6_10
redhat/java<1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el6_10
redhat/java<1.8.0-openjdk-1:1.8.0.262.b10-0.el7_8
redhat/java<11-openjdk-1:11.0.8.10-0.el7_8
redhat/java<1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el7
redhat/java<1.8.0-ibm-1:1.8.0.6.20-1jpp.1.el7
and 56 more
A flaw was found in the DerInputStream class in the Libraries component of OpenJDK. A DER (Distinguished Encoding Rules) encoded input using indefinite length encoding not supported by the DerInputSt...
redhat/java<1.8.0-openjdk-1:1.8.0.262.b10-0.el6_10
redhat/java<1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el6_10
redhat/java<1.8.0-openjdk-1:1.8.0.262.b10-0.el7_8
redhat/java<1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el7
redhat/java<1.8.0-ibm-1:1.8.0.6.20-1jpp.1.el7
redhat/java<1.8.0-openjdk-1:1.8.0.262.b10-0.el8_2
and 46 more
An unspecified vulnerability in Java SE related to the Libraries component could allow an unauthenticated attacker to cause low confidentiality impact, low integrity impact, and no availability impact...
redhat/java<1.8.0-openjdk-1:1.8.0.262.b10-0.el6_10
redhat/java<1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el6_10
redhat/java<1.8.0-openjdk-1:1.8.0.262.b10-0.el7_8
redhat/java<11-openjdk-1:11.0.8.10-0.el7_8
redhat/java<1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el7
redhat/java<1.8.0-ibm-1:1.8.0.6.20-1jpp.1.el7
and 56 more
Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Easily exploitable vulnerability allows unauthenticated attac...
redhat/java<11-openjdk-1:11.0.7.10-4.el7_8
redhat/java<11-openjdk-1:11.0.7.10-1.el8_1
redhat/java<11-openjdk-1:11.0.7.10-1.el8_0
ubuntu/openjdk-14<14.0.1+7-1ubuntu1
ubuntu/openjdk-14<14.0.1+7-1
ubuntu/openjdk-lts<11.0.7+10-2ubuntu2~18.04
and 121 more
Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Difficult to exploit vulnerability allows unauthenticated att...
redhat/java<11-openjdk-1:11.0.7.10-4.el7_8
redhat/java<11-openjdk-1:11.0.7.10-1.el8_1
redhat/java<11-openjdk-1:11.0.7.10-1.el8_0
debian/openjdk-11
ubuntu/openjdk-14<14.0.1+7-1ubuntu1
ubuntu/openjdk-14<14.0.1+7-1
and 122 more
An unspecified vulnerability in multiple Oracle products could allow an unauthenticated attacker to take control of the system.
redhat/java<1.8.0-openjdk-1:1.8.0.252.b09-2.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.1.el6_10
redhat/java<1.7.1-ibm-1:1.7.1.4.65-1jpp.1.el6_10
redhat/java<1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.2.el7_8
redhat/java<11-openjdk-1:11.0.7.10-4.el7_8
and 148 more
An unspecified vulnerability in Java SE related to the Java SE JSSE component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown ...
redhat/java<1.8.0-openjdk-1:1.8.0.252.b09-2.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.1.el6_10
redhat/java<1.7.1-ibm-1:1.7.1.4.65-1jpp.1.el6_10
redhat/java<1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.2.el7_8
redhat/java<11-openjdk-1:11.0.7.10-4.el7_8
and 166 more
An unspecified vulnerability in Java SE related to the Java SE Libraries component could allow an unauthenticated attacker to take control of the system.
redhat/java<1.8.0-openjdk-1:1.8.0.252.b09-2.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.1.el6_10
redhat/java<1.7.1-ibm-1:1.7.1.4.65-1jpp.1.el6_10
redhat/java<1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.2.el7_8
redhat/java<11-openjdk-1:11.0.7.10-4.el7_8
and 148 more
Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Difficult to exploit vulnerability allows unauthenticated att...
redhat/java<11-openjdk-1:11.0.7.10-4.el7_8
redhat/java<11-openjdk-1:11.0.7.10-1.el8_1
redhat/java<11-openjdk-1:11.0.7.10-1.el8_0
debian/openjdk-11
ubuntu/openjdk-14<14.0.1+7-1ubuntu1
ubuntu/openjdk-14<14.0.1+7-1
and 122 more
An unspecified vulnerability in Java SE related to the Java SE Concurrency component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using u...
redhat/java<1.8.0-openjdk-1:1.8.0.252.b09-2.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.1.el6_10
redhat/java<1.7.1-ibm-1:1.7.1.4.65-1jpp.1.el6_10
redhat/java<1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.2.el7_8
redhat/java<11-openjdk-1:11.0.7.10-4.el7_8
and 152 more
An unspecified vulnerability in Java SE related to the Java SE Lightweight HTTP Server component could allow an unauthenticated attacker to cause low confidentiality impact, low integrity impact, and ...
redhat/java<1.8.0-openjdk-1:1.8.0.252.b09-2.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.1.el6_10
redhat/java<1.7.1-ibm-1:1.7.1.4.65-1jpp.1.el6_10
redhat/java<1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.2.el7_8
redhat/java<11-openjdk-1:11.0.7.10-4.el7_8
and 148 more
An unspecified vulnerability in Java SE related to the Java SE Security component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unkn...
redhat/java<1.8.0-openjdk-1:1.8.0.252.b09-2.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.1.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.2.el7_8
redhat/java<11-openjdk-1:11.0.7.10-4.el7_8
redhat/java<1.8.0-openjdk-1:1.8.0.252.b09-2.el7_8
redhat/java<1.8.0-ibm-1:1.8.0.6.25-1jpp.1.el7
and 157 more
An unspecified vulnerability in Java SE related to the Java SE Serialization component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using...
redhat/java<1.8.0-openjdk-1:1.8.0.252.b09-2.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.1.el6_10
redhat/java<1.7.1-ibm-1:1.7.1.4.65-1jpp.1.el6_10
redhat/java<1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.2.el7_8
redhat/java<11-openjdk-1:11.0.7.10-4.el7_8
and 157 more
An unspecified vulnerability in Java SE related to the Java SE Serialization component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using...
redhat/java<1.8.0-openjdk-1:1.8.0.252.b09-2.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.1.el6_10
redhat/java<1.7.1-ibm-1:1.7.1.4.65-1jpp.1.el6_10
redhat/java<1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el6_10
redhat/java<1.7.0-openjdk-1:1.7.0.261-2.6.22.2.el7_8
redhat/java<11-openjdk-1:11.0.7.10-4.el7_8
and 156 more
An unspecified vulnerability in Java SE related to the Java SE Scripting component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unk...
redhat/java<1.8.0-openjdk-1:1.8.0.252.b09-2.el6_10
redhat/java<1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el6_10
redhat/java<11-openjdk-1:11.0.7.10-4.el7_8
redhat/java<1.8.0-openjdk-1:1.8.0.252.b09-2.el7_8
redhat/java<1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el7
redhat/java<11-openjdk-1:11.0.7.10-1.el8_1
and 151 more
An unspecified vulnerability in Java SE related to the Java SE Scripting component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unk...
redhat/java<1.8.0-openjdk-1:1.8.0.252.b09-2.el6_10
redhat/java<1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el6_10
redhat/java<11-openjdk-1:11.0.7.10-4.el7_8
redhat/java<1.8.0-openjdk-1:1.8.0.252.b09-2.el7_8
redhat/java<1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el7
redhat/java<11-openjdk-1:11.0.7.10-1.el8_1
and 143 more
StorageGRID (formerly StorageGRID Webscale) versions 10.0.0 through 11.3 prior to 11.2.0.8 and 11.3.0.4 are susceptible to a vulnerability which allows an unauthenticated remote attacker to cause a De...
Netapp Storagegrid>=10.0.0<11.2.0.8
Netapp Storagegrid>=11.3<11.3.0.4
OpenSSL could allow a remote attacker to obtain sensitive information, caused by the failure to immediately close the TCP connection after the hosts encounter a zero-length record with valid padding. ...
redhat/openssl<0:1.0.1e-58.el6_10
redhat/openssl<1:1.0.2k-19.el7
redhat/jws5-ecj<0:4.12.0-1.redhat_1.1.el6
redhat/jws5-javapackages-tools<0:3.4.1-5.15.11.el6
redhat/jws5-jboss-logging<0:3.3.2-1.Final_redhat_00001.1.el6
redhat/jws5-tomcat<0:9.0.21-10.redhat_4.1.el6
and 226 more

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203