Skip to content
VulniPulse

NetApp OnCommand / Data Infrastructure Insights Vulnerabilities & Security Advisories

24 advisories tracked · NetApp Product Security Advisories (PSIRT) · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published NetApp advisory that VulniPulse classified as OnCommand / Data Infrastructure Insights, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 2 critical, 12 high, 10 medium.

Android app · Google Play

Monitor NetApp CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

NetApp Product Security Advisories (PSIRT)

Polled through NetApp Product Security's official advisory API. It supplies the canonical NTAP advisory ID, NetApp-calculated CVSS, affected and investigating products, remediation releases, workarounds and revision dates without relying on a third-party keyword search.

Latest NetApp OnCommand / Data Infrastructure Insights advisories

Medium6.3NetApp

Medium [CVE-2025-8885] Bouncy Castle Vulnerability in NetApp Products

Multiple NetApp products incorporate Bouncy Castle. Certain versions of Bouncy Castle are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Data Infrastructure Insights and Data Secure Storage Workload Security Agent, ONTAP tools for VMware vSphere 10, ONTAP tools for VMware vSphere 9. NetApp states there is no workaround available at this time.

CVE-2025-8885
Active IQ Unified ManagerONTAP tools for VMwareOnCommand / Data Infrastructure Insights
Sep 12, 2025
Medium5.9NetApp

Medium [CVE-2025-30761] Java Platform Standard Edition Vulnerability in NetApp Products

Multiple NetApp products incorporate Oracle Java Platform, Standard Edition (Java SE). Java SE versions 8u451, 8u451-perf, and 11.0.27 are susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Refer to “Oracle Critical Patch Update Advisory - July 2025” for additional details. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE. Affected products: Active IQ Unified Manager for VMware vSphere, OnCommand Insight. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-30761
Active IQ Unified ManagerOnCommand / Data Infrastructure Insights
Jul 24, 2025
Medium4.9NetApp

Medium [CVE-2025-53023] MySQL Server Vulnerability in NetApp Products

Multiple NetApp products incorporate MySQL Server. MySQL Server versions 8.0.0-8.0.42 are susceptible to a vulnerability which when successfully exploited could allow a high privileged attacker with network access via multiple protocols to compromise MySQL Server. Refer to “Oracle Critical Patch Update Advisory - July 2025”. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, OnCommand Insight, SnapCenter.

CVE-2025-53023
SnapCenterActive IQ Unified ManagerOnCommand / Data Infrastructure Insights
Jul 24, 2025
Medium5.3NetApp

Medium [CVE-2023-21971] MySQL Connector/J Vulnerability in NetApp Products

Multiple NetApp products incorporate Oracle MySQL Connectors. Certain MySQL versions are susceptible to a vulnerability that could allow high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized read access to a subset of MySQL Connectors accessible data. Refer to “Oracle Critical Patch Update Advisory - April 2023” for specific version details. Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, OnCommand Insight.

CVE-2023-21971
Active IQ Unified ManagerOnCommand / Data Infrastructure Insights
Apr 27, 2023

← All NetApp advisories