Skip to content
VulniPulse

NetApp OnCommand / Data Infrastructure Insights Vulnerabilities & Security Advisories

34 advisories tracked · NetApp Product Security Advisories (PSIRT) · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published NetApp advisory that VulniPulse classified as OnCommand / Data Infrastructure Insights, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 5 critical, 17 high, 12 medium.

Android app · Google Play

Monitor NetApp CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Source

NetApp Product Security Advisories (PSIRT)

Polled through NetApp Product Security's official advisory API. It supplies the canonical NTAP advisory ID, NetApp-calculated CVSS, affected and investigating products, remediation releases, workarounds and revision dates without relying on a third-party keyword search.

Latest NetApp OnCommand / Data Infrastructure Insights advisories

Medium6.8NetApp

Medium [CVE-2026-60589 +2] August 2026 Java SE Vulnerabilities in NetApp Products

Java SE versions 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, and 26.0.2 are susceptible to vulnerabilities that allow unauthenticated attackers with network access via multiple protocols (including HTTP and TLS) to compromise Oracle Java SE. Refer to “Oracle Critical Security Patch Update Advisory - August 2026” for additional details. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE accessible data, unauthorized access to critical data or complete access to all Oracle Java SE accessible data or unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Data Infrastructure Insights and Data Secure Storage Workload Security Agent, E-Series SANtricity OS Controller Software, E-Series SANtricity Unified Manager and Web Services Proxy, OnCommand Insight, SANtricity Storage Plugin for vCenter. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status.

CVE-2026-60589CVE-2026-61308CVE-2026-70907
SANtricityActive IQ Unified ManagerOnCommand / Data Infrastructure Insights
Aug 21, 2026
Medium6.9NetApp

Medium [CVE-2026-34478] Apache Log4j Vulnerability in NetApp Products

Apache Log4j versions 2.21.0 through 2.25.3 and 3.0.0-alpha1 through 3.0.0-beta3 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. Affected products: Data Infrastructure Insights and Data Secure Storage Workload Security Agent. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-34478
OnCommand / Data Infrastructure Insights
Jul 10, 2026
Medium6.5NetApp

Medium [CVE-2026-27145] Golang Vulnerability in NetApp Products

Multiple NetApp products incorporate Golang. Golang versions through 1.25.10 and 1.26.0 through 1.26.3 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data, Denial of Service (DoS). Affected products: Data Infrastructure Insights Telegraf Agent, NetApp Kubernetes Monitoring Operator, Trident, Trident Protect. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-27145
Trident / AstraOnCommand / Data Infrastructure InsightsNetApp tools & integrations
Jun 19, 2026
Medium4.7NetApp

Medium [CVE-2026-40977] Spring Boot Vulnerability in NetApp Products

Multiple NetApp products incorporate Spring Boot. Certain versions of Spring Boot are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS). Affected products: Data Infrastructure Insights and Data Secure Storage Workload Security Agent. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-40977
OnCommand / Data Infrastructure Insights
Jun 5, 2026
Medium4.9NetApp

Medium [CVE-2026-34267 +2] April 2026 MySQL Server 8.0.0 Vulnerabilities in NetApp Products

Multiple NetApp products incorporate MySQL. MySQL versions 8.0.0 through 8.0.45 are susceptible to a vulnerability that could allow a high privileged attacker with network access via multiple protocols to compromise MySQL Server. Refer to “Oracle Critical Patch Update Advisory - April 2026” for additional details. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, OnCommand Insight. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status.

CVE-2026-34267CVE-2026-34278CVE-2026-34293
Active IQ Unified ManagerOnCommand / Data Infrastructure Insights
Apr 29, 2026
Medium6.3NetApp

Medium [CVE-2025-68161] Apache Log4j Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache Log4j. Apache Log4j versions 2.0-beta9 through 2.25.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: Data Infrastructure Insights and Data Secure Storage Workload Security Agent, NetApp Manageability SDK. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-68161
OnCommand / Data Infrastructure Insights
Jan 23, 2026
Medium5.3NetApp

Medium [CVE-2025-58181] Golang Vulnerability in NetApp Products

Multiple NetApp products incorporate Golang. Golang/x/crypto/ssh versions prior to 0.45.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Astra Control Center, Data Infrastructure Insights Telegraf Agent. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-58181
Trident / AstraOnCommand / Data Infrastructure Insights
Dec 19, 2025
Medium6.3NetApp

Medium [CVE-2025-8885] Bouncy Castle Vulnerability in NetApp Products

Multiple NetApp products incorporate Bouncy Castle. Certain versions of Bouncy Castle are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Data Infrastructure Insights and Data Secure Storage Workload Security Agent, ONTAP tools for VMware vSphere 10, ONTAP tools for VMware vSphere 9. NetApp states there is no workaround available at this time.

CVE-2025-8885
Active IQ Unified ManagerONTAP tools for VMwareOnCommand / Data Infrastructure Insights
Sep 12, 2025
Medium5.9NetApp

Medium [CVE-2025-30761] Java Platform Standard Edition Vulnerability in NetApp Products

Multiple NetApp products incorporate Oracle Java Platform, Standard Edition (Java SE). Java SE versions 8u451, 8u451-perf, and 11.0.27 are susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Refer to “Oracle Critical Patch Update Advisory - July 2025” for additional details. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE. Affected products: Active IQ Unified Manager for VMware vSphere, OnCommand Insight. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-30761
Active IQ Unified ManagerOnCommand / Data Infrastructure Insights
Jul 24, 2025
Medium4.9NetApp

Medium [CVE-2025-53023] MySQL Server Vulnerability in NetApp Products

Multiple NetApp products incorporate MySQL Server. MySQL Server versions 8.0.0-8.0.42 are susceptible to a vulnerability which when successfully exploited could allow a high privileged attacker with network access via multiple protocols to compromise MySQL Server. Refer to “Oracle Critical Patch Update Advisory - July 2025”. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, OnCommand Insight, SnapCenter.

CVE-2025-53023
SnapCenterActive IQ Unified ManagerOnCommand / Data Infrastructure Insights
Jul 24, 2025
Medium6.5NetApp

Medium [CVE-2025-50077 +21] July 2025 MySQL Vulnerabilities in NetApp Products

Multiple NetApp products incorporate MySQL Server. MySQL Server versions 8.0.0 through 8.0.42, 8.4.0 through 8.4.5, and 9.0.0 through 9.3.0 are susceptible to vulnerabilities which when successfully exploited could allow privileged and unauthenticated attackers with network access via multiple protocols or a high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Refer to “Oracle Critical Patch Update Advisory - July 2025” for additional details. Successful attacks of these vulnerabilities can result in unauthorized ability to cause a partial denial of service (partial Dos), complete denial of service (complete DOS), or unauthorized creation, deletion or modification access to critical data or all MySQL Server accessible data. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, OnCommand Insight, SnapCenter. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status.

CVE-2025-50077CVE-2025-50078CVE-2025-50079+19
SnapCenterActive IQ Unified ManagerOnCommand / Data Infrastructure Insights
Jul 24, 2025
Medium5.3NetApp

Medium [CVE-2023-21971] MySQL Connector/J Vulnerability in NetApp Products

Multiple NetApp products incorporate Oracle MySQL Connectors. Certain MySQL versions are susceptible to a vulnerability that could allow high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized read access to a subset of MySQL Connectors accessible data. Refer to “Oracle Critical Patch Update Advisory - April 2023” for specific version details. Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, OnCommand Insight.

CVE-2023-21971
Active IQ Unified ManagerOnCommand / Data Infrastructure Insights
Apr 27, 2023

← All NetApp advisories