Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. NetApp/
  3. NetApp Backup and Recovery

NetApp Backup and Recovery

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 18 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Enterprise data storage platform with hybrid cloud mgmt & data services.

by NetApp · netapp.com · source ↗

Known CVEs (18)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2016-3063 ↗HIGH 7.52017

    Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users to execute arbitrary API calls via unspecified vec…

  • CVE-2016-1894 ↗HIGH 8.12017

    NetApp OnCommand Workflow Automation before 3.1P2 allows remote attackers to bypass authentication via unspecified vectors.

  • CVE-2016-1502 ↗HIGH 7.32017

    NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and delete backups via unspecified vectors.

  • CVE-2015-8544 ↗HIGH 7.52017

    NetApp SnapDrive for Windows before 7.0.2P4, 7.0.3, and 7.1 before 7.1.3P1 allows remote attackers to obtain sensitive information via unspecified vectors.

  • CVE-2015-8322 ↗HIGH 8.82017

    NetApp OnCommand System Manager 8.3.x before 8.3.2 allows remote authenticated users to execute arbitrary code via unspecified vectors.

  • CVE-2017-5600 ↗CRITICAL 9.82017

    The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default privileged account.

  • CVE-2016-7172 ↗HIGH 7.52016

    NetApp Snap Creator Framework before 4.3.1 discloses sensitive information which could be viewed by an unauthorized user.

  • CVE-2016-7171 ↗MEDIUM 5.62016

    NetApp Plug-in for Symantec NetBackup prior to version 2.0.1 makes use of a non-unique server certificate, making it vulnerable to impersonation.

  • CVE-2016-5047 ↗MEDIUM 6.52016

    NetApp OnCommand System Manager 8.3.x before 8.3.2P5 allows remote authenticated users to cause a denial of service via unspecified vectors.

  • CVE-2016-3064 ↗MEDIUM 6.52016

    NetApp Clustered Data ONTAP before 8.2.4P4 and 8.3.x before 8.3.2P2 allows remote authenticated users to obtain sensitive cluster and tenant information via unspecified vectors.

  • CVE-2016-1563 ↗MEDIUM 6.82016

    NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted…

  • CVE-2015-7886 ↗LOW 3.72016

    NetApp Data ONTAP before 8.2.4P1, when 7-Mode and HTTP access are enabled, allows remote attackers to obtain sensitive volume information via unspecified vectors.

  • CVE-2015-3292 ↗HIGH 10.02015

    The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary co…

  • CVE-2014-9354 ↗MEDIUM 4.02015

    NetApp OnCommand Balance before 4.2P3 allows local users to obtain sensitive information via unspecified vectors related to cleartext storage.

  • CVE-2014-9353 ↗HIGH 10.02015

    NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain privileges via unspecified vectors.

  • CVE-2008-3349 ↗HIGH 10.02008

    Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, cause a denial of service (system crash), …

  • CVE-2008-0960 ↗HIGH 10.02008

    SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 thr…

  • CVE-2006-3569 ↗MEDIUM 4.62006

    Unspecified vulnerability in NetApp Data ONTAP 7.0x through 7.0.4P8D9, 7.1x, 7.1.0.1x, and 7.2RC1, RC2, and RC3, as used in IBM N series Filers and other products, allows unauthorized users to gain ac…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Backup as a Service products

see all →
  • Acsense IAM Resilience Platform · Acsense
  • Ahsay Backup Amazon S3 · Ahsay Systems Corporation
  • Ahsay Backup Microsoft Azure · Ahsay Systems Corporation
  • Ahsay Google Workspace Backup · Ahsay Systems Corporation
  • Arcserve Cloud Cyber Resilient Storage · Arcserve
  • Arcserve Cyber Resilient Storage · Arcserve
  • Arpio · Arpio
  • AvePoint Products · AvePoint