{"status":"success","advisory":{"_id":"683547255b16347a91c39d9e","kb_acknowledgements":null,"kb_affected_list":["NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in)","SnapCenter"],"kb_bad_data":false,"kb_cve":["CVE-2007-2379","CVE-2010-5312","CVE-2011-4969","CVE-2016-7103"],"kb_exploitation":"Public","kb_fixes":[{"product":"NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in)","fixes":[],"instructions":null,"wontfix":true,"eos_link":"https://mysupport.netapp.com/info/communications/ECMLP2848905.html"},{"product":"SnapCenter","fixes":[{"link":"https://mysupport.netapp.com/NOW/download/software/snapcenter/4.1/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null}],"kb_impact":"Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information or addition or modification of data.","kb_internal_notes":[{"burt":"1187632","jira":"","product":"7-Mode Transition Tool"},{"burt":"1187641","jira":"","product":"Active IQ Unified Manager for Linux"},{"burt":"1187643","jira":"","product":"Active IQ Unified Manager for Microsoft Windows"},{"burt":"1187642","jira":"","product":"Active IQ Unified Manager for VMware vSphere"},{"burt":"1187636","jira":"","product":"Data ONTAP operating in 7-Mode"},{"burt":"1187639","jira":"","product":"NetApp Cloud Backup (formerly AltaVault)"},{"burt":"1187633","jira":"","product":"NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in)"},{"burt":"1187637","jira":"","product":"NetApp SMI-S Provider"},{"burt":"1187640","jira":"","product":"NetApp VASA Provider for Clustered Data ONTAP 9.7 and above"},{"burt":"1187646","jira":"","product":"Snap Creator Framework"},{"burt":"1137813","jira":"","product":"SnapCenter"},{"burt":"1187638","jira":"","product":"Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above"},{"burt":"1187647","jira":"","product":"StorageGRID (formerly StorageGRID Webscale)"},{"burt":"1187653","jira":"","product":"System Manager 9.x"}],"kb_investigating_list":[],"kb_num":"9010000","kb_ref":["https://www.npmjs.com/advisories/127"],"kb_rev_history":[{"comment":"Initial Public Release","date":"20190416","version":"1.0"},{"comment":"After additional review, SnapCenter added to Software Versions and Fixes","date":"20190805","version":"2.0"},{"comment":"Cloud Central moved to Products Not Affected","date":"20190813","version":"3.0"},{"comment":"NetApp Cloud Backup (formerly AltaVault) moved to Products Not Affected","date":"20210426","version":"4.0"},{"comment":"NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in) moved to Won't Fix status, Final status","date":"20240102","version":"5.0"}],"kb_revised_list":[],"kb_scoring":{"CVE-2007-2379":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","CVE-2010-5312":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","CVE-2011-4969":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","CVE-2016-7103":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"kb_scoring_calc":[{"cve_id":"CVE-2007-2379","range":"MEDIUM","score":5.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"cve_id":"CVE-2010-5312","range":"MEDIUM","score":5.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"cve_id":"CVE-2011-4969","range":"MEDIUM","score":5.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"cve_id":"CVE-2016-7103","range":"MEDIUM","score":6.1,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"kb_status":"Final","kb_summary":"Multiple NetApp products incorporate jQuery. Versions of jQuery before 1.12.0 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.","kb_title":"September 2018 jQuery Vulnerabilities in NetApp Products","kb_unaffected_list":["7-Mode Transition Tool","Active IQ Unified Manager for Linux","Active IQ Unified Manager for Microsoft Windows","Active IQ Unified Manager for VMware vSphere","Brocade Fabric Operating System Firmware","Data ONTAP operating in 7-Mode","E-Series SANtricity OS Controller Software 11.x","E-Series SANtricity Unified Manager and Web Services Proxy","Element Plug-in for vCenter Server","FAS/AFF BIOS - 8300/8700/A400/C400","FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750","Host Utilities - SAN for Linux","Host Utilities - SAN for Windows","MetroCluster Tiebreaker for clustered Data ONTAP","NetApp BlueXP","NetApp Cloud Backup (formerly AltaVault)","NetApp Converged Systems Advisor Agent","NetApp HCI Compute Node (Bootstrap OS)","NetApp HCI Compute Node BIOS","NetApp Manageability SDK","NetApp NFS Plug-in for VMware VAAI","NetApp ONTAP PowerShell Toolkit (PSTK)","NetApp SMI-S Provider","NetApp SolidFire & HCI Management Node","NetApp SolidFire & HCI Storage Node (Element Software)","NetApp VASA Provider for Clustered Data ONTAP 9.7 and above","ONTAP 9 (formerly Clustered Data ONTAP)","ONTAP Antivirus Connector","ONTAP Select Deploy administration utility","OnCommand Insight","OnCommand Workflow Automation","Single Mailbox Recovery","Snap Creator Framework","SnapManager for Hyper-V","Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above","StorageGRID (formerly StorageGRID Webscale)","StorageGRID Baseboard Management Controller (BMC) - SG6060/SG6160/SGF6024/SGF6112/SG100/SG110/SG1000/SG1100","System Manager 9.x"],"kb_workarounds":"None at this time.","ntap_advisory_id":"NTAP-20190416-0007","adv_id":"ntap-20190416-0007","published_date":"2019-04-16T00:00:00","updated_date":"2024-01-02T00:00:00","inserted_date":"2025-05-27T05:01:25.198000","modified_date":null}}