Netapp Storagegrid vulnerabilities
44 known vulnerabilities affecting netapp/storagegrid.
Total CVEs
44
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH14MEDIUM18LOW11
Vulnerabilities
Page 1 of 3
CVE-2016-3427P1CRITICALCVSS 9.8KEVPoC≤ 9.0.42016-04-21
CVE-2016-3427 [CRITICAL] CWE-284 CVE-2016-3427: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRocki
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
nvd
CVE-2020-2803P3HIGHCVSS 8.3≥ 9.0.0, ≤ 9.0.42020-04-15
CVE-2020-2803 [HIGH] CVE-2020-2803: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2025-26515P3HIGHCVSS 7.5fixed in 11.8.0.15≥ 11.9.0, < 11.9.0.8+1 more2025-09-19
CVE-2025-26515 [HIGH] CWE-918 CVE-2025-26515: StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without Singl
StorageGRID (formerly
StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without
Single Sign-on enabled are susceptible to a Server-Side Request Forgery
(SSRF) vulnerability. Successful exploit could allow an unauthenticated
attacker to change the password of any Grid Manager or Tenant Manager
non-federated user.
nvd
CVE-2020-14664P3HIGHCVSS 8.3≥ 9.0.0, ≤ 9.0.42020-07-15
CVE-2020-14664 [HIGH] CVE-2020-14664: Vulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version th
Vulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while t
nvd
CVE-2020-2805P3HIGHCVSS 8.3≥ 9.0.0, ≤ 9.0.42020-04-15
CVE-2020-2805 [HIGH] CVE-2020-2805: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2020-14583P3HIGHCVSS 8.3≥ 9.0.0, ≤ 9.0.42020-07-15
CVE-2020-14583 [HIGH] CVE-2020-14583: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Succe
nvd
CVE-2020-2816P3HIGHCVSS 7.5≥ 9.0.0, ≤ 9.0.42020-04-15
CVE-2020-2816 [HIGH] CVE-2020-2816: Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that ar
Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification acc
nvd
CVE-2018-2638P3HIGHCVSS 8.3≤ 9.0.42018-01-18
CVE-2018-2638 [HIGH] CVE-2018-2638: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versi
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the atta
nvd
CVE-2020-14593P3HIGHCVSS 7.4≥ 9.0.0, ≤ 9.0.42020-07-15
CVE-2020-14593 [HIGH] CVE-2020-14593: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful atta
nvd
CVE-2019-1559P3MEDIUMCVSS 5.9≥ 9.0.0, ≤ 9.0.42019-02-27
CVE-2019-1559 [MEDIUM] CWE-203 CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to sen
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behave
nvd
CVE-2026-22048P3HIGHCVSS 7.1fixed in 11.9.0.12≥ 12.0.0.0, < 12.0.0.42026-02-18
CVE-2026-22048 [HIGH] CWE-918 CVE-2026-22048: StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sig
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configurati
nvd
CVE-2020-8571P3HIGHCVSS 7.5≥ 10.0.0, < 11.2.0.8≥ 11.3, < 11.3.0.4+1 more2020-03-13
CVE-2020-8571 [HIGH] CVE-2020-8571: StorageGRID (formerly StorageGRID Webscale) versions 10.0.0 through 11.3 prior to 11.2.0.8 and 11.3.
StorageGRID (formerly StorageGRID Webscale) versions 10.0.0 through 11.3 prior to 11.2.0.8 and 11.3.0.4 are susceptible to a vulnerability which allows an unauthenticated remote attacker to cause a Denial of Service (DoS).
nvd
CVE-2023-27318P3HIGHCVSS 7.5≥ 11.6.0, ≤ 11.6.0.132024-02-05
CVE-2023-27318 [HIGH] CWE-248 CVE-2023-27318: StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.13 are susceptible to a
StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through
11.6.0.13 are susceptible to a Denial of Service (DoS) vulnerability. A
successful exploit could lead to a crash of the Local Distribution
Router (LDR) service.
nvd
CVE-2022-23238P3MEDIUMCVSS 6.5≥ 11.6.0, < 11.6.0.32022-08-10
CVE-2022-23238 [MEDIUM] CVE-2022-23238: Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 de
Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to view limited metrics information and modify alert email recipients and content.
nvd
CVE-2022-38734P3HIGHCVSS 7.5fixed in 11.6.0.82023-03-02
CVE-2022-38734 [HIGH] CWE-400 CVE-2022-38734: StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial o
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to to a crash of the Local Distribution Router (LDR) service.
nvd
CVE-2022-23233P4HIGHCVSS 7.5fixed in 11.6.02022-03-04
CVE-2022-23233 [HIGH] CVE-2022-23233: StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerabil
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS) of the Local Distribution Router (LDR) service.
nvd
CVE-2018-2627P4HIGHCVSS 7.5≤ 9.0.42018-01-18
CVE-2018-2627 [HIGH] CVE-2018-2627: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versio
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks require human interaction from a person other th
nvd
CVE-2025-26517P4MEDIUMCVSS 5.4fixed in 11.8.0.15≥ 11.9.0, < 11.9.0.8+1 more2025-09-19
CVE-2025-26517 [MEDIUM] CWE-266 CVE-2025-26517: StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptib
StorageGRID (formerly
StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are
susceptible to a privilege escalation vulnerability. Successful exploit
could allow an unauthorized authenticated attacker to discover Grid node
names and IP addresses or modify Storage Grades.
nvd
CVE-2024-21983P4MEDIUMCVSS 6.5fixed in 11.7.0.8fixed in 11.82024-02-16
CVE-2024-21983 [MEDIUM] CWE-248 CVE-2024-21983: StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a Denial of S
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8
are susceptible to a Denial of Service (DoS) vulnerability. Successful
exploit by an authenticated attacker could lead to an out of memory
condition or node reboot.
nvd
CVE-2020-2830P4MEDIUMCVSS 5.3≥ 9.0.0, ≤ 9.0.42020-04-15
CVE-2020-2830 [MEDIUM] CVE-2020-2830: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). S
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successfu
nvd
1 / 3Next →