cbcvebase.

Netapp Storagegrid vulnerabilities

44 known vulnerabilities affecting netapp/storagegrid.

Total CVEs
44
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH14MEDIUM18LOW11

Vulnerabilities

Page 2 of 3
CVE-2020-2781P4MEDIUMCVSS 5.3≥ 9.0.0, ≤ 9.0.42020-04-15
CVE-2020-2781 [MEDIUM] CVE-2020-2781: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supporte Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE, Java SE Embedded. Successful attacks of this vu
nvd
CVE-2025-26514P4MEDIUMCVSS 6.4fixed in 11.8.0.15≥ 11.9.0, < 11.9.0.8+1 more2025-09-19
CVE-2025-26514 [MEDIUM] CWE-79 CVE-2025-26514: StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptib StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability. Successful exploit could allow an attacker to view or modify configuration settings or add or modify user accounts but requires the attacker to know specific information about the target instance and th
nvd
CVE-2024-21984P4MEDIUMCVSS 6.9fixed in 11.7.0.8fixed in 11.82024-02-16
CVE-2024-21984 [MEDIUM] CWE-79 CVE-2024-21984: StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a difficult t StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a difficult to exploit Reflected Cross-Site Scripting (XSS) vulnerability. Successful exploit requires the attacker to know specific information about the target instance and trick a privileged user into clicking a specially crafted link. This could allow the attacke
nvd
CVE-2025-26516P4MEDIUMCVSS 5.3fixed in 11.8.0.15≥ 11.9.0, < 11.9.0.8+1 more2025-09-19
CVE-2025-26516 [MEDIUM] CWE-405 CVE-2025-26516: StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptib StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Denial of Service vulnerability. Successful exploit could allow an unauthenticated attacker to cause a Denial of Service on the Admin node.
nvd
CVE-2020-14556P4MEDIUMCVSS 4.8≥ 9.0.0, ≤ 9.0.42020-07-15
CVE-2020-14556 [MEDIUM] CVE-2020-14556: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2020-2800P4MEDIUMCVSS 4.8≥ 9.0.0, ≤ 9.0.42020-04-15
CVE-2020-2800 [MEDIUM] CVE-2020-2800: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweight HTT Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embed
nvd
CVE-2024-21988P4MEDIUMCVSS 5.3fixed in 11.7.0.9≥ 11.8.0, < 11.8.0.5+1 more2024-06-14
CVE-2024-21988 [MEDIUM] CWE-347 CVE-2024-21988: StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability in the SSH cryptographic implementation.
nvd
CVE-2022-23232P4MEDIUMCVSS 4.9fixed in 11.6.02022-03-04
CVE-2022-23232 [MEDIUM] CVE-2022-23232: StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerabil StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could allow disabled, expired, or locked external user accounts to access S3 data to which they previously had access. StorageGRID 11.6.0 obtains the user account status from Active Directory or Azure and will block S3 ac
nvd
CVE-2020-2767P4MEDIUMCVSS 4.8≥ 9.0.0, ≤ 9.0.42020-04-15
CVE-2020-2767 [MEDIUM] CVE-2020-2767: Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that ar Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to
nvd
CVE-2026-22051P4MEDIUMCVSS 4.3fixed in 11.9.0.13≥ 12.0, < 12.0.0.6+1 more2026-04-20
CVE-2026-22051 [MEDIUM] CWE-200 CVE-2026-22051: StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not have access to.
nvd
CVE-2018-2581P4MEDIUMCVSS 4.7≤ 9.0.42018-01-18
CVE-2018-2581 [MEDIUM] CVE-2018-2581: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the at
nvd
CVE-2020-16166P4LOWCVSS 3.7≤ 9.0.42020-07-30
CVE-2020-16166 [LOW] CWE-330 CVE-2020-16166: The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sen The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
nvd
CVE-2021-27006P4MEDIUMCVSS 4.4≥ 11.5.0, < 11.5.0.52021-12-23
CVE-2021-27006 [MEDIUM] CVE-2021-27006: StorageGRID (formerly StorageGRID Webscale) versions 11.5 prior to 11.5.0.5 are susceptible to a vul StorageGRID (formerly StorageGRID Webscale) versions 11.5 prior to 11.5.0.5 are susceptible to a vulnerability which may allow an administrative user to escalate their privileges and modify settings in SANtricity System Manager.
nvd
CVE-2020-2756P4LOWCVSS 3.7≥ 9.0.0, ≤ 9.0.42020-04-15
CVE-2020-2756 [LOW] CWE-502 CVE-2020-2756: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.
nvd
CVE-2020-2757P4LOWCVSS 3.7≥ 9.0.0, ≤ 9.0.42020-04-15
CVE-2020-2757 [LOW] CWE-502 CVE-2020-2757: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.
nvd
CVE-2020-14577P4LOWCVSS 3.7≥ 9.0.0, ≤ 9.0.42020-07-15
CVE-2020-14577 [LOW] CVE-2020-14577: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supporte Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Java SE Embedded. Successful attacks of this
nvd
CVE-2020-14581P4LOWCVSS 3.7≥ 9.0.0, ≤ 9.0.42020-07-15
CVE-2020-14581 [LOW] CVE-2020-14581: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of
nvd
CVE-2024-21994P4MEDIUMCVSS 4.3fixed in 11.9.02024-11-08
CVE-2024-21994 [MEDIUM] CWE-770 CVE-2024-21994: StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of Se StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead to a service crash.
nvd
CVE-2020-2754P4LOWCVSS 3.7≥ 9.0.0, ≤ 9.0.42020-04-15
CVE-2020-2754 [LOW] CVE-2020-2754: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Sup Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks
nvd
CVE-2020-14578P4LOWCVSS 3.7≥ 9.0.0, ≤ 9.0.42020-07-15
CVE-2020-14578 [LOW] CVE-2020-14578: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261 and 8u251; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of
nvd
Netapp Storagegrid vulnerabilities | cvebase