Vulnerabilities > Netapp > Ontap Tools > 10

DATE CVE VULNERABILITY TITLE RISK
2024-11-07 CVE-2024-38286 Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89.
network
low complexity
apache netapp
7.5
2024-10-28 CVE-2024-49761 REXML is an XML toolkit for Ruby.
network
low complexity
ruby-lang netapp
7.5
2024-07-05 CVE-2024-39689 Insufficient Verification of Data Authenticity vulnerability in multiple products
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts.
network
low complexity
certifi netapp CWE-345
7.5
2024-03-10 CVE-2024-28757 XML Entity Expansion vulnerability in multiple products
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
network
low complexity
libexpat-project fedoraproject netapp CWE-776
7.5
2024-03-07 CVE-2024-1351 Improper Certificate Validation vulnerability in multiple products
Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed.
network
low complexity
mongodb netapp CWE-295
critical
9.8