File Writing Vulnerability in Veritas NetBackup Solutions
CVE-2022-36987

8.5HIGH

Key Information:

Vendor

Veritas

Vendor
CVE Published:
28 July 2022

What is CVE-2022-36987?

A file writing vulnerability was identified in Veritas NetBackup ranging from versions 8.1.x through 9.1.x. This flaw allows an attacker with authenticated access to a NetBackup Client to write arbitrary files to the NetBackup Primary server. Exploiting this vulnerability could result in unauthorized data manipulation and compromise the integrity of the backup environment, highlighting a significant risk for organizations reliant on NetBackup for data protection. Proper security measures and regular updates are essential to mitigate potential threats associated with this vulnerability.

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.