Arbitrary File Write Vulnerability in Veritas NetBackup
CVE-2022-36991

8.1HIGH

Key Information:

Vendor
Veritas
Vendor
CVE Published:
28 July 2022

Summary

A vulnerability in Veritas NetBackup allows an attacker with authenticated access to the NetBackup Client to write arbitrary content to a controlled location on the NetBackup Primary server. This flaw affects multiple versions, enabling unauthorized manipulation of files, which can lead to potential exploitation of the underlying system. Administrators are urged to review configurations and apply necessary security updates to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-36991 : Arbitrary File Write Vulnerability in Veritas NetBackup | SecurityVulnerability.io