SQL Injection Vulnerability in Veritas NetBackup Server
CVE-2022-42302

9CRITICAL

Key Information:

Vendor
Veritas
Status
Vendor
CVE Published:
3 October 2022

Summary

A vulnerability has been identified in Veritas NetBackup, specifically affecting versions up to 10.0. The NetBackup Primary server can be exploited through a SQL Injection attack on the NBFSMCLIENT service, potentially compromising sensitive data and system integrity. It is crucial for users to apply necessary security updates and implement measures to secure their environments from this type of threat.

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.