SQL Injection Vulnerability in Veritas NetBackup Products
CVE-2022-42303

8HIGH

Key Information:

Vendor
Veritas
Status
Vendor
CVE Published:
3 October 2022

Summary

A significant SQL Injection vulnerability has been identified in Veritas NetBackup and associated products. The NetBackup Primary server is particularly susceptible to a second-order SQL injection attack through the NBFSMCLIENT service. This vulnerability can be exploited by an attacker by leveraging a related vulnerability, CVE-2022-42302, further amplifying potential risks. Organizations using affected versions of Veritas NetBackup should take immediate action to remediate this security flaw to protect their data and systems.

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.