SQL Injection Vulnerability in Veritas NetBackup and Related Products
CVE-2022-42304

8HIGH

Key Information:

Vendor
Veritas
Status
Vendor
CVE Published:
3 October 2022

Summary

A vulnerability exists in Veritas NetBackup and related products that allows an attacker to exploit SQL Injection vulnerabilities through the NetBackup Primary server. This can impact components such as idm, nbars, and SLP manager code, potentially leading to unauthorized access and manipulation of sensitive data.

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.