Unsigned File Vulnerability in Veritas NetBackup IT Analytics
CVE-2023-28818
5.3MEDIUM
What is CVE-2023-28818?
A significant vulnerability exists in Veritas NetBackup IT Analytics 11 prior to version 11.2.0, where the application’s upgrade process incorporates unsigned files. This flaw allows malicious actors to exploit the system, potentially leading to the installation of rogue components. By leveraging this vulnerability, attackers could introduce unauthorized Collector executable files, specifically aptare.jar or upgrademanager.zip, onto the Portal server. These malicious files might subsequently be downloaded and deployed onto collectors, posing severe security risks to users and the integrity of the IT Analytics environment.