CVE Vulnerabilities

CVE-2022-36991

Published: Jul 28, 2022 | Modified: Aug 09, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily write content to a partially controlled path on a NetBackup Primary server.

Affected Software

Name Vendor Start Version End Version
Flex_appliance Veritas 1.2 (including) 1.2 (including)
Flex_appliance Veritas 1.3 (including) 1.3 (including)
Flex_appliance Veritas 2.0 (including) 2.0 (including)
Flex_appliance Veritas 2.0.1 (including) 2.0.1 (including)
Flex_appliance Veritas 2.0.2 (including) 2.0.2 (including)
Flex_appliance Veritas 2.1 (including) 2.1 (including)
Flex_scale Veritas 1.3.1 (including) 1.3.1 (including)
Flex_scale Veritas 2.1 (including) 2.1 (including)
Netbackup Veritas 8.1.1 (including) 8.1.1 (including)
Netbackup Veritas 8.1.2 (including) 8.1.2 (including)
Netbackup Veritas 8.2 (including) 8.2 (including)
Netbackup Veritas 8.3 (including) 8.3 (including)
Netbackup Veritas 8.3.0.1 (including) 8.3.0.1 (including)
Netbackup Veritas 8.3.0.2 (including) 8.3.0.2 (including)
Netbackup Veritas 9.0 (including) 9.0 (including)
Netbackup Veritas 9.0.0.1 (including) 9.0.0.1 (including)
Netbackup Veritas 9.1 (including) 9.1 (including)
Netbackup Veritas 9.1.0.1 (including) 9.1.0.1 (including)
Netbackup_appliance Veritas 3.1.1 (including) 3.1.1 (including)
Netbackup_appliance Veritas 3.1.2 (including) 3.1.2 (including)
Netbackup_appliance Veritas 3.2 (including) 3.2 (including)
Netbackup_appliance Veritas 4.0 (including) 4.0 (including)
Netbackup_appliance Veritas 4.1 (including) 4.1 (including)
Netbackup_appliance Veritas 3.2-maintenance_release1 (including) 3.2-maintenance_release1 (including)
Netbackup_appliance Veritas 3.2-maintenance_release2 (including) 3.2-maintenance_release2 (including)
Netbackup_appliance Veritas 3.2-maintenance_release3 (including) 3.2-maintenance_release3 (including)
Netbackup_appliance Veritas 3.3.0.1-maintenance_release1 (including) 3.3.0.1-maintenance_release1 (including)
Netbackup_appliance Veritas 3.3.0.1-maintenance_release2 (including) 3.3.0.1-maintenance_release2 (including)
Netbackup_appliance Veritas 3.3.0.2-maintenance_release1 (including) 3.3.0.2-maintenance_release1 (including)
Netbackup_appliance Veritas 3.3.0.2-maintenance_release2 (including) 3.3.0.2-maintenance_release2 (including)
Netbackup_appliance Veritas 4.0.0.1-maintenance_release1 (including) 4.0.0.1-maintenance_release1 (including)
Netbackup_appliance Veritas 4.0.0.1-maintenance_release2 (including) 4.0.0.1-maintenance_release2 (including)
Netbackup_appliance Veritas 4.0.0.1-maintenance_release3 (including) 4.0.0.1-maintenance_release3 (including)
Netbackup_appliance Veritas 4.1.0.1-maintenance_release1 (including) 4.1.0.1-maintenance_release1 (including)
Netbackup_appliance Veritas 4.1.0.1-maintenance_release2 (including) 4.1.0.1-maintenance_release2 (including)

References