Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Availability_orchestrator | Veeam | 4.0 (including) | 4.0 (including) |
Disaster_recovery_orchestrator | Veeam | 5.0 (including) | 5.0 (including) |
Recovery_orchestrator | Veeam | 6.0 (including) | 6.0 (including) |