Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Availability_orchestrator | Veeam | 4.0 (including) | 4.0 (including) |
| Disaster_recovery_orchestrator | Veeam | 5.0 (including) | 5.0 (including) |
| Recovery_orchestrator | Veeam | 6.0 (including) | 6.0 (including) |