CVE-2016-7399: Command Injection
scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3, and 3.0.x allow remote attackers to execute arbitrary commands via shell metacharacters in the hostName parameter to appliancews/getLicense.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7399?
CVE-2016-7399 has a high severity level as it allows remote attackers to execute arbitrary commands.
How do I fix CVE-2016-7399?
To fix CVE-2016-7399, upgrade the Vernitas NetBackup Appliance to a version that is not affected by this vulnerability.
What versions of Veritas NetBackup Appliance are affected by CVE-2016-7399?
CVE-2016-7399 affects Veritas NetBackup Appliance firmware versions 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3, and 3.0.x.
Can CVE-2016-7399 be exploited without authentication?
Yes, CVE-2016-7399 can be exploited by remote attackers without requiring authentication.
What is the impact of exploiting CVE-2016-7399?
Exploiting CVE-2016-7399 can lead to unauthorized command execution on the affected Veritas NetBackup Appliance.