CVE-2021-41570: XSS
Published Apr 19, 2022
·Updated
Veritas NetBackup OpsCenter Analytics 9.1 allows XSS via the NetBackup Master Server Name, Display Name, NetBackup User Name, or NetBackup Password field during a Settings/Configuration Add operation.
Affected Software
2 affected components
Veritas NetBackup>=8.2.0<9.0.0.1
Veritas NetBackup=9.1
Event History
Apr 19, 2022
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
Description
Frequently Asked Questions
1
What is CVE-2021-41570?
CVE-2021-41570 is a vulnerability in Veritas NetBackup OpsCenter Analytics 9.1 that allows cross-site scripting (XSS) attacks.
2
How does CVE-2021-41570 occur?
CVE-2021-41570 occurs when user input is not properly validated or sanitized, allowing an attacker to inject malicious scripts.
3
What is the severity of CVE-2021-41570?
The severity of CVE-2021-41570 is medium, with a CVSS score of 5.4.
4
What software versions are affected by CVE-2021-41570?
Veritas NetBackup versions 8.2.0 through 9.0.0.1 are affected, as well as version 9.1.
5
How can I fix CVE-2021-41570?
To fix CVE-2021-41570, it is recommended to update Veritas NetBackup OpsCenter Analytics to the latest version and apply any available patches.