CVE-2022-36949: Critical severity netbackup enterprise server vulnerability
Published Jul 27, 2022
·Updated
In Veritas NetBackup OpsCenter, an attacker with local access to a NetBackup OpsCenter server could potentially escalate their privileges. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
Affected Software
3 affected components
Veritas NetBackup>=8.0<8.3.0.2
Veritas NetBackup=9.0
Veritas NetBackup=9.1.0.0
Event History
Jul 27, 2022
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this Veritas NetBackup OpsCenter vulnerability?
The vulnerability ID for this Veritas NetBackup OpsCenter vulnerability is CVE-2022-36949.
2
What is the severity of CVE-2022-36949?
The severity of CVE-2022-36949 is critical with a CVSS score of 7.8.
3
Which versions of Veritas NetBackup OpsCenter are affected by CVE-2022-36949?
Versions 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10 are affected by CVE-2022-36949.
4
How can an attacker exploit this vulnerability?
An attacker with local access to a NetBackup OpsCenter server could potentially escalate their privileges.
5
Is there a fix for CVE-2022-36949 available?
Yes, Veritas has provided a fix for this vulnerability. Please refer to the Veritas security advisory for more information.