First published: Wed Jul 27 2022(Updated: )
In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may be able to perform remote command execution through a Java classloader manipulation. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas NetBackup | >=8.0<8.3.0.2 | |
Veritas NetBackup | =9.0 | |
Veritas NetBackup | =9.1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-36950.
The severity of CVE-2022-36950 is critical with a severity value of 9.8.
Veritas NetBackup versions 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10 are affected by CVE-2022-36950.
An attacker can exploit CVE-2022-36950 by performing remote command execution through Java classloader manipulation.
Yes, Veritas has released security patches to address this vulnerability. Please refer to the Veritas security advisory for more information.