CVE-2022-36950: Critical severity netbackup enterprise server vulnerability
Published Jul 27, 2022
·Updated
In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may be able to perform remote command execution through a Java classloader manipulation. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
Affected Software
3 affected components
Veritas NetBackup>=8.0<8.3.0.2
Veritas NetBackup=9.0
Veritas NetBackup=9.1.0.0
Event History
Jul 27, 2022
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-36950.
2
What is the severity of CVE-2022-36950?
The severity of CVE-2022-36950 is critical with a severity value of 9.8.
3
Which software is affected by CVE-2022-36950?
Veritas NetBackup versions 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10 are affected by CVE-2022-36950.
4
How can an attacker exploit CVE-2022-36950?
An attacker can exploit CVE-2022-36950 by performing remote command execution through Java classloader manipulation.
5
Is there a fix available for CVE-2022-36950?
Yes, Veritas has released security patches to address this vulnerability. Please refer to the Veritas security advisory for more information.