First published: Wed Jul 27 2022(Updated: )
In Veritas NetBackup, the NetBackup Client allows arbitrary command execution from any remote host that has access to a valid host-id NetBackup certificate/private key from the same domain. The affects 9.0.x through 9.0.0.1 and 9.1.x through 9.1.0.1.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas NetBackup | =9.0 | |
Veritas NetBackup | =9.1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Veritas NetBackup vulnerability is CVE-2022-36956.
The severity level of the CVE-2022-36956 vulnerability is critical with a severity value of 7.5.
The versions 9.0.x through 9.0.0.1 and 9.1.x through 9.1.0.1 of Veritas NetBackup are affected by CVE-2022-36956.
Arbitrary command execution can be performed in Veritas NetBackup by any remote host that has access to a valid host-id NetBackup certificate/private key from the same domain.
Please refer to the Veritas Security Advisory for information on available fixes for CVE-2022-36956.