CVE-2022-36984: High severity veritas flex appliance vulnerability
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a denial of service attack against a NetBackup Primary server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36984?
The severity of CVE-2022-36984 is high with a CVSS score of 6.5.
How can an attacker exploit CVE-2022-36984?
An attacker with authenticated access to a NetBackup Client can remotely trigger a denial of service attack against a NetBackup server.
Which versions of Veritas NetBackup are affected by CVE-2022-36984?
Veritas NetBackup versions 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products) are affected by CVE-2022-36984.
How do I fix the vulnerability CVE-2022-36984?
Update Veritas NetBackup to versions that are not affected by CVE-2022-36984 or apply the necessary patches or security updates provided by Veritas.
Where can I find more information about CVE-2022-36984?
More information about CVE-2022-36984 can be found on the Veritas support website at https://www.veritas.com/content/support/en_US/security/VTS22-004#h8.