CVE-2022-36986: Critical severity veritas flex appliance vulnerability
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with unauthenticated access could remotely execute arbitrary commands on a NetBackup Primary server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36986?
The severity of CVE-2022-36986 is critical with a CVSS score of 9.8.
How does CVE-2022-36986 affect Veritas NetBackup?
CVE-2022-36986 affects Veritas NetBackup versions 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1.
Can an attacker execute arbitrary commands on a NetBackup Primary server?
Yes, an attacker with unauthenticated access can remotely execute arbitrary commands on a NetBackup Primary server.
What is the affected software for CVE-2022-36986?
The affected software for CVE-2022-36986 includes Veritas Flex Appliance versions 1.2, 1.3, 2.0, 2.0.1, 2.0.2, and 2.1, Veritas Flex Scale versions 1.3.1 and 2.1, and Veritas NetBackup versions 8.1.1, 8.1.2, 8.2, 8.3, 8.3.0.1, 8.3.0.2, 9.0, 9.0.0.1, 9.1, and 9.1.0.1.
How can I fix CVE-2022-36986?
To fix CVE-2022-36986, users should apply the necessary security patch provided by Veritas.