First published: Thu Jul 28 2022(Updated: )
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with unauthenticated access could remotely execute arbitrary commands on a NetBackup Primary server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas Flex Appliance | =1.2 | |
Veritas Flex Appliance | =1.3 | |
Veritas Flex Appliance | =2.0 | |
Veritas Flex Appliance | =2.0.1 | |
Veritas Flex Appliance | =2.0.2 | |
Veritas Flex Appliance | =2.1 | |
Veritas Flex Scale | =1.3.1 | |
Veritas Flex Scale | =2.1 | |
Veritas NetBackup | =8.1.1 | |
Veritas NetBackup | =8.1.2 | |
Veritas NetBackup | =8.2 | |
Veritas NetBackup | =8.3 | |
Veritas NetBackup | =8.3.0.1 | |
Veritas NetBackup | =8.3.0.2 | |
Veritas NetBackup | =9.0 | |
Veritas NetBackup | =9.0.0.1 | |
Veritas NetBackup | =9.1 | |
Veritas NetBackup | =9.1.0.1 | |
Veritas NetBackup Appliance | =3.1.1 | |
Veritas NetBackup Appliance | =3.1.2 | |
Veritas NetBackup Appliance | =3.2 | |
Veritas NetBackup Appliance | =4.0 | |
Veritas NetBackup Appliance | =4.1 | |
Veritas NetBackup Appliance | =3.2-maintenance_release1 | |
Veritas NetBackup Appliance | =3.2-maintenance_release2 | |
Veritas NetBackup Appliance | =3.2-maintenance_release3 | |
Veritas NetBackup Appliance | =3.3.0.1-maintenance_release1 | |
Veritas NetBackup Appliance | =3.3.0.1-maintenance_release2 | |
Veritas NetBackup Appliance | =3.3.0.2-maintenance_release1 | |
Veritas NetBackup Appliance | =3.3.0.2-maintenance_release2 | |
Veritas NetBackup Appliance | =4.0.0.1-maintenance_release1 | |
Veritas NetBackup Appliance | =4.0.0.1-maintenance_release2 | |
Veritas NetBackup Appliance | =4.0.0.1-maintenance_release3 | |
Veritas NetBackup Appliance | =4.1.0.1-maintenance_release1 | |
Veritas NetBackup Appliance | =4.1.0.1-maintenance_release2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-36986 is critical with a CVSS score of 9.8.
CVE-2022-36986 affects Veritas NetBackup versions 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1.
Yes, an attacker with unauthenticated access can remotely execute arbitrary commands on a NetBackup Primary server.
The affected software for CVE-2022-36986 includes Veritas Flex Appliance versions 1.2, 1.3, 2.0, 2.0.1, 2.0.2, and 2.1, Veritas Flex Scale versions 1.3.1 and 2.1, and Veritas NetBackup versions 8.1.1, 8.1.2, 8.2, 8.3, 8.3.0.1, 8.3.0.2, 9.0, 9.0.0.1, 9.1, and 9.1.0.1.
To fix CVE-2022-36986, users should apply the necessary security patch provided by Veritas.