CVE-2022-36987: High severity veritas flex appliance vulnerability
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily write files to a NetBackup Primary server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-36987?
CVE-2022-36987 is an issue discovered in Veritas NetBackup and related products that allows an attacker with authenticated access to write files to a NetBackup Primary server.
Which versions of Veritas NetBackup are affected by CVE-2022-36987?
Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products) are affected.
What is the severity of CVE-2022-36987?
CVE-2022-36987 has a severity rating of 6.5 (high).
How can an attacker exploit CVE-2022-36987?
An attacker with authenticated access to a NetBackup Client can exploit CVE-2022-36987 by writing arbitrary files to a NetBackup Primary server.
Is there a fix for CVE-2022-36987?
To fix CVE-2022-36987, it is recommended to upgrade to the latest version of Veritas NetBackup and related products.