CVE-2022-36988: High severity veritas flex appliance vulnerability
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup OpsCenter server, NetBackup Primary server, or NetBackup Media server could remotely execute arbitrary commands on a NetBackup Primary server or NetBackup Media server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-36988?
CVE-2022-36988 is a vulnerability in Veritas NetBackup and related products that allows an attacker with authenticated access to a server to execute arbitrary commands as root.
Which versions of Veritas NetBackup and related products are affected by CVE-2022-36988?
Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 are affected.
What is the severity level of CVE-2022-36988?
The severity level of CVE-2022-36988 is high, with a CVSS score of 8.8.
How can an attacker exploit CVE-2022-36988?
An attacker with authenticated access to a NetBackup OpsCenter server, NetBackup Primary server, or NetBackup Media server can exploit CVE-2022-36988 to execute arbitrary commands as root.
Where can I find more information about CVE-2022-36988?
More information about CVE-2022-36988 can be found at the following reference: [Veritas Security Advisory VTS22-004](https://www.veritas.com/content/support/en_US/security/VTS22-004#h6)