CVE-2022-36991: High severity veritas flex appliance vulnerability
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily write content to a partially controlled path on a NetBackup Primary server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-36991?
CVE-2022-36991 is a vulnerability in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1, and related NetBackup products, where an attacker with authenticated access to a NetBackup Client could arbitrarily write content to a partially controlled path.
How severe is CVE-2022-36991?
CVE-2022-36991 has a severity score of 6.5, which is considered high.
Which software versions are affected by CVE-2022-36991?
Veritas NetBackup versions 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products) are affected by CVE-2022-36991.
What is the impact of CVE-2022-36991?
The impact of CVE-2022-36991 is that an attacker with authenticated access to a NetBackup Client can write arbitrary content to a partially controlled path.
Is there a fix for CVE-2022-36991?
Yes, Veritas has released patches to address this vulnerability. It is recommended to update to the latest version of Veritas NetBackup or apply the relevant security patches.