CVE-2022-36992: Critical severity veritas flex appliance vulnerability
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on a NetBackup Primary server (in specific notify conditions).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36992?
The severity of CVE-2022-36992 is critical with a score of 8.8.
How does CVE-2022-36992 affect Veritas NetBackup?
CVE-2022-36992 affects Veritas NetBackup versions 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1.
What is the affected software for CVE-2022-36992?
The affected software for CVE-2022-36992 includes Veritas NetBackup and related NetBackup products.
How can an attacker exploit CVE-2022-36992?
An attacker with authenticated access to a NetBackup Client can remotely execute arbitrary commands on a NetBackup Primary.
Is there a fix available for CVE-2022-36992?
Yes, Veritas has released patches to address CVE-2022-36992. Please refer to the Veritas Security Advisory for more information.