CVE-2022-36993: High severity veritas flex appliance vulnerability
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on a NetBackup Primary server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36993?
The severity of CVE-2022-36993 is high.
How does CVE-2022-36993 affect Veritas NetBackup?
CVE-2022-36993 affects Veritas NetBackup versions 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1.
What is the risk of CVE-2022-36993?
The risk of CVE-2022-36993 is the remote execution of arbitrary commands on a NetBackup Primary by an attacker with authenticated access to a NetBackup Client.
How can I fix CVE-2022-36993?
To fix CVE-2022-36993, it is recommended to update Veritas NetBackup to versions that are not affected by the vulnerability.
Where can I find more information about CVE-2022-36993?
You can find more information about CVE-2022-36993 at the following link: [Veritas Security Advisory](https://www.veritas.com/content/support/en_US/security/VTS22-004#h1)