First published: Thu Jul 28 2022(Updated: )
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on a NetBackup Primary server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas Flex Appliance | =1.2 | |
Veritas Flex Appliance | =1.3 | |
Veritas Flex Appliance | =2.0 | |
Veritas Flex Appliance | =2.0.1 | |
Veritas Flex Appliance | =2.0.2 | |
Veritas Flex Appliance | =2.1 | |
Veritas Flex Scale | =1.3.1 | |
Veritas Flex Scale | =2.1 | |
NetBackup Enterprise Server | =8.1.1 | |
NetBackup Enterprise Server | =8.1.2 | |
NetBackup Enterprise Server | =8.2 | |
NetBackup Enterprise Server | =8.3 | |
NetBackup Enterprise Server | =8.3.0.1 | |
NetBackup Enterprise Server | =8.3.0.2 | |
NetBackup Enterprise Server | =9.0 | |
NetBackup Enterprise Server | =9.0.0.1 | |
NetBackup Enterprise Server | =9.1 | |
NetBackup Enterprise Server | =9.1.0.1 | |
Symantec NetBackup Appliance | =3.1.1 | |
Symantec NetBackup Appliance | =3.1.2 | |
Symantec NetBackup Appliance | =3.2 | |
Symantec NetBackup Appliance | =4.0 | |
Symantec NetBackup Appliance | =4.1 | |
Symantec NetBackup Appliance | =3.2-maintenance_release1 | |
Symantec NetBackup Appliance | =3.2-maintenance_release2 | |
Symantec NetBackup Appliance | =3.2-maintenance_release3 | |
Symantec NetBackup Appliance | =3.3.0.1-maintenance_release1 | |
Symantec NetBackup Appliance | =3.3.0.1-maintenance_release2 | |
Symantec NetBackup Appliance | =3.3.0.2-maintenance_release1 | |
Symantec NetBackup Appliance | =3.3.0.2-maintenance_release2 | |
Symantec NetBackup Appliance | =4.0.0.1-maintenance_release1 | |
Symantec NetBackup Appliance | =4.0.0.1-maintenance_release2 | |
Symantec NetBackup Appliance | =4.0.0.1-maintenance_release3 | |
Symantec NetBackup Appliance | =4.1.0.1-maintenance_release1 | |
Symantec NetBackup Appliance | =4.1.0.1-maintenance_release2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-36993 is high.
CVE-2022-36993 affects Veritas NetBackup versions 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1.
The risk of CVE-2022-36993 is the remote execution of arbitrary commands on a NetBackup Primary by an attacker with authenticated access to a NetBackup Client.
To fix CVE-2022-36993, it is recommended to update Veritas NetBackup to versions that are not affected by the vulnerability.
You can find more information about CVE-2022-36993 at the following link: [Veritas Security Advisory](https://www.veritas.com/content/support/en_US/security/VTS22-004#h1)