First published: Thu Jul 28 2022(Updated: )
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily read files from a NetBackup Primary server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas Flex Appliance | =1.2 | |
Veritas Flex Appliance | =1.3 | |
Veritas Flex Appliance | =2.0 | |
Veritas Flex Appliance | =2.0.1 | |
Veritas Flex Appliance | =2.0.2 | |
Veritas Flex Appliance | =2.1 | |
Veritas Flex Scale | =1.3.1 | |
Veritas Flex Scale | =2.1 | |
Veritas NetBackup | =8.1.1 | |
Veritas NetBackup | =8.1.2 | |
Veritas NetBackup | =8.2 | |
Veritas NetBackup | =8.3 | |
Veritas NetBackup | =8.3.0.1 | |
Veritas NetBackup | =8.3.0.2 | |
Veritas NetBackup | =9.0 | |
Veritas NetBackup | =9.0.0.1 | |
Veritas NetBackup | =9.1 | |
Veritas NetBackup | =9.1.0.1 | |
Veritas NetBackup Appliance | =3.1.1 | |
Veritas NetBackup Appliance | =3.1.2 | |
Veritas NetBackup Appliance | =3.2 | |
Veritas NetBackup Appliance | =4.0 | |
Veritas NetBackup Appliance | =4.1 | |
Veritas NetBackup Appliance | =3.2-maintenance_release1 | |
Veritas NetBackup Appliance | =3.2-maintenance_release2 | |
Veritas NetBackup Appliance | =3.2-maintenance_release3 | |
Veritas NetBackup Appliance | =3.3.0.1-maintenance_release1 | |
Veritas NetBackup Appliance | =3.3.0.1-maintenance_release2 | |
Veritas NetBackup Appliance | =3.3.0.2-maintenance_release1 | |
Veritas NetBackup Appliance | =3.3.0.2-maintenance_release2 | |
Veritas NetBackup Appliance | =4.0.0.1-maintenance_release1 | |
Veritas NetBackup Appliance | =4.0.0.1-maintenance_release2 | |
Veritas NetBackup Appliance | =4.0.0.1-maintenance_release3 | |
Veritas NetBackup Appliance | =4.1.0.1-maintenance_release1 | |
Veritas NetBackup Appliance | =4.1.0.1-maintenance_release2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-36994 is medium with a CVSS score of 6.5.
An attacker with authenticated access to a NetBackup Client could arbitrarily read files from a NetBackup Primary server.
Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 are affected by CVE-2022-36994.
Yes, Veritas Flex Appliance versions 1.2, 1.3, 2.0, 2.0.1, 2.0.2, and 2.1 are affected by CVE-2022-36994.
More information about CVE-2022-36994 can be found at [https://www.veritas.com/content/support/en_US/security/VTS22-004#m4].