CVE-2022-36997: SSRF
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger impacts that include arbitrary file read, Server-Side Request Forgery (SSRF), and denial of service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36997?
The severity of CVE-2022-36997 is high.
How does CVE-2022-36997 impact Veritas NetBackup?
CVE-2022-36997 allows an attacker with authenticated access to a NetBackup Client to remotely trigger impacts that include arbitrary file read.
What software versions are affected by CVE-2022-36997?
Versions 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 of Veritas NetBackup (and related NetBackup products) are affected by CVE-2022-36997.
How do I fix CVE-2022-36997?
To fix CVE-2022-36997, it is recommended to upgrade to the latest version of Veritas NetBackup.
Where can I find more information about CVE-2022-36997?
More information about CVE-2022-36997 can be found at the following reference: [link](https://www.veritas.com/content/support/en_US/security/VTS22-004#h9)