CVE-2022-36998: Buffer Overflow
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a stack-based buffer overflow on the NetBackup Primary server, resulting in a denial of service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-36998.
What is the severity level of CVE-2022-36998?
The severity level of CVE-2022-36998 is medium with a score of 6.5.
Which products are affected by this vulnerability?
Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products) are affected by this vulnerability.
What is the CWE ID associated with this vulnerability?
The CWE ID associated with this vulnerability are 119 and 787.
How can I fix CVE-2022-36998?
To fix CVE-2022-36998, it is recommended to update Veritas NetBackup and related NetBackup products to the latest version available, as provided by the vendor.