CVE-2022-42301: XEE
Published Oct 3, 2022
·Updated
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) injection attack through the nbars process.
Affected Software
1 affected component
Veritas NetBackup<=10.0.0.1
Remediation
Event History
Oct 3, 2022
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
DescriptionSeverity
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-42301.
2
Which products are affected by this vulnerability?
Veritas NetBackup through version 10.0.0.1 and related Veritas products are affected.
3
What is the severity of CVE-2022-42301?
The severity of CVE-2022-42301 is high with a CVSS score of 8.8.
4
What is the description of CVE-2022-42301?
CVE-2022-42301 is an XML External Entity (XXE) injection vulnerability in the NetBackup Primary server.
5
How can I fix the vulnerability CVE-2022-42301?
Veritas has released a security advisory with mitigation details at the following link: https://www.veritas.com/content/support/en_US/security/VTS22-013#M1