First published: Mon Oct 03 2022(Updated: )
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) injection attack through the nbars process.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas NetBackup | <=10.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-42301.
Veritas NetBackup through version 10.0.0.1 and related Veritas products are affected.
The severity of CVE-2022-42301 is high with a CVSS score of 8.8.
CVE-2022-42301 is an XML External Entity (XXE) injection vulnerability in the NetBackup Primary server.
Veritas has released a security advisory with mitigation details at the following link: https://www.veritas.com/content/support/en_US/security/VTS22-013#M1