CVE-2022-42304: SQL Injection
Published Oct 3, 2022
·Updated
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting idm, nbars, and SLP manager code.
Affected Software
1 affected component
Veritas NetBackup<=10.0
Remediation
Event History
Oct 3, 2022
CVE Published
via MITRE·02:48 PM
Data Sourced
via MITRE·02:48 PM
DescriptionSeverity
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-42304?
CVE-2022-42304 is a vulnerability discovered in Veritas NetBackup through 10.0 and related Veritas products.
2
What is the severity of CVE-2022-42304?
The severity of CVE-2022-42304 is critical, with a CVSS score of 9.8.
3
What software is affected by CVE-2022-42304?
Veritas NetBackup versions up to and including 10.0 are affected by CVE-2022-42304.
4
How does CVE-2022-42304 impact the NetBackup Primary server?
CVE-2022-42304 exposes the NetBackup Primary server to a SQL Injection attack affecting idm, nbars, and SLP manager code.
5
Is there a fix available for CVE-2022-42304?
Yes, Veritas has released a security advisory with instructions on how to patch the vulnerability. Please refer to the Veritas support website for detailed information.