CVE-2022-42307: XEE
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-42307?
CVE-2022-42307 is a vulnerability in Veritas NetBackup and related products, which allows for XML External Entity (XXE) Injection attacks on the NetBackup Primary server through the DiscoveryService service.
How severe is CVE-2022-42307?
CVE-2022-42307 has a severity rating of 9.8, which is considered critical.
Which software versions are affected by CVE-2022-42307?
Veritas NetBackup versions up to and including 10.0.0.1 are affected by CVE-2022-42307.
What is an XML External Entity (XXE) Injection attack?
An XML External Entity (XXE) Injection attack is a type of vulnerability that allows an attacker to exploit an XML parser by including malicious external entities.
Is there a fix for CVE-2022-42307?
Yes, Veritas has released a security advisory and a patch to address CVE-2022-42307. It is recommended to apply the patch as soon as possible.