First published: Mon Oct 03 2022(Updated: )
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas NetBackup | <=10.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42307 is a vulnerability in Veritas NetBackup and related products, which allows for XML External Entity (XXE) Injection attacks on the NetBackup Primary server through the DiscoveryService service.
CVE-2022-42307 has a severity rating of 9.8, which is considered critical.
Veritas NetBackup versions up to and including 10.0.0.1 are affected by CVE-2022-42307.
An XML External Entity (XXE) Injection attack is a type of vulnerability that allows an attacker to exploit an XML parser by including malicious external entities.
Yes, Veritas has released a security advisory and a patch to address CVE-2022-42307. It is recommended to apply the patch as soon as possible.