First published: Mon Oct 03 2022(Updated: )
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by leveraging a path traversal in the pbx_exchange registration code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas NetBackup | <=8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42308 is a vulnerability in Veritas NetBackup through version 8.2 and related Veritas products, allowing an attacker with local access to delete arbitrary files through a path traversal vulnerability in the pbx_exchange registration code.
CVE-2022-42308 has a severity level of 7.1 (critical).
Veritas NetBackup through version 8.2 and related Veritas products are affected by CVE-2022-42308.
An attacker with local access can exploit CVE-2022-42308 by leveraging a path traversal vulnerability in the pbx_exchange registration code to delete arbitrary files.
Yes, Veritas has released security advisories and patches to address CVE-2022-42308. It is recommended to update to the latest version or apply the available patches.