CVE-2022-42308: Path Traversal
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by leveraging a path traversal in the pbxexchange registration code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-42308?
CVE-2022-42308 is a vulnerability in Veritas NetBackup through version 8.2 and related Veritas products, allowing an attacker with local access to delete arbitrary files through a path traversal vulnerability in the pbx_exchange registration code.
How severe is CVE-2022-42308?
CVE-2022-42308 has a severity level of 7.1 (critical).
Which Veritas products are affected by CVE-2022-42308?
Veritas NetBackup through version 8.2 and related Veritas products are affected by CVE-2022-42308.
How can an attacker exploit CVE-2022-42308?
An attacker with local access can exploit CVE-2022-42308 by leveraging a path traversal vulnerability in the pbx_exchange registration code to delete arbitrary files.
Is there a fix available for CVE-2022-42308?
Yes, Veritas has released security advisories and patches to address CVE-2022-42308. It is recommended to update to the latest version or apply the available patches.