First published: Thu Nov 17 2022(Updated: )
The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas NetBackup | <=10.1 | |
Linux Linux kernel | ||
Opengroup Unix | ||
All of | ||
Veritas NetBackup | <=10.1 | |
Any of | ||
Linux Linux kernel | ||
Opengroup Unix |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-45461.
The severity of CVE-2022-45461 is high with a severity value of 8.8.
Veritas NetBackup through version 10.1 and related Veritas products on Linux and UNIX are affected by CVE-2022-45461.
Authenticated non-root users who have been explicitly added to the auth.conf file can exploit this vulnerability.
To fix CVE-2022-45461, it is recommended to update to the latest version of Veritas NetBackup and related Veritas products.