CVE-2022-45461: OS Command Injection
Published Nov 17, 2022
·Updated
The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root.
Affected Software
6 affected components
Veritas NetBackup<=10.1
Linux Linux kernel
Opengroup Unix
All of the following
Veritas NetBackup<=10.1
Any of the following
Linux Linux kernel
Opengroup Unix
Event History
Nov 17, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-45461.
2
What is the severity of CVE-2022-45461?
The severity of CVE-2022-45461 is high with a severity value of 8.8.
3
Which products are affected by CVE-2022-45461?
Veritas NetBackup through version 10.1 and related Veritas products on Linux and UNIX are affected by CVE-2022-45461.
4
Who can exploit this vulnerability?
Authenticated non-root users who have been explicitly added to the auth.conf file can exploit this vulnerability.
5
How can the vulnerability CVE-2022-45461 be fixed?
To fix CVE-2022-45461, it is recommended to update to the latest version of Veritas NetBackup and related Veritas products.