CVE-2024-22021: Medium severity VEEAM Availability Orchestrator vulnerability
Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22021?
CVE-2024-22021 is classified as a moderate severity vulnerability.
How do I fix CVE-2024-22021?
To fix CVE-2024-22021, ensure that users have the appropriate permissions and roles assigned within Veeam Recovery Orchestrator.
Who is affected by CVE-2024-22021?
CVE-2024-22021 affects users with the Plan Author role in Veeam Recovery Orchestrator, allowing them unauthorized access to plans.
What versions are impacted by CVE-2024-22021?
CVE-2024-22021 impacts Veeam Availability Orchestrator 4.0, Veeam Disaster Recovery Orchestrator 5.0, and Veeam Recovery Orchestrator 6.0.
What actions can an attacker take due to CVE-2024-22021?
An attacker exploiting CVE-2024-22021 can retrieve plans from a scope they are not assigned to, potentially compromising sensitive operations.