CVE-2024-28222: Path Traversal
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28222?
CVE-2024-28222 is considered a high-severity vulnerability due to the potential for unauthenticated file uploads and execution.
How do I fix CVE-2024-28222?
To fix CVE-2024-28222, users should upgrade to Veritas NetBackup version 8.1.2 or later, and NetBackup Appliance version 3.1.2 or later.
What does CVE-2024-28222 affect?
CVE-2024-28222 affects Veritas NetBackup versions prior to 8.1.2 and Veritas NetBackup Appliance versions prior to 3.1.2.
Who is affected by CVE-2024-28222?
Any organization using the vulnerable versions of Veritas NetBackup or NetBackup Appliance could potentially be affected by CVE-2024-28222.
What is the impact of CVE-2024-28222?
The impact of CVE-2024-28222 includes the ability for an unauthenticated attacker to upload and execute arbitrary files on the affected systems.