First published: Fri May 03 2024(Updated: )
A vulnerability was discovered in the Alta Recovery Vault feature of Veritas NetBackup before 10.4 and NetBackup Appliance before 5.4. By design, only the cloud administrator should be able to disable the retention lock of Governance mode images. This vulnerability allowed a NetBackup administrator to modify the expiration of backups under Governance mode (which could cause premature deletion).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas NetBackup | <10.4 | |
Veritas NetBackup Appliance Firmware | <5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34404 has been classified with a high severity rating due to its potential to compromise data retention controls.
To fix CVE-2024-34404, upgrade to Veritas NetBackup version 10.4 or later and Veritas NetBackup Appliance version 5.4 or later.
CVE-2024-34404 affects Veritas NetBackup versions prior to 10.4 and Veritas NetBackup Appliance versions prior to 5.4.
The impact of CVE-2024-34404 allows unauthorized NetBackup administrators to disable retention lock on Governance mode images, risking data integrity.
There is no known workaround for CVE-2024-34404; upgrading to the patched versions is recommended.