Show filters
156 Total Results
Displaying 11-20 of 156
Sort by:
Attacker Value
Unknown

CVE-2023-40256

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by improper validation of the client certificate due to misconfiguration of the RabbitMQ service. Exploiting this impacts the confidentiality and integrity of messages controlling the backup and restore jobs, and could result in the service becoming unavailable. This impacts only the jobs controlling the backup and restore activities, and does not allow access to (or deletion of) the backup snapshot data itself. This vulnerability is confined to the NetBackup Snapshot Manager feature and does not impact the RabbitMQ instance on the NetBackup primary servers.
Attacker Value
Unknown

CVE-2023-38404

Disclosure Date: July 17, 2023 (last updated October 08, 2023)
The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server.
Attacker Value
Unknown

CVE-2023-37237

Disclosure Date: June 29, 2023 (last updated October 08, 2023)
In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.
Attacker Value
Unknown

CVE-2023-32569

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. This allows attackers (who must have admin credentials) to submit arbitrary SQL commands on the back-end database to create, read, update, or delete any sensitive data stored in the database.
Attacker Value
Unknown

CVE-2023-32568

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application does not validate user-supplied data and appends it to OS commands and internal binaries used by the application. An attacker with root/administrator level privileges can leverage this to read sensitive data stored on the servers, modify data or server configuration, and delete data or application configuration.
Attacker Value
Unknown

CVE-2023-26788

Disclosure Date: April 10, 2023 (last updated October 08, 2023)
Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks. HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address.
Attacker Value
Unknown

CVE-2023-26789

Disclosure Date: April 05, 2023 (last updated October 08, 2023)
Veritas NetBackUp OpsCenter Version 9.1.0.1 is vulnerable to Reflected Cross-site scripting (XSS). The Web App fails to adequately sanitize special characters. By leveraging this issue, an attacker is able to cause arbitrary HTML and JavaScript code to be executed in a user's browser.
Attacker Value
Unknown

CVE-2023-28818

Disclosure Date: March 24, 2023 (last updated October 08, 2023)
An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exploited and result in a customer installing unauthentic components. A malicious actor could install rogue Collector executable files (aptare.jar or upgrademanager.zip) on the Portal server, which might then be downloaded and installed on collectors.
Attacker Value
Unknown

CVE-2023-28759

Disclosure Date: March 23, 2023 (last updated October 08, 2023)
An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loading may allow a lower-level user to elevate privileges and compromise the system.
Attacker Value
Unknown

CVE-2023-28758

Disclosure Date: March 23, 2023 (last updated October 08, 2023)
An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files.