Show filters
156 Total Results
Displaying 91-100 of 156
Sort by:
Attacker Value
Unknown

CVE-2020-12875

Disclosure Date: May 14, 2020 (last updated February 21, 2025)
Veritas APTARE versions prior to 10.4 did not perform adequate authorization checks. An authenticated user could gain unauthorized access to sensitive information or functionality by manipulating specific parameters within the application.
Attacker Value
Unknown

CVE-2020-12874

Disclosure Date: May 14, 2020 (last updated February 21, 2025)
Veritas APTARE versions prior to 10.4 included code that bypassed the normal login process when specific authentication credentials were provided to the server.
Attacker Value
Unknown

CVE-2020-12877

Disclosure Date: May 14, 2020 (last updated February 21, 2025)
Veritas APTARE versions prior to 10.4 allowed sensitive information to be accessible without authentication.
Attacker Value
Unknown

CVE-2020-12876

Disclosure Date: May 14, 2020 (last updated February 21, 2025)
Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows server deployments.
Attacker Value
Unknown

CVE-2019-18780

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier, Access Appliance 7.4.2 and earlier, Flex Appliance 1.2 and earlier, InfoScale 7.3.1 and earlier, InfoScale between 7.4.0 and 7.4.1, Veritas Cluster Server (VCS) 6.2.1 and earlier on Linux/UNIX, Veritas Cluster Server (VCS) 6.1 and earlier on Windows, Storage Foundation HA (SFHA) 6.2.1 and earlier on Linux/UNIX, and Storage Foundation HA (SFHA) 6.1 and earlier on Windows.
Attacker Value
Unknown

CVE-2019-14418

Disclosure Date: July 29, 2019 (last updated November 27, 2024)
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. When uploading an application bundle, a directory traversal vulnerability allows a VRP user with sufficient privileges to overwrite any file in the VRP virtual machine. A malicious VRP user could use this to replace existing files to take control of the VRP virtual machine.
Attacker Value
Unknown

CVE-2019-14415

Disclosure Date: July 29, 2019 (last updated November 27, 2024)
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. A persistent cross-site scripting (XSS) vulnerability allows a malicious VRP user to inject malicious script into another user's browser, related to resiliency plans functionality. A victim must open a resiliency plan that an attacker has access to.
Attacker Value
Unknown

CVE-2019-14416

Disclosure Date: July 29, 2019 (last updated November 27, 2024)
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerability allows a malicious VRP user to execute commands with root privilege within the VRP virtual machine, related to resiliency plans and custom script functionality.
Attacker Value
Unknown

CVE-2019-14417

Disclosure Date: July 29, 2019 (last updated November 27, 2024)
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerability allows a malicious VRP user to execute commands with root privilege within the VRP virtual machine, related to DNS functionality.
0
Attacker Value
Unknown

CVE-2019-9868

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The SMTP password is displayed to an administrator.
0