Show filters
49 Total Results
Displaying 1-10 of 49
Sort by:
Attacker Value
High
CVE-2022-22965
Disclosure Date: April 01, 2022 (last updated October 07, 2023)
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
7
Attacker Value
Unknown
CVE-2024-28222
Disclosure Date: March 07, 2024 (last updated January 22, 2025)
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
0
Attacker Value
Unknown
CVE-2023-37237
Disclosure Date: June 29, 2023 (last updated October 08, 2023)
In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.
0
Attacker Value
Unknown
CVE-2023-26788
Disclosure Date: April 10, 2023 (last updated October 08, 2023)
Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks. HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address.
0
Attacker Value
Unknown
CVE-2022-46414
Disclosure Date: December 04, 2022 (last updated October 08, 2023)
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal.
0
Attacker Value
Unknown
CVE-2022-46413
Disclosure Date: December 04, 2022 (last updated October 08, 2023)
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated remote command execution can occur via the management portal.
0
Attacker Value
Unknown
CVE-2022-46412
Disclosure Date: December 04, 2022 (last updated October 08, 2023)
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell and execute privileged commands.
0
Attacker Value
Unknown
CVE-2022-46411
Disclosure Date: December 04, 2022 (last updated October 08, 2023)
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.
0
Attacker Value
Unknown
CVE-2022-46410
Disclosure Date: December 04, 2022 (last updated October 08, 2023)
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root by using specific commands.
0
Attacker Value
Unknown
CVE-2022-37000
Disclosure Date: July 28, 2022 (last updated October 08, 2023)
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely read files on a NetBackup Primary server.
0