
CVE-2024-28222
https://notcve.org/view.php?id=CVE-2024-28222
07 Mar 2024 — In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file. En Veritas NetBackup anterior a 8.1.2 y NetBackup Appliance anterior a 3.1.2, el proceso BPCD valida inadecuadamente la ruta del archivo, lo que permite que un atacante no autenticado cargue y ejecute un archivo personalizado. • https://www.veritas.com/content/support/en_US/security/VTS23-010 •

CVE-2023-37237
https://notcve.org/view.php?id=CVE-2023-37237
29 Jun 2023 — In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH. • https://www.veritas.com/content/support/en_US/security/VTS23-004 • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2023-26788
https://notcve.org/view.php?id=CVE-2023-26788
10 Apr 2023 — Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks. HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address. • https://github.com/IthacaLabs/Veritas-Technologies • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-46410
https://notcve.org/view.php?id=CVE-2022-46410
04 Dec 2022 — An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root by using specific commands. Se descubrió un problema en Veritas NetBackup Flex Scale hasta 3.0. Un atacante con privilegios no root puede escalar privilegios a root mediante el uso de comandos específicos. • https://www.veritas.com/content/support/en_US/security/VTS22-019#issue5 •

CVE-2022-46411
https://notcve.org/view.php?id=CVE-2022-46411
04 Dec 2022 — An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges. Se descubrió un problema en Veritas NetBackup Flex Scale hasta 3.0 y Access Appliance hasta 8.0.100. Una contraseña predeterminada persiste después de la instalación y puede descubrirse y usarse para escalar privilegios. • https://www.veritas.com/content/support/en_US/security/VTS22-019#issue3 • CWE-287: Improper Authentication •

CVE-2022-46412
https://notcve.org/view.php?id=CVE-2022-46412
04 Dec 2022 — An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell and execute privileged commands. Se descubrió un problema en Veritas NetBackup Flex Scale hasta 3.0. Un usuario sin privilegios puede escapar de un shell restringido y ejecutar comandos privilegiados. • https://www.veritas.com/content/support/en_US/security/VTS22-019#issue4 •

CVE-2022-46413
https://notcve.org/view.php?id=CVE-2022-46413
04 Dec 2022 — An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated remote command execution can occur via the management portal. Se descubrió un problema en Veritas NetBackup Flex Scale hasta 3.0 y Access Appliance hasta 8.0.100. La ejecución de comandos remotos autenticados puede ocurrir a través del portal de administración. • https://www.veritas.com/content/support/en_US/security/VTS22-019#issue2 •

CVE-2022-46414
https://notcve.org/view.php?id=CVE-2022-46414
04 Dec 2022 — An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal. Se descubrió un problema en Veritas NetBackup Flex Scale hasta 3.0 y Access Appliance hasta 8.0.100. La ejecución de comandos remotos no autenticados puede ocurrir a través del portal de administración. • https://www.veritas.com/content/support/en_US/security/VTS22-019#issue1 •

CVE-2022-36984
https://notcve.org/view.php?id=CVE-2022-36984
28 Jul 2022 — An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a denial of service attack against a NetBackup Primary server. Se ha detectado un problema en Veritas NetBackup versiones 8.1.x hasta 8.1.2, 8.2, 8.3.x hasta 8.3.0.2, 9.x hasta 9.0.0.1 y 9.1.x hasta 9.1.0.1 (y productos NetBackup relacionados). Un atacan... • https://www.veritas.com/content/support/en_US/security/VTS22-004#h8 •

CVE-2022-36985
https://notcve.org/view.php?id=CVE-2022-36985
28 Jul 2022 — An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with unprivileged local access to a Windows NetBackup Primary server could potentially escalate their privileges. Se ha detectado un problema en Veritas NetBackup versiones 8.1.x hasta 8.1.2, 8.2, 8.3.x hasta 8.3.0.2, 9.x hasta 9.0.0.1 y 9.1.x hasta 9.1.0.1 (y productos NetBackup relacionados). Un atacante con acceso local ... • https://www.veritas.com/content/support/en_US/security/VTS22-004#h7 •