CVE-2019-14418
Veritas Resiliency Platform (VRP) Traversal / Command Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. When uploading an application bundle, a directory traversal vulnerability allows a VRP user with sufficient privileges to overwrite any file in the VRP virtual machine. A malicious VRP user could use this to replace existing files to take control of the VRP virtual machine.
Se detectó un problema en Veritas Resiliencia Platform (VRP) anterior a versión 3.4 HF1. Cuando se carga un paquete de aplicaciones, una vulnerabilidad de salto de directorio permite a un usuario de VRP, con privilegios suficientes, sobrescribir cualquier archivo en la máquina virtual de VRP. Un usuario de VRP malicioso podría usar esto para reemplazar los archivos existentes y tomar el control de la máquina virtual de VRP.
Veritas Resiliency Platform (VRP) suffers from cross site scripting, command execution, and directory traversal vulnerabilities. Versions prior to VRP 3.3.2 HF14 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-07-29 CVE Reserved
- 2019-07-29 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/153842/Veritas-Resiliency-Platform-VRP-Traversal-Command-Execution.html | Third Party Advisory |
|
http://seclists.org/fulldisclosure/2019/Jul/39 | Broken Link |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.veritas.com/content/support/en_US/security/VTS19-002.html#Issue1 | 2023-03-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Veritas Search vendor "Veritas" | Resiliency Platform Search vendor "Veritas" for product "Resiliency Platform" | 1.2 Search vendor "Veritas" for product "Resiliency Platform" and version "1.2" | - |
Affected
| ||||||
Veritas Search vendor "Veritas" | Resiliency Platform Search vendor "Veritas" for product "Resiliency Platform" | 2.0 Search vendor "Veritas" for product "Resiliency Platform" and version "2.0" | - |
Affected
| ||||||
Veritas Search vendor "Veritas" | Resiliency Platform Search vendor "Veritas" for product "Resiliency Platform" | 2.1 Search vendor "Veritas" for product "Resiliency Platform" and version "2.1" | - |
Affected
| ||||||
Veritas Search vendor "Veritas" | Resiliency Platform Search vendor "Veritas" for product "Resiliency Platform" | 2.2 Search vendor "Veritas" for product "Resiliency Platform" and version "2.2" | - |
Affected
| ||||||
Veritas Search vendor "Veritas" | Resiliency Platform Search vendor "Veritas" for product "Resiliency Platform" | 2.2 Search vendor "Veritas" for product "Resiliency Platform" and version "2.2" | update_3 |
Affected
| ||||||
Veritas Search vendor "Veritas" | Resiliency Platform Search vendor "Veritas" for product "Resiliency Platform" | 3.0 Search vendor "Veritas" for product "Resiliency Platform" and version "3.0" | - |
Affected
| ||||||
Veritas Search vendor "Veritas" | Resiliency Platform Search vendor "Veritas" for product "Resiliency Platform" | 3.1 Search vendor "Veritas" for product "Resiliency Platform" and version "3.1" | - |
Affected
| ||||||
Veritas Search vendor "Veritas" | Resiliency Platform Search vendor "Veritas" for product "Resiliency Platform" | 3.2 Search vendor "Veritas" for product "Resiliency Platform" and version "3.2" | - |
Affected
| ||||||
Veritas Search vendor "Veritas" | Resiliency Platform Search vendor "Veritas" for product "Resiliency Platform" | 3.3 Search vendor "Veritas" for product "Resiliency Platform" and version "3.3" | - |
Affected
| ||||||
Veritas Search vendor "Veritas" | Resiliency Platform Search vendor "Veritas" for product "Resiliency Platform" | 3.3.1 Search vendor "Veritas" for product "Resiliency Platform" and version "3.3.1" | - |
Affected
| ||||||
Veritas Search vendor "Veritas" | Resiliency Platform Search vendor "Veritas" for product "Resiliency Platform" | 3.3.2 Search vendor "Veritas" for product "Resiliency Platform" and version "3.3.2" | - |
Affected
|