Vulnerabilities > Veritas

DATE CVE VULNERABILITY TITLE RISK
2024-10-04 CVE-2024-47854 Cross-site Scripting vulnerability in Veritas Data Insight
An XSS vulnerability was discovered in Veritas Data Insight before 7.1.
network
low complexity
veritas CWE-79
6.1
2023-08-11 CVE-2023-40256 Improper Certificate Validation vulnerability in Veritas Netbackup Snapshot Manager
A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service.
network
low complexity
veritas CWE-295
critical
9.8
2023-07-17 CVE-2023-38404 Unrestricted Upload of File with Dangerous Type vulnerability in Veritas Infoscale Operations Manager
The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server.
network
low complexity
veritas CWE-434
8.8
2023-06-29 CVE-2023-37237 Incorrect Permission Assignment for Critical Resource vulnerability in Veritas Netbackup Appliance
In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.
network
low complexity
veritas CWE-732
7.2
2023-05-10 CVE-2023-32568 OS Command Injection vulnerability in Veritas Infoscale Operations Manager
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410.
network
low complexity
veritas CWE-78
7.2
2023-05-10 CVE-2023-32569 SQL Injection vulnerability in Veritas Infoscale Operations Manager
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410.
network
low complexity
veritas CWE-89
critical
9.8
2023-04-10 CVE-2023-26788 Cross-site Scripting vulnerability in Veritas Netbackup Appliance Firmware 4.1.0.1
Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks.
network
low complexity
veritas CWE-79
6.1
2023-04-05 CVE-2023-26789 Cross-site Scripting vulnerability in Veritas Netbackup Opscenter 9.1.0.1
Veritas NetBackUp OpsCenter Version 9.1.0.1 is vulnerable to Reflected Cross-site scripting (XSS).
network
low complexity
veritas CWE-79
6.1
2023-03-24 CVE-2023-28818 Improper Verification of Cryptographic Signature vulnerability in Veritas Aptare IT Analytics and Netbackup IT Analytics
An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0.
network
low complexity
veritas CWE-347
5.3
2023-03-23 CVE-2023-28758 Unspecified vulnerability in Veritas Netbackup
An issue was discovered in Veritas NetBackup before 8.3.0.2.
local
low complexity
veritas
7.1