Vulnerabilities > Veritas > Netbackup

DATE CVE VULNERABILITY TITLE RISK
2024-03-07 CVE-2024-28222 Path Traversal vulnerability in Veritas Netbackup and Netbackup Appliance
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
network
low complexity
veritas CWE-22
critical
9.8
2023-03-23 CVE-2023-28758 Unspecified vulnerability in Veritas Netbackup
An issue was discovered in Veritas NetBackup before 8.3.0.2.
local
low complexity
veritas
7.1
2023-03-23 CVE-2023-28759 Uncontrolled Search Path Element vulnerability in Veritas Netbackup
An issue was discovered in Veritas NetBackup before 10.0 on Windows.
local
low complexity
veritas CWE-427
7.8
2022-11-17 CVE-2022-45461 OS Command Injection vulnerability in Veritas Netbackup
The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root.
network
low complexity
veritas CWE-78
8.8
2022-10-03 CVE-2022-42299 Unspecified vulnerability in Veritas Netbackup
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products.
network
low complexity
veritas
7.5
2022-10-03 CVE-2022-42300 Unspecified vulnerability in Veritas Netbackup
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products.
network
low complexity
veritas
6.5
2022-10-03 CVE-2022-42301 XXE vulnerability in Veritas Netbackup
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products.
network
low complexity
veritas CWE-611
8.8
2022-10-03 CVE-2022-42302 SQL Injection vulnerability in Veritas Netbackup
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products.
network
low complexity
veritas CWE-89
critical
9.8
2022-10-03 CVE-2022-42303 SQL Injection vulnerability in Veritas Netbackup
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products.
network
low complexity
veritas CWE-89
critical
9.8
2022-10-03 CVE-2022-42304 SQL Injection vulnerability in Veritas Netbackup
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products.
network
low complexity
veritas CWE-89
critical
9.8