Vulnerabilities > Veritas

DATE CVE VULNERABILITY TITLE RISK
2024-11-18 CVE-2024-52945 Unspecified vulnerability in Veritas Netbackup
An issue was discovered in Veritas NetBackup before 10.5.
local
low complexity
veritas
7.8
2024-10-04 CVE-2024-47854 Cross-site Scripting vulnerability in Veritas Data Insight
An XSS vulnerability was discovered in Veritas Data Insight before 7.1.
network
low complexity
veritas CWE-79
6.1
2024-03-07 CVE-2024-28222 Path Traversal vulnerability in Veritas Netbackup and Netbackup Appliance
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
network
low complexity
veritas CWE-22
critical
9.8
2024-02-22 CVE-2024-27283 Unspecified vulnerability in Veritas Ediscovery Platform
A vulnerability was discovered in Veritas eDiscovery Platform before 10.2.5.
network
low complexity
veritas
7.2
2023-08-11 CVE-2023-40256 Improper Certificate Validation vulnerability in Veritas Netbackup Snapshot Manager
A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service.
network
low complexity
veritas CWE-295
critical
9.8
2023-07-17 CVE-2023-38404 Unrestricted Upload of File with Dangerous Type vulnerability in Veritas Infoscale Operations Manager
The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server.
network
low complexity
veritas CWE-434
8.8
2023-06-29 CVE-2023-37237 Incorrect Permission Assignment for Critical Resource vulnerability in Veritas Netbackup Appliance
In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.
network
low complexity
veritas CWE-732
7.2
2023-05-10 CVE-2023-32568 OS Command Injection vulnerability in Veritas Infoscale Operations Manager
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410.
network
low complexity
veritas CWE-78
7.2
2023-05-10 CVE-2023-32569 SQL Injection vulnerability in Veritas Infoscale Operations Manager
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410.
network
low complexity
veritas CWE-89
critical
9.8
2023-04-10 CVE-2023-26788 Cross-site Scripting vulnerability in Veritas Netbackup Appliance Firmware 4.1.0.1
Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks.
network
low complexity
veritas CWE-79
6.1