PT-2022-26357 · Veritas · Netbackup

Published

2022-10-03

·

Updated

2022-10-05

·

CVE-2022-42302

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Veritas NetBackup versions prior to 10.0 Veritas products related to NetBackup (affected versions not specified)
Description An issue was discovered that makes the NetBackup Primary server vulnerable to a SQL Injection attack. This attack affects the NBFSMCLIENT service.
Recommendations For Veritas NetBackup versions prior to 10.0, update to version 10.0 or later to resolve the issue. For related Veritas products, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-42302

Affected Products

Netbackup