PT-2022-27862 · Veritas · Veritas Netbackup Access Appliance+1

Published

2022-12-04

·

Updated

2022-12-06

·

CVE-2022-46413

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Veritas NetBackup Flex Scale versions 1.0 through 3.0 Veritas NetBackup Access Appliance versions 1.0 through 8.0.100
Description An issue was discovered that allows authenticated remote command execution via the management portal.
Recommendations For Veritas NetBackup Flex Scale versions 1.0 through 3.0, update to a version later than 3.0 to resolve the issue. For Veritas NetBackup Access Appliance versions 1.0 through 8.0.100, update to a version later than 8.0.100 to resolve the issue. As a temporary workaround, consider restricting access to the management portal until a patch is available.

Fix

Related Identifiers

CVE-2022-46413

Affected Products

Veritas Netbackup Access Appliance
Veritas Netbackup Flex Scale