PT-2023-8787 · Veritas · Veritas Netbackup It Analytics
Published
2023-03-24
·
Updated
2023-03-31
·
CVE-2023-28818
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Veritas NetBackup IT Analytics versions prior to 11.2.0
Description
The issue is related to errors in cryptographic signature verification, which could allow a remote attacker to compromise data integrity. A malicious actor could exploit the application upgrade process, which includes unsigned files, to install rogue Collector executable files, such as
aptare.jar or upgrademanager.zip, on the Portal server. These files might then be downloaded and installed on collectors.Recommendations
For Veritas NetBackup IT Analytics versions prior to 11.2.0, update to version 11.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Portal server to minimize the risk of exploitation. Avoid using the unsigned files in the application upgrade process until the issue is resolved.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Veritas Netbackup It Analytics