📦 Netbackup

by Veritas

🔍 What is Netbackup?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-28222

CRITICAL CVSS 9.8 Mar 7, 2024

This critical vulnerability allows unauthenticated attackers to upload and execute arbitrary files on Veritas NetBackup systems by exploiting improper path validation in the BPCD process. It affects a...

CVE-2022-36990

CRITICAL CVSS 9.6 Jul 28, 2022

This vulnerability allows an authenticated attacker on a NetBackup Client to remotely write arbitrary files to any location on any other Client via a Primary server. This affects Veritas NetBackup ver...

CVE-2022-36992

CRITICAL CVSS 9.9 Jul 28, 2022

This vulnerability allows an authenticated attacker on a NetBackup Client to remotely execute arbitrary commands on a NetBackup Primary server under specific notify conditions. It affects Veritas NetB...

CVE-2022-36954

CRITICAL CVSS 9.9 Jul 27, 2022

In Veritas NetBackup OpsCenter, an authenticated remote attacker can create or modify user accounts under specific conditions. This vulnerability affects OpsCenter versions 8.x through 8.3.0.2, 9.x th...

CVE-2022-36956

CRITICAL CVSS 9.0 Jul 27, 2022

CVE-2022-36956 allows remote attackers with a valid NetBackup certificate/private key from the same domain to execute arbitrary commands on NetBackup Client systems. This affects Veritas NetBackup ver...

CVE-2022-36949

CRITICAL CVSS 9.3 Jul 27, 2022

CVE-2022-36949 is a local privilege escalation vulnerability in Veritas NetBackup OpsCenter. An attacker with local access to an OpsCenter server could potentially gain elevated privileges. This affec...

CVE-2022-36951

CRITICAL CVSS 9.8 Jul 27, 2022

CVE-2022-36951 is an unauthenticated remote code execution vulnerability in Veritas NetBackup OpsCenter that allows attackers to compromise the host by exploiting an incorrectly patched previous vulne...

CVE-2024-52945

HIGH CVSS 7.8 Nov 18, 2024

This vulnerability allows attackers to execute arbitrary code by loading malicious DLLs when users run specific NetBackup commands on Windows systems. It affects Veritas NetBackup versions before 10.5...

CVE-2023-28758

HIGH CVSS 7.1 Mar 23, 2023

This vulnerability in Veritas NetBackup's BPCD component allows unprivileged users to specify arbitrary log file paths when executing commands, enabling them to overwrite existing NetBackup log files....

CVE-2022-36997

HIGH CVSS 7.1 Jul 28, 2022

This vulnerability in Veritas NetBackup allows authenticated attackers on NetBackup Clients to remotely read arbitrary files, perform Server-Side Request Forgery (SSRF), and cause denial of service. I...

CVE-2022-36985

HIGH CVSS 7.8 Jul 28, 2022

CVE-2022-36985 is a local privilege escalation vulnerability in Veritas NetBackup that allows attackers with unprivileged local access to Windows NetBackup Primary servers to gain elevated privileges....

CVE-2022-36987

HIGH CVSS 8.5 Jul 28, 2022

This vulnerability allows authenticated attackers on NetBackup Client systems to write arbitrary files to NetBackup Primary servers. This could lead to remote code execution, data manipulation, or sys...

CVE-2022-36989

HIGH CVSS 8.8 Jul 28, 2022

This vulnerability allows authenticated attackers on NetBackup Client systems to remotely execute arbitrary commands on NetBackup Primary servers. It affects multiple versions of Veritas NetBackup and...