
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-36997 is a high-severity vulnerability discovered in Veritas NetBackup versions 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 and related NetBackup products. The vulnerability was disclosed on July 27, 2022, and received a CVSS v3.1 base score of 7.1, indicating high severity (NVD, Veritas Advisory).
The vulnerability allows an attacker with authenticated access to a NetBackup Client to remotely trigger multiple security impacts. These include arbitrary file read capabilities, Server-Side Request Forgery (SSRF), and denial of service conditions. The attack vector is network-based, requires low privileges, and no user interaction is needed for exploitation (Veritas Advisory).
The successful exploitation of this vulnerability can lead to unauthorized file reading, Server-Side Request Forgery (SSRF) attacks, and system availability disruption through denial of service. The vulnerability primarily affects the confidentiality and availability of the system, with potential for information disclosure and service disruption (Veritas Advisory).
Veritas has released HotFixes for affected versions of NetBackup. Organizations should apply the VTS22-004 HotFix to both Primary servers and Media servers. For systems running versions prior to 8.1.2, users must first upgrade to a supported version before applying the HotFix. The fix is available for NetBackup versions 8.1.2, 8.2, 8.3.0.1, 8.3.0.2, 9.0.0.1, and 9.1.0.1 (Veritas Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."