← Back

CVE-2016-7399

nvd nist
Published: Jan 4, 2017Modified: May 6, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3, and 3.0.x allow remote attackers to execute arbitrary commands via shell metacharacters in the hostName parameter to appliancews/getLicense.

Affected (12)

1 product
Netbackup Appliance Firmware
Configuration A
12 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Veritas
Version 2.6.0.0
Version 2.6.0.1
Version 2.6.0.2
Version 2.6.0.3
Version 2.6.0.4
Version 2.6.1.0
Version 2.6.1.1
Version 2.6.1.2
Version 2.7.0.0
Version 2.7.1.0
Version 2.7.2.0
Version 3.0.0.0
Running on/withPlatform Versions
Veritas
Netbackup Appliance
All versions

References (10)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
MitigationPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationPatchVendor Advisory

Timeline

No history available yet.