← Back

Netbackup

netbackup

Vendor: Veritas • 66 CVEs

CVEs (66)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Veritas
1Netbackup
Apr 30, 2025
Nov 18, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social enginee...Show more
An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL could be loaded, resulting in execution of the attacker's code in the user's security context.Show less
1Veritas
1Netbackup
Jun 10, 2025
Apr 26, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected files.
1Veritas
2Netbackup
Netbackup Appliance
Jan 21, 2025
Mar 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
1Veritas
1Netbackup
Feb 25, 2025
Mar 23, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loading may allow a lower-level user to elevate privileges and compromise th...Show more
An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loading may allow a lower-level user to elevate privileges and compromise the system.Show less
1Veritas
1Netbackup
Feb 25, 2025
Mar 23, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files.
1Veritas
1Netbackup
Apr 29, 2025
Nov 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary com...Show more
The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root.Show less
1Veritas
1Netbackup
Nov 21, 2024
Oct 3, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by leveraging a path traversal in the pbx_exchange registration code.
1Veritas
1Netbackup
Nov 21, 2024
Oct 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service...Show more
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service.Show less
1Veritas
1Netbackup
Nov 21, 2024
Oct 3, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can send a crafted packet to pbx_exchange during registration and cause a NULL pointer exception, effec...Show more
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can send a crafted packet to pbx_exchange during registration and cause a NULL pointer exception, effectively crashing the pbx_exchange process.Show less
1Veritas
1Netbackup
Nov 21, 2024
Oct 3, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to a Path traversal attack through the DiscoveryService service.
1Veritas
1Netbackup
Nov 21, 2024
Oct 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting idm, nbars, and SLP manager code.
1Veritas
1Netbackup
Nov 21, 2024
Oct 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a second-order SQL Injection attack affecting the NBFSMCLIENT service by leveraging CV...Show more
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a second-order SQL Injection attack affecting the NBFSMCLIENT service by leveraging CVE-2022-42302.Show less
1Veritas
1Netbackup
Nov 21, 2024
Oct 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting the NBFSMCLIENT service.
1Veritas
1Netbackup
Nov 21, 2024
Oct 3, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) injection attack through the nbars process.
1Veritas
1Netbackup
Nov 21, 2024
Oct 3, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server nbars process can be crashed resulting in a denial of service. (Note: the watchdog service will aut...Show more
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server nbars process can be crashed resulting in a denial of service. (Note: the watchdog service will automatically restart the process.)Show less
1Veritas
1Netbackup
Nov 21, 2024
Oct 3, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to a denial of service attack through the DiscoveryService service.
1Veritas
4Flex Appliance
Flex ScaleNetbackup+1 more
Nov 21, 2024
Jul 28, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with au...Show more
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely read files on a NetBackup Primary server.Show less
1Veritas
4Flex Appliance
Flex ScaleNetbackup+1 more
Nov 21, 2024
Jul 28, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with au...Show more
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely read files on a NetBackup Primary server.Show less
1Veritas
4Flex Appliance
Flex ScaleNetbackup+1 more
Nov 21, 2024
Jul 28, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a Ne...Show more
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a stack-based buffer overflow on the NetBackup Primary server, resulting in a denial of service.Show less
1Veritas
4Flex Appliance
Flex ScaleNetbackup+1 more
Nov 21, 2024
Jul 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a Ne...Show more
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger impacts that include arbitrary file read, Server-Side Request Forgery (SSRF), and denial of service.Show less