← Back

Bacula

bacula

7 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Bacula
bacula
Bacula Web
bacula-web

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bacula
1Bacula Web
Aug 6, 2025
Jul 29, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
SQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request.
1Bacula
1Bacula Web
Nov 21, 2024
Mar 7, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.
1Bacula
1Bacula Web
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote attackers to execute arbitrary SQL commands via the jobid parameter.
2Bacula
Debian
2Bacula
Debian Linux
Apr 29, 2026
Oct 10, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump information via unspecified vectors.
1Bacula
1Bacula
Apr 23, 2026
Dec 8, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
mtx-changer.Adic-Scalar-24 in bacula-common 2.4.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mtx.##### temporary file, probably a related issue to CVE-2005-2995.
1Bacula
1Bacula
Apr 23, 2026
Oct 23, 2007
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attacker...Show more
make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the password by listing the process and its arguments, or by sniffing the network.Show less
1Bacula
1Bacula
Apr 16, 2026
Sep 20, 2005
N/A· v4
N/A· v3
3.6 LOW· v2
bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autoconf/randpass when openssl is not available, or (2) the mtx.[PID] temporary file in...Show more
bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autoconf/randpass when openssl is not available, or (2) the mtx.[PID] temporary file in mtx-changer.in.Show less