← Back

Veritas

veritas

140 CVEs • 31 products

Products (31)

Click to collapse
Toggle
Netbackup
netbackup
Flex Scale
flex_scale
Backup Exec
backup_exec
Aptare
aptare
Access
access
Infoscale
infoscale
Opscenter
opscenter
Cluster Server
cluster_server
Cloudpoint
cloudpoint
Data Insight
data_insight

CVEs (140)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Veritas
1Netbackup Snapshot Manager
Nov 21, 2024
Aug 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by improper validation of the client certificate...Show more
A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by improper validation of the client certificate due to misconfiguration of the RabbitMQ service. Exploiting this impacts the confidentiality and integrity of messages controlling the backup and restore jobs, and could result in the service becoming unavailable. This impacts only the jobs controlling the backup and restore activities, and does not allow access to (or deletion of) the backup snapshot data itself. This vulnerability is confined to the NetBackup Snapshot Manager feature and does not impact the RabbitMQ instance on the NetBackup primary servers.Show less
1Veritas
1Infoscale Operations Manager
Nov 21, 2024
Jul 17, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malic...Show more
The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server.Show less
1Veritas
1Netbackup Appliance
Nov 21, 2024
Jun 29, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.
1Veritas
1Infoscale Operations Manager
Jan 28, 2025
May 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. T...Show more
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. This allows attackers (who must have admin credentials) to submit arbitrary SQL commands on the back-end database to create, read, update, or delete any sensitive data stored in the database.Show less
1Veritas
1Infoscale Operations Manager
Jan 28, 2025
May 10, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application does not validate user-supplied data and appends it to OS commands and internal bin...Show more
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application does not validate user-supplied data and appends it to OS commands and internal binaries used by the application. An attacker with root/administrator level privileges can leverage this to read sensitive data stored on the servers, modify data or server configuration, and delete data or application configuration.Show less
1Veritas
1Netbackup Appliance Firmware
Feb 11, 2025
Apr 10, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks. HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the req...Show more
Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks. HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address.Show less
1Veritas
1Netbackup Opscenter
Feb 13, 2025
Apr 5, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Veritas NetBackUp OpsCenter Version 9.1.0.1 is vulnerable to Reflected Cross-site scripting (XSS). The Web App fails to adequately sanitize special characters. By leveraging this issue, an attacker is able to cause arbit...Show more
Veritas NetBackUp OpsCenter Version 9.1.0.1 is vulnerable to Reflected Cross-site scripting (XSS). The Web App fails to adequately sanitize special characters. By leveraging this issue, an attacker is able to cause arbitrary HTML and JavaScript code to be executed in a user's browser.Show less
1Veritas
2Aptare It Analytics
Netbackup It Analytics
Feb 19, 2025
Mar 24, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exploited and result in a customer installing unauthentic components. A ma...Show more
An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exploited and result in a customer installing unauthentic components. A malicious actor could install rogue Collector executable files (aptare.jar or upgrademanager.zip) on the Portal server, which might then be downloaded and installed on collectors.Show less
1Veritas
1Netbackup
Feb 25, 2025
Mar 23, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loading may allow a lower-level user to elevate privileges and compromise th...Show more
An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loading may allow a lower-level user to elevate privileges and compromise the system.Show less
1Veritas
1Netbackup
Feb 25, 2025
Mar 23, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files.
1Veritas
2Access Appliance
Netbackup Flex Scale Appliance
Apr 24, 2025
Dec 4, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal.
1Veritas
2Access Appliance
Netbackup Flex Scale Appliance
Nov 21, 2024
Dec 4, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated remote command execution can occur via the management portal.
1Veritas
1Netbackup Flex Scale Appliance
Nov 21, 2024
Dec 4, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell and execute privileged commands.
1Veritas
2Access Appliance
Netbackup Flex Scale Appliance
Apr 24, 2025
Dec 4, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.
1Veritas
1Netbackup Flex Scale Appliance
Apr 24, 2025
Dec 4, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root by using specific commands.
1Veritas
1Netbackup
Apr 29, 2025
Nov 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary com...Show more
The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root.Show less
1Veritas
1Netbackup
Nov 21, 2024
Oct 3, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by leveraging a path traversal in the pbx_exchange registration code.
1Veritas
1Netbackup
Nov 21, 2024
Oct 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service...Show more
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service.Show less
1Veritas
1Netbackup
Nov 21, 2024
Oct 3, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can send a crafted packet to pbx_exchange during registration and cause a NULL pointer exception, effec...Show more
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can send a crafted packet to pbx_exchange during registration and cause a NULL pointer exception, effectively crashing the pbx_exchange process.Show less
1Veritas
1Netbackup
Nov 21, 2024
Oct 3, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to a Path traversal attack through the DiscoveryService service.