In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Jan 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Veritas
Veritas netbackup Veritas netbackup Appliance |
|
Weaknesses | CWE-22 | |
CPEs | cpe:2.3:a:veritas:netbackup:*:*:*:*:*:*:*:* cpe:2.3:a:veritas:netbackup_appliance:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Veritas
Veritas netbackup Veritas netbackup Appliance |

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-15T19:13:08.179Z
Reserved: 2024-03-07T00:00:00
Link: CVE-2024-28222

Updated: 2024-08-02T00:48:49.473Z

Status : Analyzed
Published: 2024-03-07T07:15:08.377
Modified: 2025-01-21T18:29:18.877
Link: CVE-2024-28222

No data.