QID 377958

Date Published: 2023-02-07

QID 377958: Veritas NetBackup SQL Injection Vulnerability

Veritas NetBackup is an enterprise level heterogeneous backup and recovery suite.

Affected Versions:
Veritas NetBackup v10.0.0.0 and earlier.

QID Detection Logic (Authenticated):
Operating Systems: Windows
The QID checks for the File Version of nbutil.exe

An attacker can comprise the Veritas NetBackup via SQL Injection.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.1 severity.
  • Solution
    The vendor has issued a fix for these vulnerabilities. Please refer to the vendor advisory VTS22-011 which addresses this issue.

    CVEs related to QID 377958

    Software Advisories
    Advisory ID Software Component Link
    VTS22-011 URL Logo www.veritas.com/content/support/en_US/security/VTS22-011