Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | bare_metal_restore | * |
Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server 5.1, and NetBackup Server 5.0 and 5.1, allows attackers to execute arbitrary commands via the bpjava-susvc process, possibly related to the call-back feature.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | 3.4.0 |
| veritas | netbackup | 4.5.0 |
| veritas | netbackup | 3.4.1 |
| veritas | netbackup | 5.0 |
| veritas | netbackup | 5.1 |
VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of service (Remote Agent crash) via (1) a crafted packet in NDMLSRVR.DLL or (2) a request packet with an invalid (non-0) "Error Status" value, which triggers a null dereference.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-476,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | backup_exec | * |
Stack-based buffer overflow in the volume manager daemon (vmd) in Veritas NetBackup Enterprise Server 5.0 through 6.0 and DataCenter and BusinesServer 4.5FP and 4.5MP allows attackers to execute arbitrary code via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | 4.5.0 |
| veritas | netbackup | 5.0 |
| veritas | netbackup | 5.1 |
| veritas | netbackup | 6.0 |
Stack-based buffer overflow in the NetBackup Catalog daemon (bpdbm) in Veritas NetBackup Enterprise Server 5.0 through 6.0 and DataCenter and BusinesServer 4.5FP and 4.5MP allows attackers to execute arbitrary code via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | 4.5.0 |
| veritas | netbackup | 5.0 |
| veritas | netbackup | 5.1 |
| veritas | netbackup | 6.0 |
Buffer overflow in the NetBackup Sharepoint Services server daemon (bpspsserver) on NetBackup 6.0 for Windows allows remote attackers to execute arbitrary code via crafted "Request Service" packets to the vnetd service (TCP port 13724).
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | 4.5.0 |
| veritas | netbackup | 5.0 |
| veritas | netbackup | 5.1 |
| veritas | netbackup | 6.0 |
bpcd in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary commands via crafted input.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup_appliance | 2.5.3 |
| veritas | netbackup_appliance | 2.0.2 |
| veritas | netbackup | 7.0 |
| veritas | netbackup | 7.0.1 |
| veritas | netbackup | 7.5.0.5 |
| veritas | netbackup_appliance | 2.5.2 |
| veritas | netbackup_appliance | 2.6.1.2 |
| veritas | netbackup_appliance | 2.6.0.2 |
| veritas | netbackup_appliance | 2.0.1 |
| veritas | netbackup | 7.1.0.2 |
| veritas | netbackup | 7.6.0.4 |
| veritas | netbackup_appliance | 2.6.0.4 |
| veritas | netbackup_appliance | 1.1.0.2 |
| veritas | netbackup_appliance | 2.6 |
| veritas | netbackup | 7.6.1.1 |
| veritas | netbackup | 7.5.0.6 |
| veritas | netbackup | 7.5.0.1 |
| veritas | netbackup | 7.1.0.3 |
| veritas | netbackup_appliance | 2.7.1 |
| veritas | netbackup_appliance | 1.2 |
| veritas | netbackup | 7.5.0.4 |
| veritas | netbackup_appliance | 2.5 |
| veritas | netbackup_appliance | 2.0 |
| veritas | netbackup | 7.6.0.3 |
| veritas | netbackup | 7.6.1.2 |
| veritas | netbackup_appliance | 2.6.1 |
| veritas | netbackup_appliance | 2.6.1.1 |
| veritas | netbackup | 7.6.0.2 |
| veritas | netbackup | 7.5.0.3 |
| veritas | netbackup | 7.1.0.4 |
| veritas | netbackup | 7.1.0.1 |
| veritas | netbackup_appliance | 1.1.0.1 |
| veritas | netbackup_appliance | 2.0.3 |
| veritas | netbackup | 7.7.1 |
| veritas | netbackup_appliance | 2.5.1 |
| veritas | netbackup_appliance | 2.6.0.3 |
| veritas | netbackup | 7.5.0.7 |
Veritas NetBackup 7.x through 7.5.0.7 and 7.6.0.x through 7.6.0.4 and NetBackup Appliance through 2.5.4 and 2.6.0.x through 2.6.0.4 do not use TLS for administration-console traffic to the NBU server, which allows remote attackers to obtain sensitive information by sniffing the network for key-exchange packets.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup_appliance | 2.5.3 |
| veritas | netbackup_appliance | 2.0.2 |
| veritas | netbackup | 7.0 |
| veritas | netbackup | 7.0.1 |
| veritas | netbackup_appliance | 2.5.2 |
| veritas | netbackup | 7.5.0.5 |
| veritas | netbackup_appliance | 2.6.1.2 |
| veritas | netbackup_appliance | 2.6.0.2 |
| veritas | netbackup_appliance | 2.0.1 |
| veritas | netbackup | 7.6.0.4 |
| veritas | netbackup | 7.1.0.2 |
| veritas | netbackup_appliance | 2.6.0.4 |
| veritas | netbackup_appliance | 1.1.0.2 |
| veritas | netbackup_appliance | 2.6 |
| veritas | netbackup | 7.6.1.1 |
| veritas | netbackup | 7.5.0.6 |
| veritas | netbackup | 7.5.0.1 |
| veritas | netbackup | 7.1.0.3 |
| veritas | netbackup_appliance | 2.7.1 |
| veritas | netbackup_appliance | 1.2 |
| veritas | netbackup | 7.5.0.4 |
| veritas | netbackup_appliance | 2.5 |
| veritas | netbackup | 7.6.0.3 |
| veritas | netbackup | 7.6.1.2 |
| veritas | netbackup_appliance | 2.0 |
| veritas | netbackup_appliance | 2.6.1 |
| veritas | netbackup_appliance | 2.6.1.1 |
| veritas | netbackup | 7.6.0.2 |
| veritas | netbackup | 7.5.0.3 |
| veritas | netbackup | 7.1.0.4 |
| veritas | netbackup | 7.1.0.1 |
| veritas | netbackup_appliance | 1.1.0.1 |
| veritas | netbackup_appliance | 2.0.3 |
| veritas | netbackup | 7.7.1 |
| veritas | netbackup_appliance | 2.5.1 |
| veritas | netbackup_appliance | 2.6.0.3 |
| veritas | netbackup | 7.5.0.7 |
The management-services protocol implementation in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, and 2.7.x before 2.7.2 allows remote attackers to make arbitrary RPC calls via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup_appliance | 2.5.3 |
| veritas | netbackup_appliance | 2.0.2 |
| veritas | netbackup | 7.0 |
| veritas | netbackup | 7.0.1 |
| veritas | netbackup | 7.5.0.5 |
| veritas | netbackup_appliance | 2.5.2 |
| veritas | netbackup_appliance | 2.6.1.2 |
| veritas | netbackup_appliance | 2.6.0.2 |
| veritas | netbackup_appliance | 2.0.1 |
| veritas | netbackup | 7.6.0.4 |
| veritas | netbackup | 7.1.0.2 |
| veritas | netbackup_appliance | 2.6.0.4 |
| veritas | netbackup_appliance | 1.1.0.2 |
| veritas | netbackup_appliance | 2.6 |
| veritas | netbackup | 7.6.1.1 |
| veritas | netbackup | 7.5.0.6 |
| veritas | netbackup | 7.5.0.1 |
| veritas | netbackup_appliance | 2.7.1 |
| veritas | netbackup | 7.1.0.3 |
| veritas | netbackup | 7.5.0.4 |
| veritas | netbackup_appliance | 1.2 |
| veritas | netbackup_appliance | 2.5 |
| veritas | netbackup_appliance | 2.0 |
| veritas | netbackup | 7.6.1.2 |
| veritas | netbackup | 7.6.0.3 |
| veritas | netbackup_appliance | 2.6.1 |
| veritas | netbackup_appliance | 2.6.1.1 |
| veritas | netbackup | 7.6.0.2 |
| veritas | netbackup | 7.5.0.3 |
| veritas | netbackup | 7.1.0.4 |
| veritas | netbackup | 7.1.0.1 |
| veritas | netbackup_appliance | 1.1.0.1 |
| veritas | netbackup_appliance | 2.0.3 |
| veritas | netbackup | 7.7.1 |
| veritas | netbackup_appliance | 2.5.1 |
| veritas | netbackup_appliance | 2.6.0.3 |
| veritas | netbackup | 7.5.0.7 |
scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3, and 3.0.x allow remote attackers to execute arbitrary commands via shell metacharacters in the hostName parameter to appliancews/getLicense.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup_appliance_firmware | 2.7.0.0 |
| veritas | netbackup_appliance_firmware | 2.6.0.3 |
| veritas | netbackup_appliance_firmware | 2.6.0.0 |
| veritas | netbackup_appliance_firmware | 2.6.1.1 |
| veritas | netbackup_appliance_firmware | 3.0.0.0 |
| veritas | netbackup_appliance_firmware | 2.7.2.0 |
| veritas | netbackup_appliance_firmware | 2.6.0.4 |
| veritas | netbackup_appliance_firmware | 2.6.0.1 |
| veritas | netbackup_appliance_firmware | 2.6.0.2 |
| veritas | netbackup_appliance_firmware | 2.7.1.0 |
| veritas | netbackup_appliance_firmware | 2.6.1.2 |
| veritas | netbackup_appliance_firmware | 2.6.1.0 |
An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged remote command execution on NetBackup Server and Client (on the server or a connected client) can occur.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | * |
| veritas | access | * |
| veritas | netbackup_appliance | * |
An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged command execution on NetBackup Server and Client can occur (on the local system).
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | * |
| veritas | access | * |
| veritas | netbackup_appliance | * |
An issue was discovered in Veritas NetBackup before 8.0 and NetBackup Appliance before 3.0. Local arbitrary command execution can occur when using bpcd and bpnbat.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-269,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | * |
| veritas | netbackup_appliance | * |
An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Denial of service affecting NetBackup server can occur.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | * |
| veritas | netbackup_appliance | * |
An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username and password.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | * |
| veritas | netbackup_appliance | * |
An issue was discovered in Veritas NetBackup Before 7.7 and NetBackup Appliance Before 2.7. There are world-writable log files, allowing destruction or spoofing of log data.
CVSS 2.0
Severity: LOW
Problem Type: CWE-276,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | * |
| veritas | netbackup_appliance | * |
An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Hostname-based security is open to DNS spoofing.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-290,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | * |
| veritas | netbackup_appliance | * |
An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Arbitrary privileged command execution, using whitelist directory escape with "../" substrings, can occur.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | * |
| veritas | access | * |
| veritas | netbackup_appliance | * |
An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged remote command execution on NetBackup Server and Client (on the server or a connected client) can occur.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | * |
| veritas | netbackup_appliance | * |
An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. A local-privilege-escalation race condition in pbx_exchange can occur when a local user connects to a socket before permissions are secured.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | * |
| veritas | netbackup_appliance | * |
An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Unauthenticated CORBA interfaces permit inappropriate access.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-306,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | * |
| veritas | netbackup_appliance | * |
In Veritas System Recovery before 16 SP1, there is a DLL hijacking vulnerability in the patch installer if an attacker has write access to the directory from which the product is executed.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | system_recovery | 16 |
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution using the 'bprd' process.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | * |
| veritas | netbackup_appliance | * |
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote command execution using the 'bprd' process.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | * |
| veritas | netbackup_appliance | * |
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated privileged remote file write using the 'bprd' process.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup | * |
| veritas | netbackup_appliance | * |
In Veritas NetBackup Appliance 3.0 and earlier, unauthenticated users can execute arbitrary commands as root.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup_appliance | 2.7.3 |
| veritas | netbackup_appliance | 3.0 |
| veritas | netbackup_appliance | * |
In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of service or remote code execution. An unauthenticated attacker can use this vulnerability to crash the agent or potentially take control of the agent process and then the system it is running on.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-416,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | backup_exec | * |
A remote command execution vulnerability in Veritas NetBackup Appliance before 3.1.2 allows authenticated administrators to execute arbitrary commands as root. This issue was caused by insufficient filtering of user provided input.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup_appliance | * |
An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The proxy server password is displayed to an administrator.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup_appliance | * |
An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The SMTP password is displayed to an administrator.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| veritas | netbackup_appliance | * |