Vulnerability Details CVE-2022-42301
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) injection attack through the nbars process.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.3%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2022-42301
-
cpe:2.3:a:veritas:netbackup:-
-
cpe:2.3:a:veritas:netbackup:10.0
-
cpe:2.3:a:veritas:netbackup:10.0.0.1
-
cpe:2.3:a:veritas:netbackup:4.5.0
-
cpe:2.3:a:veritas:netbackup:5.0.0
-
cpe:2.3:a:veritas:netbackup:5.1.0
-
cpe:2.3:a:veritas:netbackup:7.0
-
cpe:2.3:a:veritas:netbackup:7.0.1
-
cpe:2.3:a:veritas:netbackup:7.1.0.1
-
cpe:2.3:a:veritas:netbackup:7.1.0.2
-
cpe:2.3:a:veritas:netbackup:7.1.0.3
-
cpe:2.3:a:veritas:netbackup:7.1.0.4
-
cpe:2.3:a:veritas:netbackup:7.5.0.1
-
cpe:2.3:a:veritas:netbackup:7.5.0.3
-
cpe:2.3:a:veritas:netbackup:7.5.0.4
-
cpe:2.3:a:veritas:netbackup:7.5.0.5
-
cpe:2.3:a:veritas:netbackup:7.5.0.6
-
cpe:2.3:a:veritas:netbackup:7.5.0.7
-
cpe:2.3:a:veritas:netbackup:7.6.0.2
-
cpe:2.3:a:veritas:netbackup:7.6.0.3
-
cpe:2.3:a:veritas:netbackup:7.6.0.4
-
cpe:2.3:a:veritas:netbackup:7.6.1.1
-
cpe:2.3:a:veritas:netbackup:7.6.1.2
-
cpe:2.3:a:veritas:netbackup:7.7.1
-
cpe:2.3:a:veritas:netbackup:8.0
-
cpe:2.3:a:veritas:netbackup:8.1.1
-
cpe:2.3:a:veritas:netbackup:8.1.2
-
cpe:2.3:a:veritas:netbackup:8.2
-
cpe:2.3:a:veritas:netbackup:8.3
-
cpe:2.3:a:veritas:netbackup:8.3.0.0
-
cpe:2.3:a:veritas:netbackup:8.3.0.1
-
cpe:2.3:a:veritas:netbackup:8.3.0.2
-
cpe:2.3:a:veritas:netbackup:9.0
-
cpe:2.3:a:veritas:netbackup:9.0.0.1
-
cpe:2.3:a:veritas:netbackup:9.1
-
cpe:2.3:a:veritas:netbackup:9.1.0.0
-
cpe:2.3:a:veritas:netbackup:9.1.0.1