2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2022-36998" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2022-07-28T01:15:18.257" ,
"lastModified" : "2022-08-09T15:30:36.297" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a stack-based buffer overflow on the NetBackup Primary server, resulting in a denial of service."
} ,
{
"lang" : "es" ,
"value" : "Se ha detectado un problema en Veritas NetBackup versiones 8.1.x hasta 8.1.2, 8.2, 8.3.x hasta 8.3.0.2, 9.x hasta 9.0.0.1 y 9.1.x hasta 9.1.0.1 (y productos NetBackup relacionados). Un atacante con acceso autenticado a un cliente de NetBackup podr\u00eda desencadenar de forma remota un desbordamiento del b\u00fafer basado en la pila en el servidor primario de NetBackup, resultando en una denegaci\u00f3n de servicio"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 6.5 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 3.6
} ,
{
"source" : "cve@mitre.org" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 6.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 4.0
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-787"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:flex_appliance:1.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "025BC427-C1D3-4888-8585-EE5EF288AE86"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:flex_appliance:1.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E18698DE-9043-4AA0-B798-51C0B4CACBAD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:flex_appliance:2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8CE9674B-4528-4168-B09A-DBAA48622307"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:flex_appliance:2.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9810D40F-FF25-495F-80A4-7A8D8679FA33"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:flex_appliance:2.0.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "02B3BC5A-97E2-4295-9EA3-62D29E579E9F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:flex_appliance:2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EC18FEAF-65B4-4F56-A703-21DF9B969B0B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:flex_scale:1.3.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0BDD5695-9235-4592-9B8A-A90BE7762F90"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:flex_scale:2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "20EF9FB3-5862-4C85-A082-5903E9619A01"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:netbackup:8.1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "48682500-A4CC-417A-AE87-254A38E9A837"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:netbackup:8.1.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F28926F3-D951-40EC-A383-27038FF62D9A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:netbackup:8.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3678D77D-D641-47C6-92BA-FE124D645F47"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:netbackup:8.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A32EEA7C-4AE9-4E8A-89C5-7354DCE953A7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:netbackup:8.3.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "06FB11BA-21B8-4AF5-8E06-A03A148380A0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:netbackup:8.3.0.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F903AD8B-FCF5-4287-828C-AB19C69C00FB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:netbackup:9.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E3A9DC13-0464-4507-A5A2-91BEF7E55AA1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:netbackup:9.0.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0B23C8C3-3385-435D-861E-F1EEFD382C6F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:netbackup:9.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8797A64D-D4EA-45F4-911E-3F5794979FBB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:netbackup:9.1.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "26A3CE2C-544C-4785-B879-6C4E0A594FFE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:netbackup_appliance:3.1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C5DFF0B8-7BA5-4BF0-B98A-BB833D3FA6A1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:netbackup_appliance:3.1.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "070A8292-8AA8-45B0-BD12-174071C142ED"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:netbackup_appliance:3.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DA05618C-73DD-4A02-AF1B-90C5D968C881"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:netbackup_appliance:4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5D33CB9E-3A08-4B80-8C3F-3D180C0F3E85"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:veritas:netbackup_appliance:4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B8EDC739-0410-45C6-9628-EC833AC7400E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:veritas:netbackup_appliance:3.2:maintenance_release1:*:*:*:*:*:*" ,
"matchCriteriaId" : "40BE7CD2-A828-4A21-B3EB-3BC4688C6D96"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:veritas:netbackup_appliance:3.2:maintenance_release2:*:*:*:*:*:*" ,
"matchCriteriaId" : "0D532AFE-824C-4002-AD4E-431F83911D27"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:veritas:netbackup_appliance:3.2:maintenance_release3:*:*:*:*:*:*" ,
"matchCriteriaId" : "C9CD8205-281F-4ABD-BF1D-EB97090B3755"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:veritas:netbackup_appliance:3.3.0.1:maintenance_release1:*:*:*:*:*:*" ,
"matchCriteriaId" : "0DD01222-0F16-48D3-842A-C07377C0872F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:veritas:netbackup_appliance:3.3.0.1:maintenance_release2:*:*:*:*:*:*" ,
"matchCriteriaId" : "3ED514C2-AEDD-4071-A145-5D281C789703"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:veritas:netbackup_appliance:3.3.0.2:maintenance_release1:*:*:*:*:*:*" ,
"matchCriteriaId" : "BF2D4F61-2307-4A29-B620-E811E7642E66"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:veritas:netbackup_appliance:3.3.0.2:maintenance_release2:*:*:*:*:*:*" ,
"matchCriteriaId" : "CF307131-DB9A-41CA-9990-EAAF56B671DB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:veritas:netbackup_appliance:4.0.0.1:maintenance_release1:*:*:*:*:*:*" ,
"matchCriteriaId" : "42554066-06A0-44EF-8911-5982A4033E00"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:veritas:netbackup_appliance:4.0.0.1:maintenance_release2:*:*:*:*:*:*" ,
"matchCriteriaId" : "BE52F0C6-7AB6-4E84-9A8C-01C2AE170504"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:veritas:netbackup_appliance:4.0.0.1:maintenance_release3:*:*:*:*:*:*" ,
"matchCriteriaId" : "F2762443-9B5B-4675-84B3-21A60385F86E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:veritas:netbackup_appliance:4.1.0.1:maintenance_release1:*:*:*:*:*:*" ,
"matchCriteriaId" : "6256AE6A-34BF-417A-BAB9-8889457BA31B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:veritas:netbackup_appliance:4.1.0.1:maintenance_release2:*:*:*:*:*:*" ,
"matchCriteriaId" : "FBEF9B41-F0AF-49A8-95A9-5F803E5AFDE0"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://www.veritas.com/content/support/en_US/security/VTS22-004#m3" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
}
]
}