An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Arbitrary privileged command execution, using whitelist directory escape with "../" substrings, can occur.
2017-03-02T06:59:00.980
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 8.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | veritas | access | ≤ 7.2.1 | Yes |
Application | veritas | netbackup | ≤ 7.7.1 | Yes |
Application | veritas | netbackup_appliance | ≤ 2.7.1 | Yes |