An issue exists in Veritas NetBackup prior to 7.7.2 and NetBackup Appliance prior to 2.7.2. Arbitrary privileged command execution, using whitelist directory escape with "../" substrings, can occur.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
veritas netbackup |
||
veritas netbackup appliance |
||
veritas access |