NA

CVE-2023-28818

Published: 24/03/2023 Updated: 31/03/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in Veritas NetBackup IT Analytics 11 prior to 11.2.0. The application upgrade process included unsigned files that could be exploited and result in a customer installing unauthentic components. A malicious actor could install rogue Collector executable files (aptare.jar or upgrademanager.zip) on the Portal server, which might then be downloaded and installed on collectors.

Vulnerable Product Search on Vulmon Subscribe to Product

veritas netbackup it analytics 11.1.00

veritas netbackup it analytics 11.0.00

veritas aptare it analytics