CVE-2016-7399
Last modified
CVE-2016-7399 is a vulnerability of currently unknown severity. scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3, and 3.0.x allow remote attackers to execute arbitrary commands via shell metacharacters in the hostName parameter to appliancews/getLicense.. EPSS estimates a 4.94% chance of exploitation in the next 30 days.
Description
scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3, and 3.0.x allow remote attackers to execute arbitrary commands via shell metacharacters in the hostName parameter to appliancews/getLicense.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Veritas | Netbackup Appliance Firmware | 2.6.0.0 |
| Veritas | Netbackup Appliance Firmware | 2.6.0.1 |
| Veritas | Netbackup Appliance Firmware | 2.6.0.2 |
| Veritas | Netbackup Appliance Firmware | 2.6.0.3 |
| Veritas | Netbackup Appliance Firmware | 2.6.0.4 |
| Veritas | Netbackup Appliance Firmware | 2.6.1.0 |
| Veritas | Netbackup Appliance Firmware | 2.6.1.1 |
| Veritas | Netbackup Appliance Firmware | 2.6.1.2 |
| Veritas | Netbackup Appliance Firmware | 2.7.0.0 |
| Veritas | Netbackup Appliance Firmware | 2.7.1.0 |
| Veritas | Netbackup Appliance Firmware | 2.7.2.0 |
| Veritas | Netbackup Appliance Firmware | 3.0.0.0 |
References
- http://www.securityfocus.com/bid/94384Third Party Advisory, VDB Entry
- https://www.veritas.com/support/en_US/article.000116055Mitigation, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/94384Third Party Advisory, VDB Entry
- https://www.veritas.com/support/en_US/article.000116055Mitigation, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-7399?
How severe is CVE-2016-7399?
How do I fix CVE-2016-7399?
Are you affected by CVE-2016-7399?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
