CVE-2022-36953
Last modified
CVE-2022-36953 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. In Veritas NetBackup OpsCenter, certain endpoints could allow an unauthenticated remote attacker to gain sensitive information. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
In Veritas NetBackup OpsCenter, certain endpoints could allow an unauthenticated remote attacker to gain sensitive information. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Veritas | Netbackup | >= 8.0, < 8.3.0.2 |
| Veritas | Netbackup | 9.0 |
| Veritas | Netbackup | 9.1.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-36953?
How severe is CVE-2022-36953?
How do I fix CVE-2022-36953?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-36948In Veritas NetBackup OpsCenter, a DOM XSS attack can occur. …5.4
- CVE-2022-36949In Veritas NetBackup OpsCenter, an attacker with local acces…7.8
- CVE-2022-3695 Hitachi Vantara Pentaho Business Analytics Server prior to …6.1
- CVE-2022-36950In Veritas NetBackup OpsCenter, an unauthenticated remote at…9.8
- CVE-2022-36951In Veritas NetBackup OpsCenter, an unauthenticated remote at…9.8
- CVE-2022-36952In Veritas NetBackup OpsCenter, a hard-coded credential exis…9.8
- CVE-2022-36954In Veritas NetBackup OpsCenter, under specific conditions, a…6.5
- CVE-2022-36955In Veritas NetBackup, an attacker with unprivileged local ac…8.4
- CVE-2022-36956In Veritas NetBackup, the NetBackup Client allows arbitrary …7.5
- CVE-2022-36957SolarWinds Platform was susceptible to the Deserialization o…7.2
- CVE-2022-36958SolarWinds Platform was susceptible to the Deserialization o…8.8
- CVE-2022-3696A post-auth code injection vulnerability allows admins to ex…7.2
Are you affected by CVE-2022-36953?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
