veritas security advisories
22 threat alerts tracking vulnerabilities and security advisories that affect veritas products.
Vulnios monitors veritas CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent veritas security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2020-36166 — veritas, microsoft — infoscale, infoscale_operations_manager
An issue was discovered in Veritas InfoScale 7.x through 7.4.2 on Windows, Storage Foundation through 6.1 on Windows, Storage Foundation HA through 6.1 on Windows, and InfoScale Operations Manager (ak
criticalCVE-2020-36166Critical Vulnerability: CVE-2020-36163 — veritas, microsoft — netbackup, opscenter
An issue was discovered in Veritas NetBackup and OpsCenter through 8.3.0.1. NetBackup processes using Strawberry Perl attempt to load and execute libraries from paths that do not exist by default on t
criticalCVE-2020-36163Critical Vulnerability: CVE-2020-36169 — veritas, microsoft — netbackup, opscenter
An issue was discovered in Veritas NetBackup through 8.3.0.1 and OpsCenter through 8.3.0.1. Processes using OpenSSL attempt to load and execute libraries from paths that do not exist by default on the
criticalCVE-2020-36169Critical Vulnerability: CVE-2020-36167 — veritas — backup_exec
An issue was discovered in the server in Veritas Backup Exec through 16.2, 20.6 before hotfix 298543, and 21.1 before hotfix 657517. On start-up, it loads the OpenSSL library from the Installation fol
criticalCVE-2020-36167Critical Vulnerability: CVE-2020-36164 — veritas, microsoft — enterprise_vault, windows
An issue was discovered in Veritas Enterprise Vault through 14.0. On start-up, it loads the OpenSSL library. The OpenSSL library then attempts to load the openssl.cnf configuration file (which does no
criticalCVE-2020-36164Critical Vulnerability: CVE-2020-36165 — veritas, microsoft — desktop_and_laptop_option, windows
An issue was discovered in Veritas Desktop and Laptop Option (DLO) before 9.4. On start-up, it loads the OpenSSL library from /ReleaseX64/ssl. This library attempts to load the /ReleaseX64/ssl/openssl
criticalCVE-2020-36165Critical Vulnerability: CVE-2020-36160 — veritas, microsoft — system_recovery, windows
An issue was discovered in Veritas System Recovery before 21.2. On start-up, it loads the OpenSSL library from \usr\local\ssl. This library attempts to load the from \usr\local\ssl\openssl.cnf configu
criticalCVE-2020-36160Critical Vulnerability: CVE-2020-36168 — veritas — resiliency_platform
An issue was discovered in Veritas Resiliency Platform 3.4 and 3.5. It leverages OpenSSL on Windows systems when using the Managed Host addon. On start-up, it loads the OpenSSL library. This library m
criticalCVE-2020-36168Critical Vulnerability: CVE-2020-36162 — veritas, microsoft — cloudpoint, netbackup_cloudpoint
An issue was discovered in Veritas CloudPoint before 8.3.0.1+hotfix. The CloudPoint Windows Agent leverages OpenSSL. This OpenSSL library attempts to load the \usr\local\ssl\openssl.cnf configuration
criticalCVE-2020-36162Critical Vulnerability: CVE-2020-27156 — veritas — aptare
Veritas APTARE versions prior to 10.5 did not perform adequate authorization checks. This vulnerability could allow for remote code execution by an unauthenticated user.
criticalCVE-2020-27156Critical Vulnerability: CVE-2020-12874 — veritas — aptare
Veritas APTARE versions prior to 10.4 included code that bypassed the normal login process when specific authentication credentials were provided to the server.
criticalCVE-2020-12874Critical Vulnerability: CVE-2019-18780 — veritas, microsoft — access, access_appliance
An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. Thes
criticalCVE-2019-18780Critical Vulnerability: CVE-2017-8895 — veritas — backup_exec
In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of serv
criticalCVE-2017-8895Critical Vulnerability: CVE-2017-8857 — veritas — netbackup, netbackup_appliance
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote command execution using the 'bprd' process.
criticalCVE-2017-8857Critical Vulnerability: CVE-2017-8858 — veritas — netbackup, netbackup_appliance
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated privileged remote file write using the 'bprd' process.
criticalCVE-2017-8858Critical Vulnerability: CVE-2017-8856 — veritas — netbackup, netbackup_appliance
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution using the 'bprd' process.
criticalCVE-2017-8856Critical Vulnerability: CVE-2017-8859 — veritas — netbackup_appliance
In Veritas NetBackup Appliance 3.0 and earlier, unauthenticated users can execute arbitrary commands as root.
criticalCVE-2017-8859Critical Vulnerability: CVE-2017-6409 — veritas — netbackup, netbackup_appliance
An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Unauthenticated CORBA interfaces permit inappropriate access.
criticalCVE-2017-6409Critical Vulnerability: CVE-2017-6403 — veritas — netbackup, netbackup_appliance
An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username and password.
criticalCVE-2017-6403Critical Vulnerability: CVE-2016-7399 — veritas — netbackup_appliance_firmware, netbackup_appliance
scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3, and 3.0.x allow remote attackers to execute arbitrary commands via shell metach
criticalCVE-2016-7399Critical Vulnerability: CVE-2015-6552 — veritas — netbackup_appliance, netbackup
The management-services protocol implementation in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4
criticalCVE-2015-6552Critical Vulnerability: CVE-2015-6550 — veritas — netbackup_appliance, netbackup
bpcd in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x through
criticalCVE-2015-6550
Track veritas exposure across your environment
Vulnios automatically cross-references your asset inventory against new veritas CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan