Skip to main content

Vendor archive

veritas CVEs

Beta · best-effort

140 CVEs tagged to vendor veritas51 Critical, 52 High, 37 Medium, 0 Low, 0 Unrated.

CVE-2026-44925

Published May 20, 2026

Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a maliciou…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-53915

Published Nov 24, 2024

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24405. It allows remote attackers to execute arbitrary code because untrusted data, received…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-53914

Published Nov 24, 2024

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24344. It allows remote attackers to execute arbitrary code because untrusted data, received…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-53913

Published Nov 24, 2024

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24343. It allows remote attackers to execute arbitrary code because untrusted data, received…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-53912

Published Nov 24, 2024

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code because untrusted data, received…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-53911

Published Nov 24, 2024

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24339. It allows remote attackers to execute arbitrary code because untrusted data, received…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-53910

Published Nov 24, 2024

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24336. It allows remote attackers to execute arbitrary code because untrusted data, received…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-53909

Published Nov 24, 2024

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers to execute arbitrary code because untrusted data, received…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-52945

Published Nov 18, 2024

An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup co…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52944

Published Nov 18, 2024

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, al…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52943

Published Nov 18, 2024

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP request, al…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52942

Published Nov 18, 2024

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP request, al…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47854

Published Oct 4, 2024

An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-33673

Published Apr 26, 2024

An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search path.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-33672

Published Apr 26, 2024

An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected files.

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-33671

Published Apr 26, 2024

An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file d…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27283

Published Feb 22, 2024

A vulnerability was discovered in Veritas eDiscovery Platform before 10.2.5. The application administrator can upload potentially malicious files to arbitrary locations on the ser…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40256

Published Aug 11, 2023

A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by impro…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-38404

Published Jul 17, 2023

The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenti…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37237

Published Jun 29, 2023

In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system comman…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32569

Published May 10, 2023

An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection i…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32568

Published May 10, 2023

An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application does not validate user-supplied data and a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 140 CVEsPage 1 of 6