XML External Entity (XXE) Injection Vulnerability in Veritas NetBackup DiscoveryService

XML External Entity (XXE) Injection Vulnerability in Veritas NetBackup DiscoveryService

CVE-2022-42307 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service.

Learn more about our Cis Benchmark Audit For Server Software.