CVE-2022-36990
Status: ModifiedMedium (6.5)—
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely write arbitrary files to arbitrary locations from any Client to any other Client via a Primary server.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Base score: 6.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.66%
- Percentile among all scored CVEs: 50
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (4)
CWEs
- NVD-CWE-noinfo
References
Raw JSON (NVD)
Show
{
"id": "CVE-2022-36990",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.6,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 5.8,
"exploitabilityScore": 3.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2022-07-28T01:15:17.857",
"references": [
{
"url": "https://www.veritas.com/content/support/en_US/security/VTS22-004#c2",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.veritas.com/content/support/en_US/security/VTS22-004#c2",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely write arbitrary files to arbitrary locations from any Client to any other Client via a Primary server."
},
{
"lang": "es",
"value": "Se ha detectado un problema en Veritas NetBackup versiones 8.1.x hasta 8.1.2, 8.2, 8.3.x hasta 8.3.0.2, 9.x hasta 9.0.0.1 y 9.1.x hasta 9.1.0.1 (y productos NetBackup relacionados). Un atacante con acceso autenticado a un Cliente NetBackup podría escribir remotamente archivos arbitrarios en ubicaciones arbitrarias desde cualquier Cliente a cualquier otro Cliente por medio de un servidor primario"
}
],
"lastModified": "2026-06-17T04:54:25.023",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:veritas:flex_appliance:1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "025BC427-C1D3-4888-8585-EE5EF288AE86"
},
{
"criteria": "cpe:2.3:a:veritas:flex_appliance:1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E18698DE-9043-4AA0-B798-51C0B4CACBAD"
},
{
"criteria": "cpe:2.3:a:veritas:flex_appliance:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8CE9674B-4528-4168-B09A-DBAA48622307"
},
{
"criteria": "cpe:2.3:a:veritas:flex_appliance:2.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9810D40F-FF25-495F-80A4-7A8D8679FA33"
},
{
"criteria": "cpe:2.3:a:veritas:flex_appliance:2.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02B3BC5A-97E2-4295-9EA3-62D29E579E9F"
},
{
"criteria": "cpe:2.3:a:veritas:flex_appliance:2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EC18FEAF-65B4-4F56-A703-21DF9B969B0B"
},
{
"criteria": "cpe:2.3:a:veritas:flex_scale:1.3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0BDD5695-9235-4592-9B8A-A90BE7762F90"
},
{
"criteria": "cpe:2.3:a:veritas:flex_scale:2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20EF9FB3-5862-4C85-A082-5903E9619A01"
},
{
"criteria": "cpe:2.3:a:veritas:netbackup:8.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "48682500-A4CC-417A-AE87-254A38E9A837"
},
{
"criteria": "cpe:2.3:a:veritas:netbackup:8.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F28926F3-D951-40EC-A383-27038FF62D9A"
},
{
"criteria": "cpe:2.3:a:veritas:netbackup:8.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3678D77D-D641-47C6-92BA-FE124D645F47"
},
{
"criteria": "cpe:2.3:a:veritas:netbackup:8.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A32EEA7C-4AE9-4E8A-89C5-7354DCE953A7"
},
{
"criteria": "cpe:2.3:a:veritas:netbackup:8.3.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "06FB11BA-21B8-4AF5-8E06-A03A148380A0"
},
{
"criteria": "cpe:2.3:a:veritas:netbackup:8.3.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F903AD8B-FCF5-4287-828C-AB19C69C00FB"
},
{
"criteria": "cpe:2.3:a:veritas:netbackup:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E3A9DC13-0464-4507-A5A2-91BEF7E55AA1"
},
{
"criteria": "cpe:2.3:a:veritas:netbackup:9.0.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B23C8C3-3385-435D-861E-F1EEFD382C6F"
},
{
"criteria": "cpe:2.3:a:veritas:netbackup:9.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8797A64D-D4EA-45F4-911E-3F5794979FBB"
},
{
"criteria": "cpe:2.3:a:veritas:netbackup:9.1.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "26A3CE2C-544C-4785-B879-6C4E0A594FFE"
},
{
"criteria": "cpe:2.3:a:veritas:netbackup_appliance:3.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C5DFF0B8-7BA5-4BF0-B98A-BB833D3FA6A1"
},
{
"criteria": "cpe:2.3:a:veritas:netbackup_appliance:3.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "070A8292-8AA8-45B0-BD12-174071C142ED"
},
{
"criteria": "cpe:2.3:a:veritas:netbackup_appliance:3.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DA05618C-73DD-4A02-AF1B-90C5D968C881"
},
{
"criteria": "cpe:2.3:a:veritas:netbackup_appliance:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D33CB9E-3A08-4B80-8C3F-3D180C0F3E85"
},
{
"criteria": "cpe:2.3:a:veritas:netbackup_appliance:4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B8EDC739-0410-45C6-9628-EC833AC7400E"
},
{
"criteria": "cpe:2.3:h:veritas:netbackup_appliance:3.2:maintenance_release1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "40BE7CD2-A828-4A21-B3EB-3BC4688C6D96"
},
{
"criteria": "cpe:2.3:h:veritas:netbackup_appliance:3.2:maintenance_release2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0D532AFE-824C-4002-AD4E-431F83911D27"
},
{
"criteria": "cpe:2.3:h:veritas:netbackup_appliance:3.2:maintenance_release3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C9CD8205-281F-4ABD-BF1D-EB97090B3755"
},
{
"criteria": "cpe:2.3:h:veritas:netbackup_appliance:3.3.0.1:maintenance_release1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0DD01222-0F16-48D3-842A-C07377C0872F"
},
{
"criteria": "cpe:2.3:h:veritas:netbackup_appliance:3.3.0.1:maintenance_release2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3ED514C2-AEDD-4071-A145-5D281C789703"
},
{
"criteria": "cpe:2.3:h:veritas:netbackup_appliance:3.3.0.2:maintenance_release1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BF2D4F61-2307-4A29-B620-E811E7642E66"
},
{
"criteria": "cpe:2.3:h:veritas:netbackup_appliance:3.3.0.2:maintenance_release2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF307131-DB9A-41CA-9990-EAAF56B671DB"
},
{
"criteria": "cpe:2.3:h:veritas:netbackup_appliance:4.0.0.1:maintenance_release1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "42554066-06A0-44EF-8911-5982A4033E00"
},
{
"criteria": "cpe:2.3:h:veritas:netbackup_appliance:4.0.0.1:maintenance_release2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE52F0C6-7AB6-4E84-9A8C-01C2AE170504"
},
{
"criteria": "cpe:2.3:h:veritas:netbackup_appliance:4.0.0.1:maintenance_release3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F2762443-9B5B-4675-84B3-21A60385F86E"
},
{
"criteria": "cpe:2.3:h:veritas:netbackup_appliance:4.1.0.1:maintenance_release1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6256AE6A-34BF-417A-BAB9-8889457BA31B"
},
{
"criteria": "cpe:2.3:h:veritas:netbackup_appliance:4.1.0.1:maintenance_release2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FBEF9B41-F0AF-49A8-95A9-5F803E5AFDE0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}