In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote command execution using the 'bprd' process.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://www.veritas.com/content/support/en_US/security/VTS17-004.html#Issue2 | vendor advisory |
http://www.securityfocus.com/bid/98384 | vdb entry third party advisory |