Dell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability. A non-LDAP remote user with low privileges may exploit this vulnerability to perform 'saveset' related operations in an unintended manner. The vulnerability is not exploitable by users authenticated via LDAP.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
The product makes files or directories accessible to unauthorized actors, even though they should not be.