RSS   Vulnerabilities for 'Infoscale operations manager'   RSS

2022-03-04
 
CVE-2022-26483

CWE-79
 

 
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. A reflected cross-site scripting (XSS) vulnerability in admin/cgi-bin/listdir.pl allows authenticated remote administrators to inject arbitrary web script or HTML into an HTTP GET parameter (which reflect the user input without sanitization).

 
 
CVE-2022-26484

CWE-22
 

 
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. The web server fails to sanitize admin/cgi-bin/rulemgr.pl/getfile/ input data, allowing a remote authenticated administrator to read arbitrary files on the system via Directory Traversal. By manipulating the resource name in GET requests referring to files with absolute paths, it is possible to access arbitrary files stored on the filesystem, including application source code, configuration files, and critical system files.

 

 >>> Vendor: Veritas 15 Products
Bare metal restore
Netbackup
Netbackup appliance
Netbackup appliance firmware
Access
System recovery
Backup exec
Resiliency platform
Access appliance
Flex appliance
Infoscale
Aptare
Desktop and laptop option
Enterprise vault
Infoscale operations manager


Copyright 2022, cxsecurity.com

 

Back to Top