CVE-2022-26500
17.03.2022, 21:15
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
Vendor | Product | Version |
---|---|---|
veeam | veeam_backup_\&_replication | 10.0.0.4442 ≤ 𝑥 < 10.0.1.4854 |
veeam | veeam_backup_\&_replication | 11.0.0.825 ≤ 𝑥 < 11.0.1.1261 |
veeam | veeam_backup_\&_replication | 9.5.0.1536 |
veeam | veeam_backup_\&_replication | 9.5.4.2615 |
veeam | veeam_backup_\&_replication | 10.0.1.4854 |
veeam | veeam_backup_\&_replication | 10.0.1.4854:p20201202 |
veeam | veeam_backup_\&_replication | 10.0.1.4854:p20210609 |
veeam | veeam_backup_\&_replication | 11.0.1.1261 |
veeam | veeam_backup_\&_replication | 11.0.1.1261:p20211123 |
veeam | veeam_backup_\&_replication | 11.0.1.1261:p20211211 |
𝑥
= Vulnerable software versions