CVE-2024-22021
07.02.2024, 01:15
VulnerabilityCVE-2024-22021 allowsaVeeam Recovery Orchestrator user with a lowprivilegedrole (PlanAuthor)to retrieveplansfromaScope other than the one they are assigned to.Enginsight
Vendor | Product | Version |
---|---|---|
veeam | availability_orchestrator | 4.0 |
veeam | disaster_recovery_orchestrator | 5.0 |
veeam | recovery_orchestrator | 6.0 |
𝑥
= Vulnerable software versions