what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Veritas Resiliency Platform (VRP) Traversal / Command Execution

Veritas Resiliency Platform (VRP) Traversal / Command Execution
Posted Jul 31, 2019
Authored by David Dillard

Veritas Resiliency Platform (VRP) suffers from cross site scripting, command execution, and directory traversal vulnerabilities. Versions prior to VRP 3.3.2 HF14 are affected.

tags | advisory, vulnerability, xss
advisories | CVE-2019-14415, CVE-2019-14416, CVE-2019-14417, CVE-2019-14418
SHA-256 | 19b3557291834e8c0ffcc8ed02b5d8ede660703088173b45e8a1ff7cfc4db3ef

Veritas Resiliency Platform (VRP) Traversal / Command Execution

Change Mirror Download
Four vulnerabilities have been fixed in VRP 3.4 HF1, one of which is of critical severity.

Directory traversal vulnerability related to uploading application bundles
CVE-2019-14415
Critical severity

Arbitrary command execution vulnerability with root privilege related to DNS server configuration
CVE-2019-14416
High severity

Arbitrary command execution vulnerability with root privilege related to resiliency plans and custom scripts
CVE-2019-14417
High severity

A persistent cross-site scripting (XSS) vulnerability allows a malicious VRP user to inject malicious script into another user's browser, related to resiliency plans functionality.
CVE-2019-14418
Medium severity

https://www.veritas.com/content/support/en_US/security/VTS19-002.html



Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    0 Files
  • 3
    Sep 3rd
    0 Files
  • 4
    Sep 4th
    0 Files
  • 5
    Sep 5th
    0 Files
  • 6
    Sep 6th
    0 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    0 Files
  • 9
    Sep 9th
    0 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close