Veritas Enterprise Vault 14.4.2

CPE Details

Veritas Enterprise Vault 14.4.2
14.4.2
2024-12-17
15h40 +00:00
2024-12-17
15h40 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:veritas:enterprise_vault:14.4.2:*:*:*:*:*:*:*

Informations

Vendor

veritas

Product

enterprise_vault

Version

14.4.2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-53909 2024-11-23 23h00 +00:00 An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
9.8
Critical
CVE-2024-53910 2024-11-23 23h00 +00:00 An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24336. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
9.8
Critical
CVE-2024-53911 2024-11-23 23h00 +00:00 An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24339. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
9.8
Critical
CVE-2024-53912 2024-11-23 23h00 +00:00 An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
9.8
Critical
CVE-2024-53913 2024-11-23 23h00 +00:00 An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24343. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
9.8
Critical
CVE-2024-53914 2024-11-23 23h00 +00:00 An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24344. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
9.8
Critical
CVE-2024-53915 2024-11-23 23h00 +00:00 An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24405. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
9.8
Critical
CVE-2024-52943 2024-11-18 00h00 +00:00 An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.
5.4
Medium
CVE-2024-52942 2024-11-17 23h00 +00:00 An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.
5.4
Medium
CVE-2024-52944 2024-11-17 23h00 +00:00 An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.
5.4
Medium