An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command. Successful exploitation could expose sensitive system configuration and credential material stored on the appliance.
Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.