Veritas InfoScale Operations Manager (VIOM) 7.4.0.200 affected by vulnerability CVE-2023-38404

book

Article ID: 100061309

calendar_today

Updated On:

Description

Error Message

n/a

 

Cause

A vulnerability is present in the VIOM xprtld service whereby affected versions allow an authenticated attacker to upload all types of files to the server and then could execute those files.

Resolution

There are no plans to address this issue by way of a patch or hotfix in earlier versions of the software at the present time.  However, the issue has been addressed in the revision of the product specified at the end of this article. 

Please contact your Veritas Sales representative or the Veritas Sales group for upgrade information including upgrade eligibility to the release containing the resolution for this issue.

 

Upgrade VIOM to a minimum version of 7.4.2.810, 8.0.0.410 or 8.0.2.

Issue/Introduction

Veritas InfoScale Operations Manager (VIOM) 7.4.0.200 affected by vulnerability CVE-2023-38404

Additional Information

JIRA: SDSCPE-13382