| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally. |
| A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins. |
| A vulnerability allowing remote unauthenticated code execution on the agent host. |
| A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service. |
| A vulnerability allowing local privilege escalation to the Reporter service context. |
| A vulnerability allowing a low-privileged user to inject SQL and extract database contents. |
| A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. |
| A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link. |
| A vulnerability allowing a high-privileged user to execute arbitrary code on the server. |
| A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. |
| A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system. |
| Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account. |
| A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. |
| A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication. |
| A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. |
| This vulnerability in Veeam Service Provider Console allows for remote code execution. |
| This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation. |
| A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server. |
| A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. |
| A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository. |