Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
| Software | From | Fixed in |
|---|---|---|
| veeam / veeam_backup_&_replication | 11.0.1.1261-p20211123 | 11.0.1.1261-p20211123.x |
| veeam / veeam_backup_&_replication | 11.0.1.1261-p20211211 | 11.0.1.1261-p20211211.x |
| veeam / veeam_backup_&_replication | 11.0.1.1261 | 11.0.1.1261.x |
| veeam / veeam_backup_&_replication | 10.0.1.4854-p20210609 | 10.0.1.4854-p20210609.x |
| veeam / veeam_backup_&_replication | 9.5.4.2615 | 9.5.4.2615.x |
| veeam / veeam_backup_&_replication | 9.5.0.1536 | 9.5.0.1536.x |
| veeam / veeam_backup_&_replication | 10.0.1.4854-p20201202 | 10.0.1.4854-p20201202.x |
| veeam / veeam_backup_&_replication | 10.0.1.4854 | 10.0.1.4854.x |
| veeam / veeam_backup_&_replication | 10.0.0.4442 | 10.0.1.4854 |
| veeam / veeam_backup_&_replication | 11.0.0.825 | 11.0.1.1261 |