Impact of CVE-2024-50379, CVE-2024-56337 and CVE-2024-54677 affecting Apache Tomcat on Veritas NetBackup, OpsCenter & Appliances Platform

Article: 100073477
Last Published: 2025-03-07
Ratings: 1 0
Product(s): Appliances, NetBackup & Alta Data Protection

 

Description:

NetBackup 10.5.0.1 shipped with Apache Tomcat version 10.1.34 and this version does not report the CVE vulnerabilities.

For previous versions of NetBackup, there is no impact from the CVEs as explained below:

  • CVE-2024-50379: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat  

    https://nvd.nist.gov/vuln/detail/CVE-2024-50379  

    Impact: 
    Veritas NetBackup, OpsCenter and Appliances versions are NOT vulnerable because we do not have the default servlet enabled for write. 

  • CVE-2024-56337: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat 

    https://nvd.nist.gov/vuln/detail/CVE-2024-56337  

    Impact: 
    Veritas NetBackup, OpsCenter and Appliances versions are NOT vulnerable because we do not have the default servlet enabled for write.

  • CVE-2024-54677: Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat 

    https://nvd.nist.gov/vuln/detail/CVE-2024-54677   

    Impact: 
    Veritas NetBackup, OpsCenter and Appliances versions are NOT vulnerable because we do not ship any of Tomcat's default applications. 

 

 

Questions

For questions or problems regarding these vulnerabilities, please contact Technical Support (https://www.veritas.com/support)  

Disclaimer

THE SECURITY ADVISORY IS PROVIDED "AS IS" AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT, ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TO BE LEGALLY INVALID. VERITAS TECHNOLOGIES LLC SHALL NOT BE LIABLE FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE FURNISHING, PERFORMANCE, OR USE OF THIS DOCUMENTATION. THE INFORMATION CONTAINED IN THIS DOCUMENTATION IS SUBJECT TO CHANGE WITHOUT NOTICE. 

Cohesity, Inc. 
300 Park Ave Ste 1700, San Jose, CA 95110 

Was this content helpful?