Impact of CVE-2024-50379, CVE-2024-56337 and CVE-2024-54677 affecting Apache Tomcat on Veritas NetBackup, OpsCenter & Appliances Platform
Description:
NetBackup 10.5.0.1 shipped with Apache Tomcat version 10.1.34 and this version does not report the CVE vulnerabilities.
For previous versions of NetBackup, there is no impact from the CVEs as explained below:
CVE-2024-50379: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat
https://nvd.nist.gov/vuln/detail/CVE-2024-50379
Impact:
Veritas NetBackup, OpsCenter and Appliances versions are NOT vulnerable because we do not have the default servlet enabled for write.CVE-2024-56337: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat
https://nvd.nist.gov/vuln/detail/CVE-2024-56337
Impact:
Veritas NetBackup, OpsCenter and Appliances versions are NOT vulnerable because we do not have the default servlet enabled for write.CVE-2024-54677: Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat
https://nvd.nist.gov/vuln/detail/CVE-2024-54677
Impact:
Veritas NetBackup, OpsCenter and Appliances versions are NOT vulnerable because we do not ship any of Tomcat's default applications.
Questions
For questions or problems regarding these vulnerabilities, please contact Technical Support (https://www.veritas.com/support)
Disclaimer
THE SECURITY ADVISORY IS PROVIDED "AS IS" AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT, ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TO BE LEGALLY INVALID. VERITAS TECHNOLOGIES LLC SHALL NOT BE LIABLE FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE FURNISHING, PERFORMANCE, OR USE OF THIS DOCUMENTATION. THE INFORMATION CONTAINED IN THIS DOCUMENTATION IS SUBJECT TO CHANGE WITHOUT NOTICE.
Cohesity, Inc.
300 Park Ave Ste 1700, San Jose, CA 95110