NAKIVO Backup & Replication XXE Vulnerability in Director NBR Component

Vulnerability

A XML External Entity (XXE) vulnerability has been identified in the Director NBR component of NAKIVO Backup & Replication, affecting versions 10.3.x through 11.0.1. This vulnerability allows remote attackers to fetch and parse the XML response, potentially leading to unauthorized access to sensitive data. By injecting a malicious host parameter, an attacker could manipulate the system into connecting to a server they control, enabling the retrieval of arbitrary files from the affected system.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive data and the ability to retrieve arbitrary files from the affected system.

Remediation

To address this vulnerability, users should upgrade to NAKIVO Backup & Replication version 11.0.2 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.5
exploitability
6.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.