NAKIVO Backup & Replication XXE Vulnerability in Director NBR Component
Vulnerability
A XML External Entity (XXE) vulnerability has been identified in the Director NBR component of NAKIVO Backup & Replication, affecting versions 10.3.x through 11.0.1. This vulnerability allows remote attackers to fetch and parse the XML response, potentially leading to unauthorized access to sensitive data. By injecting a malicious host parameter, an attacker could manipulate the system into connecting to a server they control, enabling the retrieval of arbitrary files from the affected system.
Impact
Exploitation of this vulnerability could result in unauthorized access to sensitive data and the ability to retrieve arbitrary files from the affected system.
Remediation
To address this vulnerability, users should upgrade to NAKIVO Backup & Replication version 11.0.2 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
