CVE-2023-28818: Veritas Aptare It Analytics

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exploited and result in a customer installing unauthentic components. A malicious actor could install rogue Collector executable files (aptare.jar or upgrademanager.zip) on the Portal server, which might then be downloaded and installed on collectors.

Affected products

  • Veritas Aptare It Analytics: before 10.6.00 (fixed in 10.6.00)
  • Veritas Netbackup It Analytics: version 11.0.00 only; version 11.1.00 only

Published 2023-03-24. Last modified 2026-06-17.