Vulnerabilities (CVE)

Filtered by vendor Veritas
Filtered by product Desktop And Laptop Option
Angry Yack Logo
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-41319 1 Veritas 1 Desktop And Laptop Option 2025-05-27 N/A 6.1 MEDIUM
A Reflected Cross-Site Scripting (XSS) vulnerability affects the Veritas Desktop Laptop Option (DLO) application login page (aka the DLOServer/restore/login.jsp URI). This affects versions before 9.8 (e.g., 9.1 through 9.7).
CVE-2020-36165 2 Microsoft, Veritas 2 Windows, Desktop And Laptop Option 2024-11-21 7.2 HIGH 9.3 CRITICAL
An issue was discovered in Veritas Desktop and Laptop Option (DLO) before 9.4. On start-up, it loads the OpenSSL library from /ReleaseX64/ssl. This library attempts to load the /ReleaseX64/ssl/openssl.cnf configuration file, which does not exist. By default, on Windows systems, users can create directories under C:\. A low privileged user can create a C:/ReleaseX64/ssl/openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the serv ...

Show More

CVE-2020-36159 1 Veritas 1 Desktop And Laptop Option 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Veritas Desktop and Laptop Option (DLO) before 9.5 disclosed operational information on the backup processing status through a URL that did not require authentication.