Loading...
Loading...
All vulnerabilities disclosed in this article affect Veeam Service Provider Console 9.2.0.33215 and all earlier version 9 builds.
This vulnerability was fixed starting with the following build: Veeam Service Provider Console 9.2.1.33875
This vulnerability can only be exploited when alarm script execution is enabled. Starting in Veeam Service Provider Console 9.2.0.33215, alarm script execution is disabled by default. The default applies to new deployments and to upgrades where no alarms had a script execution action configured; deployments where this setting remained at the default are not affected by this vulnerability. Note: The mitigation method discussed below cannot be applied to builds older than Veeam Service Provider Console 9.2.0.33215, because the setting AlarmManagement_ScriptExecutionEnabled was introduced in Veeam Service Provider Console 9.2.0.33215. Therefore, all builds prior to 9.2.0.33215 (e.g., 9.1, 9.0, and 8) are affected and must be upgraded to 9.2.1.33875. To check whether a Veeam Service Provider Console 9.2.0.33215 deployment is affected: On the Veeam Service Provider Console server, open the following file in a text editor: C:\ProgramData\Veeam\Veeam Availability Console\Configuration\Service\configuration.overrides.json Within the configuration.overrides.json file, identify the value "AlarmManagement_ScriptExecutionEnabled": If this setting is not present in the file, the deployment is not affected, and alarms with script execution are disabled by default. If this value is set to False, then the deployment is not affected. If the value is set to True, the issue can be mitigated prior to applying 9.2.1.33875 by setting the value to False and restarting the Veeam Management Portal Service.
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.