Sensitive Information Disclosure Vulnerability: Password Stored in Windows Registry
Backup Exec System Recovery (SR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the backup configuration. This vulnerability could provide a Windows user who has sufficient privileges to access a network file system which they were not authorized to access.
Customers under a current maintenance contract can download and install application binaries which mitigate this vulnerability, as described below:
If you are on SR 18:
If you are on SR 21:
See the Backup Exec Download Center for available updates: https://supportbackupexec.cloud.com/support-home/home
A Sensitive Information Disclosure Vulnerability has been found in Backup Exec System Recovery (SR).