10

CVE-2009-3027

VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA) 4.3MP2, 5.0, 5.0RP1a, 5.0RP2, 5.1, and 5.1AP1; Veritas Storage Foundation for High Availability (SFHA) 3.5; Veritas Storage Foundation for Oracle (SFO) 4.1, 5.0, and 5.0.1; Veritas Storage Foundation for DB2 4.1 and 5.0; Veritas Storage Foundation for Sybase 4.1 and 5.0; Veritas Storage Foundation for Oracle Real Application Cluster (SFRAC) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Manager (SFM) 1.0, 1.0 MP1, 1.1, 1.1.1Ux, 1.1.1Win, and 2.0; Veritas Cluster Server (VCS) 3.5, 4.0, 4.1, and 5.0; Veritas Cluster Server One (VCSOne) 2.0, 2.0.1, and 2.0.2; Veritas Application Director (VAD) 1.1 and 1.1 Platform Expansion; Veritas Cluster Server Management Console (VCSMC) 5.1, 5.5, and 5.5.1; Veritas Storage Foundation Cluster File System (SFCFS) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Cluster File System for Oracle RAC (SFCFS RAC) 5.0; Veritas Command Central Storage (CCS) 4.x, 5.0, and 5.1; Veritas Command Central Enterprise Reporter (CC-ER) 5.0 GA, 5.0 MP1, 5.0 MP1RP1, and 5.1; Veritas Command Central Storage Change Manager (CC-SCM) 5.0 and 5.1; and Veritas MicroMeasure 5.0 does not properly validate authentication requests, which allows remote attackers to trigger the unpacking of a WAR archive, and execute arbitrary code in the contained files, via crafted data to TCP port 14300.

Data is provided by the National Vulnerability Database (NVD)
SymantecVeritas Application Director Version1.1 Editionplatform_expansion
SymantecVeritas Backup Exec Version11d
SymantecVeritas Backup Exec Version12.0
SymantecVeritas Backup Exec Version12.5
SymantecVeritas Cluster Server Version3.5 Editionhp-ux
SymantecVeritas Cluster Server Version4.0 Editionaix
SymantecVeritas Cluster Server Version4.0 Editionlinux
SymantecVeritas Cluster Server Version4.1 Editionhp-ux
SymantecVeritas Cluster Server Version4.1 Editionlinux
SymantecVeritas Cluster Server Version4.1 Editionsolaris
SymantecVeritas Cluster Server Version5.0 Editionaix
SymantecVeritas Cluster Server Version5.0 Editionhp-ux
SymantecVeritas Cluster Server Version5.0 Editionlinux
SymantecVeritas Cluster Server Version5.0 Editionsolaris
SymantecVeritas Storae Foundation Version3.5_onwards
SymantecVeritas Storage Foundation For Db2 Version4.1 Editionlinux
SymantecVeritas Storage Foundation For Db2 Version4.1 Editionsolaris
SymantecVeritas Storage Foundation For Db2 Version5.0 Editionaix
SymantecVeritas Storage Foundation For Db2 Version5.0 Editionlinux
SymantecVeritas Storage Foundation For Db2 Version5.0 Editionsolaris
SymantecVeritas Storage Foundation For Sybase Version4.1 Editionsolaris
SymantecVeritas Storage Foundation For Sybase Version5.0 Editionsolaris
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 43.91% 0.972
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.