← Back

CVE-2009-3027

nvd nist
Published: Dec 11, 2009Modified: Apr 23, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA) 4.3MP2, 5.0, 5.0RP1a, 5.0RP2, 5.1, and 5.1AP1; Veritas Storage Foundation for High Availability (SFHA) 3.5; Veritas Storage Foundation for Oracle (SFO) 4.1, 5.0, and 5.0.1; Veritas Storage Foundation for DB2 4.1 and 5.0; Veritas Storage Foundation for Sybase 4.1 and 5.0; Veritas Storage Foundation for Oracle Real Application Cluster (SFRAC) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Manager (SFM) 1.0, 1.0 MP1, 1.1, 1.1.1Ux, 1.1.1Win, and 2.0; Veritas Cluster Server (VCS) 3.5, 4.0, 4.1, and 5.0; Veritas Cluster Server One (VCSOne) 2.0, 2.0.1, and 2.0.2; Veritas Application Director (VAD) 1.1 and 1.1 Platform Expansion; Veritas Cluster Server Management Console (VCSMC) 5.1, 5.5, and 5.5.1; Veritas Storage Foundation Cluster File System (SFCFS) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Cluster File System for Oracle RAC (SFCFS RAC) 5.0; Veritas Command Central Storage (CCS) 4.x, 5.0, and 5.1; Veritas Command Central Enterprise Reporter (CC-ER) 5.0 GA, 5.0 MP1, 5.0 MP1RP1, and 5.1; Veritas Command Central Storage Change Manager (CC-SCM) 5.0 and 5.1; and Veritas MicroMeasure 5.0 does not properly validate authentication requests, which allows remote attackers to trigger the unpacking of a WAR archive, and execute arbitrary code in the contained files, via crafted data to TCP port 14300.

Affected (88)

Products: Symantec: Backup Exec Continuous Protection Server, Veritas Application Director, Veritas Backup Exec, Veritas Cluster Server, Veritas Cluster Server Management Console, Veritas Cluster Server One, Veritas Command Central Enterprise Reporter, Veritas Command Central Storage, Veritas Command Central Storage Change Manager, Veritas Micromeasure, Veritas Netbackup Operations Manager, Veritas Netbackup Reporter, Veritas Storae Foundation, Veritas Storage Foundation, Veritas Storage Foundation Cluster File System, Veritas Storage Foundation Cluster File System For Oracle Rac, Veritas Storage Foundation For Db2, Veritas Storage Foundation For High Availability, Veritas Storage Foundation For Oracle, Veritas Storage Foundation For Oracle Real Application Cluster, Veritas Storage Foundation For Sybase, Veritas Storage Foundation For Windows High Availability, Veritas Storage Foundation Manager
Configuration A
88 vulnerable
Vulnerable SoftwareAffected Versions
Symantec
Version 11d
Version 12.0
Version 12.5
Symantec
Version 1.1
Version 1.1
Symantec
Version 11d
Version 12.0
Version 12.5
Symantec
Version 3.5
Version 4.0
Version 4.0
Version 4.1
Version 4.1
Version 4.1
Version 5.0
Version 5.0
Version 5.0
Version 5.0
Symantec
Version 5.1
Version 5.5.1
Version 5.5
Symantec
Version 2.0.1
Version 2.0.2
Version 2.0
Symantec
Version 5.0_ga
Version 5.0mp1
Version 5.0mp1rp1
Version 5.1
Symantec
Version 4.x
Version 5.0
Version 5.1
Symantec
Version 5.0
Version 5.1
Version 5.0
Symantec
Version 6.0_ga
Version 6.5.5
Symantec
Version 6.0_ga
Version 6.6
Version 3.5_onwards
Version 3.5
Symantec
Version 3.5
Version 4.0
Version 4.0
Version 4.0
Version 4.0
Version 4.1
Version 4.1
Version 4.1
Version 4.1
Version 5.0
Version 5.0
Version 5.0
Version 5.0
Version 5.0
Symantec
Version 4.1
Version 4.1
Version 5.0
Version 5.0
Version 5.0
Version 3.5
Symantec
Version 4.1
Version 5.0.1
Version 5.0
Symantec
Version 3.5
Version 4.0
Version 4.0
Version 4.1
Version 4.1
Version 4.1 hp-ux
Version 5.0
Version 5.0
Version 5.0
Version 5.0
Version 5.0
Symantec
Version 4.1
Version 5.0
Symantec
Version 4.3mp2
Version 5.0
Version 5.0rp1a
Version 5.0rp2
Version 5.1
Version 5.1ap1
Symantec
Version 1.0
Version 1.0mp1
Version 1.1.1ux
Version 1.1.1win
Version 1.1
Version 2.0

References (48)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.