HIGH · 10.0

CVE-2009-3027

VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6....

Vulnerability Description

VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA) 4.3MP2, 5.0, 5.0RP1a, 5.0RP2, 5.1, and 5.1AP1; Veritas Storage Foundation for High Availability (SFHA) 3.5; Veritas Storage Foundation for Oracle (SFO) 4.1, 5.0, and 5.0.1; Veritas Storage Foundation for DB2 4.1 and 5.0; Veritas Storage Foundation for Sybase 4.1 and 5.0; Veritas Storage Foundation for Oracle Real Application Cluster (SFRAC) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Manager (SFM) 1.0, 1.0 MP1, 1.1, 1.1.1Ux, 1.1.1Win, and 2.0; Veritas Cluster Server (VCS) 3.5, 4.0, 4.1, and 5.0; Veritas Cluster Server One (VCSOne) 2.0, 2.0.1, and 2.0.2; Veritas Application Director (VAD) 1.1 and 1.1 Platform Expansion; Veritas Cluster Server Management Console (VCSMC) 5.1, 5.5, and 5.5.1; Veritas Storage Foundation Cluster File System (SFCFS) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Cluster File System for Oracle RAC (SFCFS RAC) 5.0; Veritas Command Central Storage (CCS) 4.x, 5.0, and 5.1; Veritas Command Central Enterprise Reporter (CC-ER) 5.0 GA, 5.0 MP1, 5.0 MP1RP1, and 5.1; Veritas Command Central Storage Change Manager (CC-SCM) 5.0 and 5.1; and Veritas MicroMeasure 5.0 does not properly validate authentication requests, which allows remote attackers to trigger the unpacking of a WAR archive, and execute arbitrary code in the contained files, via crafted data to TCP port 14300.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
SymantecBackup Exec Continuous Protection Server11d
SymantecVeritas Application Director1.1
SymantecVeritas Backup Exec11d
SymantecVeritas Cluster Server3.5
SymantecVeritas Cluster Server Management Console5.1
SymantecVeritas Cluster Server One2.0
SymantecVeritas Command Central Enterprise Reporter5.0_ga
SymantecVeritas Command Central Storage4.x
SymantecVeritas Command Central Storage Change Manager5.0
SymantecVeritas Micromeasure5.0
SymantecVeritas Netbackup Operations Manager6.0_ga
SymantecVeritas Netbackup Reporter6.0_ga
SymantecVeritas Storae Foundation3.5_onwards
SymantecVeritas Storage Foundation3.5
SymantecVeritas Storage Foundation Cluster File System3.5
SymantecVeritas Storage Foundation Cluster File System For Oracle Rac5.0
SymantecVeritas Storage Foundation For Db24.1
SymantecVeritas Storage Foundation For High Availability3.5
SymantecVeritas Storage Foundation For Oracle4.1
SymantecVeritas Storage Foundation For Oracle Real Application Cluster3.5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-3027?

CVE-2009-3027 is a vulnerability with a CVSS score of 10.0 (HIGH). VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6....

How severe is CVE-2009-3027?

CVE-2009-3027 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-3027?

Check the references section above for vendor advisories and patch information. Affected products include: Symantec Backup Exec Continuous Protection Server, Symantec Veritas Application Director, Symantec Veritas Backup Exec, Symantec Veritas Cluster Server, Symantec Veritas Cluster Server Management Console.