CVE-2009-3027

UnknownEPSS 10.61%

Last modified

CVE-2009-3027 is a vulnerability of currently unknown severity. VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA) 4.3MP2, 5.0, 5.0RP1a, 5.0RP2, 5.1, and 5.1AP1; Veritas Storage Foundation for High Availability (SFHA) 3.5; Veritas Storage Foundation for Oracle (SFO) 4.1, 5.0, and 5.0.1; Veritas Storage Foundation for DB2 4.1 and 5.0; Veritas Storage Foundation for Sybase 4.1 and 5.0; Veritas Storage Foundation for Oracle Real Application Cluster (SFRAC) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Manager (SFM) 1.0, 1.0 MP1, 1.1, 1.1.1Ux, 1.1.1Win, and 2.0; Veritas Cluster Server (VCS) 3.5, 4.0, 4.1, and 5.0; Veritas Cluster Server One (VCSOne) 2.0, 2.0.1, and 2.0.2; Veritas Application Director (VAD) 1.1 and 1.1 Platform Expansion; Veritas Cluster Server Management Console (VCSMC) 5.1, 5.5, and 5.5.1; Veritas Storage Foundation Cluster File System (SFCFS) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Cluster File System for Oracle RAC (SFCFS RAC) 5.0; Veritas Command Central Storage (CCS) 4.x, 5.0, and 5.1; Veritas Command Central Enterprise Reporter (CC-ER) 5.0 GA, 5.0 MP1, 5.0 MP1RP1, and 5.1; Veritas Command Central Storage Change Manager (CC-SCM) 5.0 and 5.1; and Veritas MicroMeasure 5.0 does not properly validate authentication requests, which allows remote attackers to trigger the unpacking of a WAR archive, and execute arbitrary code in the contained files, via crafted data to TCP port 14300.. EPSS estimates a 10.61% chance of exploitation in the next 30 days.

Description

VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA) 4.3MP2, 5.0, 5.0RP1a, 5.0RP2, 5.1, and 5.1AP1; Veritas Storage Foundation for High Availability (SFHA) 3.5; Veritas Storage Foundation for Oracle (SFO) 4.1, 5.0, and 5.0.1; Veritas Storage Foundation for DB2 4.1 and 5.0; Veritas Storage Foundation for Sybase 4.1 and 5.0; Veritas Storage Foundation for Oracle Real Application Cluster (SFRAC) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Manager (SFM) 1.0, 1.0 MP1, 1.1, 1.1.1Ux, 1.1.1Win, and 2.0; Veritas Cluster Server (VCS) 3.5, 4.0, 4.1, and 5.0; Veritas Cluster Server One (VCSOne) 2.0, 2.0.1, and 2.0.2; Veritas Application Director (VAD) 1.1 and 1.1 Platform Expansion; Veritas Cluster Server Management Console (VCSMC) 5.1, 5.5, and 5.5.1; Veritas Storage Foundation Cluster File System (SFCFS) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Cluster File System for Oracle RAC (SFCFS RAC) 5.0; Veritas Command Central Storage (CCS) 4.x, 5.0, and 5.1; Veritas Command Central Enterprise Reporter (CC-ER) 5.0 GA, 5.0 MP1, 5.0 MP1RP1, and 5.1; Veritas Command Central Storage Change Manager (CC-SCM) 5.0 and 5.1; and Veritas MicroMeasure 5.0 does not properly validate authentication requests, which allows remote attackers to trigger the unpacking of a WAR archive, and execute arbitrary code in the contained files, via crafted data to TCP port 14300.

Metrics

EPSS Probability
10.61%

95.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SymantecBackup Exec Continuous Protection Server11d
SymantecBackup Exec Continuous Protection Server12.0
SymantecBackup Exec Continuous Protection Server12.5
SymantecVeritas Application Director1.1
SymantecVeritas Backup Exec11d
SymantecVeritas Backup Exec12.0
SymantecVeritas Backup Exec12.5
SymantecVeritas Cluster Server3.5
SymantecVeritas Cluster Server4.0
SymantecVeritas Cluster Server4.1
SymantecVeritas Cluster Server5.0
SymantecVeritas Cluster Server Management Console5.1
SymantecVeritas Cluster Server Management Console5.5
SymantecVeritas Cluster Server Management Console5.5.1
SymantecVeritas Cluster Server One2.0
SymantecVeritas Cluster Server One2.0.1
SymantecVeritas Cluster Server One2.0.2
SymantecVeritas Command Central Enterprise Reporter5.0_ga
SymantecVeritas Command Central Enterprise Reporter5.0mp1
SymantecVeritas Command Central Enterprise Reporter5.0mp1rp1
SymantecVeritas Command Central Enterprise Reporter5.1
SymantecVeritas Command Central Storage4.x
SymantecVeritas Command Central Storage5.0
SymantecVeritas Command Central Storage5.1
SymantecVeritas Command Central Storage Change Manager5.0
SymantecVeritas Command Central Storage Change Manager5.1
SymantecVeritas Micromeasure5.0
SymantecVeritas Netbackup Operations Manager6.0_ga
SymantecVeritas Netbackup Operations Manager6.5.5
SymantecVeritas Netbackup Reporter6.0_ga
SymantecVeritas Netbackup Reporter6.6
SymantecVeritas Storae Foundation3.5_onwards
SymantecVeritas Storage Foundation3.5
SymantecVeritas Storage Foundation Cluster File System3.5
SymantecVeritas Storage Foundation Cluster File System4.0
SymantecVeritas Storage Foundation Cluster File System4.1
SymantecVeritas Storage Foundation Cluster File System5.0
SymantecVeritas Storage Foundation Cluster File System For Oracle Rac5.0
SymantecVeritas Storage Foundation For Db24.1
SymantecVeritas Storage Foundation For Db25.0
SymantecVeritas Storage Foundation For High Availability3.5
SymantecVeritas Storage Foundation For Oracle4.1
SymantecVeritas Storage Foundation For Oracle5.0
SymantecVeritas Storage Foundation For Oracle5.0.1
SymantecVeritas Storage Foundation For Oracle Real Application Cluster3.5
SymantecVeritas Storage Foundation For Oracle Real Application Cluster4.0
SymantecVeritas Storage Foundation For Oracle Real Application Cluster4.1
SymantecVeritas Storage Foundation For Oracle Real Application Cluster5.0
SymantecVeritas Storage Foundation For Sybase4.1
SymantecVeritas Storage Foundation For Sybase5.0

Showing 50 of 62 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-3027?
VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA) 4.3MP2, 5.0, 5.0RP1a, 5.0RP2, 5.1, and 5.1AP1; Veritas Storage Foundation for High Availability (SFHA) 3.5; Veritas Storage Foundation for Oracle (SFO) 4.1, 5.0, and 5.0.1; Veritas Storage Foundation for DB2 4.1 and 5.0; Veritas Storage Foundation for Sybase 4.1 and 5.0; Veritas Storage Foundation for Oracle Real Application Cluster (SFRAC) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Manager (SFM) 1.0, 1.0 MP1, 1.1, 1.1.1Ux, 1.1.1Win, and 2.0; Veritas Cluster Server (VCS) 3.5, 4.0, 4.1, and 5.0; Veritas Cluster Server One (VCSOne) 2.0, 2.0.1, and 2.0.2; Veritas Application Director (VAD) 1.1 and 1.1 Platform Expansion; Veritas Cluster Server Management Console (VCSMC) 5.1, 5.5, and 5.5.1; Veritas Storage Foundation Cluster File System (SFCFS) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Cluster File System for Oracle RAC (SFCFS RAC) 5.0; Veritas Command Central Storage (CCS) 4.x, 5.0, and 5.1; Veritas Command Central Enterprise Reporter (CC-ER) 5.0 GA, 5.0 MP1, 5.0 MP1RP1, and 5.1; Veritas Command Central Storage Change Manager (CC-SCM) 5.0 and 5.1; and Veritas MicroMeasure 5.0 does not properly validate authentication requests, which allows remote attackers to trigger the unpacking of a WAR archive, and execute arbitrary code in the contained files, via crafted data to TCP port 14300.
How severe is CVE-2009-3027?
Severity scoring for CVE-2009-3027 is pending analysis. The EPSS model estimates a 10.61% probability of exploitation in the next 30 days.
How do I fix CVE-2009-3027?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-3027?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST