VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA) 4.3MP2, 5.0, 5.0RP1a, 5.0RP2, 5.1, and 5.1AP1; Veritas Storage Foundation for High Availability (SFHA) 3.5; Veritas Storage Foundation for Oracle (SFO) 4.1, 5.0, and 5.0.1; Veritas Storage Foundation for DB2 4.1 and 5.0; Veritas Storage Foundation for Sybase 4.1 and 5.0; Veritas Storage Foundation for Oracle Real Application Cluster (SFRAC) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Manager (SFM) 1.0, 1.0 MP1, 1.1, 1.1.1Ux, 1.1.1Win, and 2.0; Veritas Cluster Server (VCS) 3.5, 4.0, 4.1, and 5.0; Veritas Cluster Server One (VCSOne) 2.0, 2.0.1, and 2.0.2; Veritas Application Director (VAD) 1.1 and 1.1 Platform Expansion; Veritas Cluster Server Management Console (VCSMC) 5.1, 5.5, and 5.5.1; Veritas Storage Foundation Cluster File System (SFCFS) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Cluster File System for Oracle RAC (SFCFS RAC) 5.0; Veritas Command Central Storage (CCS) 4.x, 5.0, and 5.1; Veritas Command Central Enterprise Reporter (CC-ER) 5.0 GA, 5.0 MP1, 5.0 MP1RP1, and 5.1; Veritas Command Central Storage Change Manager (CC-SCM) 5.0 and 5.1; and Veritas MicroMeasure 5.0 does not properly validate authentication requests, which allows remote attackers to trigger the unpacking of a WAR archive, and execute arbitrary code in the contained files, via crafted data to TCP port 14300.

Project Subscriptions

Vendors Products
Symantec Subscribe
Backup Exec Continuous Protection Server Subscribe
Veritas Application Director Subscribe
Veritas Backup Exec Subscribe
Veritas Cluster Server Subscribe
Veritas Cluster Server Management Console Subscribe
Veritas Cluster Server One Subscribe
Veritas Command Central Enterprise Reporter Subscribe
Veritas Command Central Storage Subscribe
Veritas Command Central Storage Change Manager Subscribe
Veritas Micromeasure Subscribe
Veritas Netbackup Operations Manager Subscribe
Veritas Netbackup Reporter Subscribe
Veritas Storae Foundation Subscribe
Veritas Storage Foundation Subscribe
Veritas Storage Foundation Cluster File System Subscribe
Veritas Storage Foundation Cluster File System For Oracle Rac Subscribe
Veritas Storage Foundation For Db2 Subscribe
Veritas Storage Foundation For High Availability Subscribe
Veritas Storage Foundation For Oracle Subscribe
Veritas Storage Foundation For Oracle Real Application Cluster Subscribe
Veritas Storage Foundation For Sybase Subscribe
Veritas Storage Foundation For Windows High Availability Subscribe
Veritas Storage Foundation Manager Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T06:14:56.480Z

Reserved: 2009-08-31T00:00:00

Link: CVE-2009-3027

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2009-12-11T16:30:00.203

Modified: 2025-04-09T00:30:58.490

Link: CVE-2009-3027

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses