CVE Feed

    Dashboard / CVE / CVE-2009-3027

    CVE-2009-3027

    VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA) 4.3MP2, 5.0, 5.0RP1a, 5.0RP2, 5.1, and 5.1AP1; Veritas Storage Foundation for High Availability (SFHA) 3.5; Veritas Storage Foundation for Oracle (SFO) 4.1, 5.0, and 5.0.1; Veritas Storage Foundation for DB2 4.1 and 5.0; Veritas Storage Foundation for Sybase 4.1 and 5.0; Veritas Storage Foundation for Oracle Real Application Cluster (SFRAC) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Manager (SFM) 1.0, 1.0 MP1, 1.1, 1.1.1Ux, 1.1.1Win, and 2.0; Veritas Cluster Server (VCS) 3.5, 4.0, 4.1, and 5.0; Veritas Cluster Server One (VCSOne) 2.0, 2.0.1, and 2.0.2; Veritas Application Director (VAD) 1.1 and 1.1 Platform Expansion; Veritas Cluster Server Management Console (VCSMC) 5.1, 5.5, and 5.5.1; Veritas Storage Foundation Cluster File System (SFCFS) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Cluster File System for Oracle RAC (SFCFS RAC) 5.0; Veritas Command Central Storage (CCS) 4.x, 5.0, and 5.1; Veritas Command Central Enterprise Reporter (CC-ER) 5.0 GA, 5.0 MP1, 5.0 MP1RP1, and 5.1; Veritas Command Central Storage Change Manager (CC-SCM) 5.0 and 5.1; and Veritas MicroMeasure 5.0 does not properly validate authentication requests, which allows remote attackers to trigger the unpacking of a WAR archive, and execute arbitrary code in the contained files, via crafted data to TCP port 14300.

    Published:Dec 11, 2009
    Last Modified:Apr 23, 2026
    EPS:Dec 11, 2009
    EPSS Score:0.43912
    CVSS Score:10

    Affected Products

    Vendor
    Symantec
    Product
    Backup Exec Continuous Protection Server
    Vendor
    Symantec
    Product
    Veritas Application Director
    Vendor
    Symantec
    Product
    Veritas Backup Exec
    Vendor
    Symantec
    Product
    Veritas Cluster Server
    Vendor
    Symantec
    Product
    Veritas Cluster Server Management Console
    Vendor
    Symantec
    Product
    Veritas Cluster Server One
    Vendor
    Symantec
    Product
    Veritas Command Central Enterprise Reporter
    Vendor
    Symantec
    Product
    Veritas Command Central Storage
    Vendor
    Symantec
    Product
    Veritas Command Central Storage Change Manager
    Vendor
    Symantec
    Product
    Veritas Micromeasure
    Vendor
    Symantec
    Product
    Veritas Netbackup Operations Manager
    Vendor
    Symantec
    Product
    Veritas Netbackup Reporter
    Vendor
    Symantec
    Product
    Veritas Storae Foundation
    Vendor
    Symantec
    Product
    Veritas Storage Foundation
    Vendor
    Symantec
    Product
    Veritas Storage Foundation Cluster File System
    Vendor
    Symantec
    Product
    Veritas Storage Foundation Cluster File System For Oracle Rac
    Vendor
    Symantec
    Product
    Veritas Storage Foundation For Db2
    Vendor
    Symantec
    Product
    Veritas Storage Foundation For High Availability
    Vendor
    Symantec
    Product
    Veritas Storage Foundation For Oracle
    Vendor
    Symantec
    Product
    Veritas Storage Foundation For Oracle Real Application Cluster
    Vendor
    Symantec
    Product
    Veritas Storage Foundation For Sybase
    Vendor
    Symantec
    Product
    Veritas Storage Foundation For Windows High Availability
    Vendor
    Symantec
    Product
    Veritas Storage Foundation Manager

    Exploits

    No exploit reference

    Common Weakness Enumeration

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High