CVE-2004-1389
Summary
| CVE | CVE-2004-1389 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server 5.1, and NetBackup Server 5.0 and 5.1, allows attackers to execute arbitrary commands via the bpjava-susvc process, possibly related to the call-back feature. |
Risk And Classification
Primary CVSS: v2.0 6 from [email protected]
AV:L/AC:H/Au:S/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
HighAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:H/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Veritas | Netbackup | 3.4.0 | All | businessserver | All |
| Application | Veritas | Netbackup | 3.4.0 | All | datacenter | All |
| Application | Veritas | Netbackup | 3.4.1 | All | businessserver | All |
| Application | Veritas | Netbackup | 3.4.1 | All | datacenter | All |
| Application | Veritas | Netbackup | 4.5.0 | All | businessserver | All |
| Application | Veritas | Netbackup | 4.5.0 | All | datacenter | All |
| Application | Veritas | Netbackup | 5.0 | All | server | All |
| Application | Veritas | Netbackup | 5.1 | All | enterprise_server | All |
| Application | Veritas | Netbackup | 5.1 | All | server | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Veritas NetBackup Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Secunia - Advisories - VERITAS NetBackup "bpjava-susvc" Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| VERITAS NetBackup (tm) Java GUI is susceptible to an exploit which could allow a normal user to execute commands with root authority. Anyone who administers NetBackup via the Java GUI that does not use the work-around listed below could be potentially affected by this exploit. | af854a3a-2127-422b-91ae-364da2661108 | seer.support.veritas.com | Patch, Vendor Advisory |
| P-020: VERITAS NetBackup (tm) Java GUI Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.ciac.org | Patch, Vendor Advisory |
| US-CERT Vulnerability Note VU#685456 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Patch, Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.