CVE-2009-3027
Summary
| CVE | CVE-2009-3027 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-12-11 16:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA) 4.3MP2, 5.0, 5.0RP1a, 5.0RP2, 5.1, and 5.1AP1; Veritas Storage Foundation for High Availability (SFHA) 3.5; Veritas Storage Foundation for Oracle (SFO) 4.1, 5.0, and 5.0.1; Veritas Storage Foundation for DB2 4.1 and 5.0; Veritas Storage Foundation for Sybase 4.1 and 5.0; Veritas Storage Foundation for Oracle Real Application Cluster (SFRAC) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Manager (SFM) 1.0, 1.0 MP1, 1.1, 1.1.1Ux, 1.1.1Win, and 2.0; Veritas Cluster Server (VCS) 3.5, 4.0, 4.1, and 5.0; Veritas Cluster Server One (VCSOne) 2.0, 2.0.1, and 2.0.2; Veritas Application Director (VAD) 1.1 and 1.1 Platform Expansion; Veritas Cluster Server Management Console (VCSMC) 5.1, 5.5, and 5.5.1; Veritas Storage Foundation Cluster File System (SFCFS) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Cluster File System for Oracle RAC (SFCFS RAC) 5.0; Veritas Command Central Storage (CCS) 4.x, 5.0, and 5.1; Veritas Command Central Enterprise Reporter (CC-ER) 5.0 GA, 5.0 MP1, 5.0 MP1RP1, and 5.1; Veritas Command Central Storage Change Manager (CC-SCM) 5.0 and 5.1; and Veritas MicroMeasure 5.0 does not properly validate authentication requests, which allows remote attackers to trigger the unpacking of a WAR archive, and execute arbitrary code in the contained files, via crafted data to TCP port 14300. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Security Advisory SYM09-017 Veritas Cluster Server Management Console 5.x patch for Linux, Solaris and Windows | af854a3a-2127-422b-91ae-364da2661108 | seer.entsupport.symantec.com | Patch, Vendor Advisory |
| HP-UX update for VRTSweb - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - Veritas Cluster Server Input Validation Flaw in VRTSweb Component Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| '[security bulletin] HPSBUX02480 SSRT090253 rev.1 - HP-UX Running VRTSweb, Remote Execution of Arbitr' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| www.securityfocus.com/bid/37012 | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Symantec Products Veritas VRTSweb Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Security Advisory SYM09-017 Storage Foundation and High Availability Solutions patches for UNIX and Linux | af854a3a-2127-422b-91ae-364da2661108 | seer.entsupport.symantec.com | Patch, Vendor Advisory |
| SecurityTracker.com Archives - HP-UX Buffer Overflow in VRTSweb Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| SecurityTracker.com Archives - Symantec Veritas Storage Foundation Input Validation Flaw in VRTSweb Component Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Symantec Products Veritas VRTSweb Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Security Advisory SYM09-017 Backup Exec Continuous Protection Server (CPS) patches for Symantec Veritas VRTSweb component | af854a3a-2127-422b-91ae-364da2661108 | seer.entsupport.symantec.com | Patch, Vendor Advisory |
| Security Advisory SYM09-017 Resolution for Storage Foundation Manager 1.x and 2.0 | af854a3a-2127-422b-91ae-364da2661108 | seer.entsupport.symantec.com | Patch, Vendor Advisory |
| Security Advisory SYM09-017 Veritas Cluster Server One 2.0 Hotfix 2 for Linux and Solaris | af854a3a-2127-422b-91ae-364da2661108 | seer.entsupport.symantec.com | Patch, Vendor Advisory |
| Security Advisory SYM09-017 CommandCentral Storage 4.x, 5.0 and 5.1 and CommandCentral Enterprise Reporter 5.0, 5.0 MP1, 5.0 MP1RP1, and 5.1 resolutions for VRTSweb component | af854a3a-2127-422b-91ae-364da2661108 | seer.entsupport.symantec.com | Patch, Vendor Advisory |
| Security Advisories Relating to Symantec Products - Symantec Veritas VRTSweb remote code execution, escalation of privilege - 2009-12-09T08:52:17 PST | Symantec | af854a3a-2127-422b-91ae-364da2661108 | www.symantec.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | Patch |
| securitytracker.com/id | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| www.osvdb.org/60884 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| SecurityTracker.com Archives - Symantec Backup Exec Continuous Protection Server Input Validation Flaw in VRTSweb Component Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.