{"api_version":"1","generated_at":"2026-07-23T06:52:03+00:00","cve":"CVE-2004-1389","urls":{"html":"https://cve.report/CVE-2004-1389","api":"https://cve.report/api/cve/CVE-2004-1389.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1389","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1389"},"summary":{"title":"CVE-2004-1389","description":"Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server 5.1, and NetBackup Server 5.0 and 5.1, allows attackers to execute arbitrary commands via the bpjava-susvc process, possibly related to the call-back feature.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6","severity":"","vector":"AV:L/AC:H/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:H/Au:S/C:C/I:C/A:C","baseScore":6,"accessVector":"LOCAL","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/11494","name":"http://www.securityfocus.com/bid/11494","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Veritas NetBackup Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17811","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17811","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/12901/","name":"http://secunia.com/advisories/12901/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - VERITAS NetBackup \"bpjava-susvc\" Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seer.support.veritas.com/docs/271727.htm","name":"http://seer.support.veritas.com/docs/271727.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"VERITAS NetBackup (tm) Java GUI is susceptible to an exploit which could allow a normal user to execute commands with root authority. Anyone who administers NetBackup via the Java GUI that does not use the work-around listed below could be potentially affected by this exploit.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ciac.org/ciac/bulletins/p-020.shtml","name":"http://www.ciac.org/ciac/bulletins/p-020.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"P-020: VERITAS NetBackup (tm) Java GUI Vulnerability","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/685456","name":"http://www.kb.cert.org/vuls/id/685456","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory","US Government Resource"],"title":"US-CERT Vulnerability Note VU#685456","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1389","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1389","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1389","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"veritas","cpe5":"netbackup","cpe6":"3.4.0","cpe7":"*","cpe8":"businessserver","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1389","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"veritas","cpe5":"netbackup","cpe6":"3.4.0","cpe7":"*","cpe8":"datacenter","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1389","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"veritas","cpe5":"netbackup","cpe6":"3.4.1","cpe7":"*","cpe8":"businessserver","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1389","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"veritas","cpe5":"netbackup","cpe6":"3.4.1","cpe7":"*","cpe8":"datacenter","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1389","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"veritas","cpe5":"netbackup","cpe6":"4.5.0","cpe7":"*","cpe8":"businessserver","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1389","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"veritas","cpe5":"netbackup","cpe6":"4.5.0","cpe7":"*","cpe8":"datacenter","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1389","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"veritas","cpe5":"netbackup","cpe6":"5.0","cpe7":"*","cpe8":"server","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1389","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"veritas","cpe5":"netbackup","cpe6":"5.1","cpe7":"*","cpe8":"enterprise_server","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1389","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"veritas","cpe5":"netbackup","cpe6":"5.1","cpe7":"*","cpe8":"server","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:46:12.557Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"P-020","tags":["third-party-advisory","government-resource","x_refsource_CIAC","x_transferred"],"url":"http://www.ciac.org/ciac/bulletins/p-020.shtml"},{"name":"nebackup-bpjavasusvc-gain-privileges(17811)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17811"},{"name":"12901","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/12901/"},{"name":"VU#685456","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/685456"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://seer.support.veritas.com/docs/271727.htm"},{"name":"11494","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11494"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-10-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server 5.1, and NetBackup Server 5.0 and 5.1, allows attackers to execute arbitrary commands via the bpjava-susvc process, possibly related to the call-back feature."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"P-020","tags":["third-party-advisory","government-resource","x_refsource_CIAC"],"url":"http://www.ciac.org/ciac/bulletins/p-020.shtml"},{"name":"nebackup-bpjavasusvc-gain-privileges(17811)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17811"},{"name":"12901","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/12901/"},{"name":"VU#685456","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/685456"},{"tags":["x_refsource_CONFIRM"],"url":"http://seer.support.veritas.com/docs/271727.htm"},{"name":"11494","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11494"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1389","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server 5.1, and NetBackup Server 5.0 and 5.1, allows attackers to execute arbitrary commands via the bpjava-susvc process, possibly related to the call-back feature."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"P-020","refsource":"CIAC","url":"http://www.ciac.org/ciac/bulletins/p-020.shtml"},{"name":"nebackup-bpjavasusvc-gain-privileges(17811)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17811"},{"name":"12901","refsource":"SECUNIA","url":"http://secunia.com/advisories/12901/"},{"name":"VU#685456","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/685456"},{"name":"http://seer.support.veritas.com/docs/271727.htm","refsource":"CONFIRM","url":"http://seer.support.veritas.com/docs/271727.htm"},{"name":"11494","refsource":"BID","url":"http://www.securityfocus.com/bid/11494"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1389","datePublished":"2005-02-06T05:00:00.000Z","dateReserved":"2005-01-31T00:00:00.000Z","dateUpdated":"2024-08-08T00:46:12.557Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:H/Au:S/C:C/I:C/A:C","baseScore":6,"accessVector":"LOCAL","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":1.5,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:veritas:netbackup:3.4.0:*:businessserver:*:*:*:*:*","matchCriteriaId":"B0A9F84C-E5EF-441B-89A2-FAA8D4968681"},{"vulnerable":true,"criteria":"cpe:2.3:a:veritas:netbackup:3.4.0:*:datacenter:*:*:*:*:*","matchCriteriaId":"B8967ED7-3FE2-4F38-AA20-FCEC0C3D2CA4"},{"vulnerable":true,"criteria":"cpe:2.3:a:veritas:netbackup:3.4.1:*:businessserver:*:*:*:*:*","matchCriteriaId":"BACC4230-D744-49CE-BAB8-7D3D11877B81"},{"vulnerable":true,"criteria":"cpe:2.3:a:veritas:netbackup:3.4.1:*:datacenter:*:*:*:*:*","matchCriteriaId":"6EC2AABD-38A2-4BC4-AD91-8205808CD302"},{"vulnerable":true,"criteria":"cpe:2.3:a:veritas:netbackup:4.5.0:*:businessserver:*:*:*:*:*","matchCriteriaId":"E5CD1A9D-8EC4-4435-A266-46EB53C0C81F"},{"vulnerable":true,"criteria":"cpe:2.3:a:veritas:netbackup:4.5.0:*:datacenter:*:*:*:*:*","matchCriteriaId":"DDB99533-907E-48FD-85F5-495263CE59F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:veritas:netbackup:5.0:*:server:*:*:*:*:*","matchCriteriaId":"790282C3-9148-4D78-95ED-058D2166EB92"},{"vulnerable":true,"criteria":"cpe:2.3:a:veritas:netbackup:5.1:*:enterprise_server:*:*:*:*:*","matchCriteriaId":"D6AD552C-8462-4B56-865C-7858A1892E58"},{"vulnerable":true,"criteria":"cpe:2.3:a:veritas:netbackup:5.1:*:server:*:*:*:*:*","matchCriteriaId":"F570650A-8E21-4F66-B4D2-447FBB8EA9D9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1389","Ordinal":"1","Title":"CVE-2004-1389","CVE":"CVE-2004-1389","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1389","Ordinal":"1","NoteData":"Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server 5.1, and NetBackup Server 5.0 and 5.1, allows attackers to execute arbitrary commands via the bpjava-susvc process, possibly related to the call-back feature.","Type":"Description","Title":"CVE-2004-1389"},{"CveYear":"2004","CveId":"1389","Ordinal":"2","NoteData":"2005-02-06","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1389","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}