VERITAS NetBackup Java User-Interface Remote Format String Vulnerability

BID:15079

Info

VERITAS NetBackup Java User-Interface Remote Format String Vulnerability

Bugtraq ID: 15079
Class: Input Validation Error
CVE: CVE-2005-2715
Remote: Yes
Local: No
Published: Oct 12 2005 12:00AM
Updated: Nov 01 2007 10:26PM
Credit: Discovered by Kevin Finisterre with assistance from JohnH.
Vulnerable: Veritas Software NetBackup Server 6.0
Veritas Software NetBackup Server 5.1
Veritas Software NetBackup Server 5.1
Veritas Software NetBackup Server 5.0
Veritas Software NetBackup Server 5.0
Veritas Software NetBackup Server 3.4
Veritas Software NetBackup Global Data Manager 5.0
Veritas Software NetBackup Global Data Manager 4.5 MP4
Veritas Software NetBackup Global Data Manager 4.5 MP3
Veritas Software NetBackup Global Data Manager 4.5 MP2
Veritas Software NetBackup Global Data Manager 4.5 MP1
Veritas Software NetBackup Global Data Manager 4.5 FP4
Veritas Software NetBackup Global Data Manager 4.5 FP3
Veritas Software NetBackup Global Data Manager 4.5 FP2
Veritas Software NetBackup Global Data Manager 4.5 FP1
Veritas Software NetBackup Global Data Manager 4.5
Veritas Software NetBackup for NetWare Media Servers 5.1 MP3
Veritas Software NetBackup for NetWare Media Servers 5.1 MP2
Veritas Software NetBackup for NetWare Media Servers 5.1 MP1
Veritas Software NetBackup for NetWare Media Servers 5.1
Veritas Software NetBackup for NetWare Media Servers 5.0 MP5
Veritas Software NetBackup for NetWare Media Servers 5.0 MP4
Veritas Software NetBackup for NetWare Media Servers 5.0 MP3
Veritas Software NetBackup for NetWare Media Servers 5.0 MP2
Veritas Software NetBackup for NetWare Media Servers 5.0 MP1
Veritas Software NetBackup for NetWare Media Servers 5.0
Veritas Software NetBackup for NetWare Media Servers 4.5 MP8
Veritas Software NetBackup for NetWare Media Servers 4.5 MP7
Veritas Software NetBackup for NetWare Media Servers 4.5 MP6
Veritas Software NetBackup for NetWare Media Servers 4.5 MP5
Veritas Software NetBackup for NetWare Media Servers 4.5 MP4
Veritas Software NetBackup for NetWare Media Servers 4.5 MP3
Veritas Software NetBackup for NetWare Media Servers 4.5 MP2
Veritas Software NetBackup for NetWare Media Servers 4.5 MP1
Veritas Software NetBackup for NetWare Media Servers 4.5 FP8
Veritas Software NetBackup for NetWare Media Servers 4.5 FP7
Veritas Software NetBackup for NetWare Media Servers 4.5 FP6
Veritas Software NetBackup for NetWare Media Servers 4.5 FP5
Veritas Software NetBackup for NetWare Media Servers 4.5 FP4
Veritas Software NetBackup for NetWare Media Servers 4.5 FP3
Veritas Software NetBackup for NetWare Media Servers 4.5 FP2
Veritas Software NetBackup for NetWare Media Servers 4.5 FP1
Veritas Software NetBackup for NetWare Media Servers 4.5
Veritas Software NetBackup Enterprise Server 6.0
Veritas Software NetBackup Enterprise Server 5.1
Veritas Software NetBackup Enterprise Server 5.0
Veritas Software NetBackup DataCenter 5.0
Veritas Software NetBackup DataCenter 4.5 MP
Veritas Software NetBackup DataCenter 4.5 FP
Veritas Software NetBackup DataCenter 4.5
Veritas Software NetBackup DataCenter 3.4
Veritas Software NetBackup Client 6.0
Veritas Software NetBackup Client 5.1
Veritas Software NetBackup Client 5.0
Veritas Software NetBackup BusinesServer 4.5 MP
Veritas Software NetBackup BusinesServer 4.5 FP
Veritas Software NetBackup BusinesServer 4.5
Veritas Software NetBackup BusinesServer 3.4
Veritas Software NetBackup Advanced Reporter 4.5 MP4
Veritas Software NetBackup Advanced Reporter 4.5 MP3
Veritas Software NetBackup Advanced Reporter 4.5 MP2
Veritas Software NetBackup Advanced Reporter 4.5 MP1
Veritas Software NetBackup Advanced Reporter 4.5 FP4
Veritas Software NetBackup Advanced Reporter 4.5 FP3
Veritas Software NetBackup Advanced Reporter 4.5 FP2
Veritas Software NetBackup Advanced Reporter 4.5 FP1
Veritas Software NetBackup Advanced Reporter 4.5
Not Vulnerable: Veritas Software NetBackup DataCenter for Windows 4.5 MP
Veritas Software NetBackup BusinesServer for Windows 4.5 MP

Discussion

VERITAS NetBackup Java User-Interface Remote Format String Vulnerability

NetBackup Java user interface is affected by a remote format-string vulnerability.

An attacker can exploit this vulnerability by crafting a malicious request that contains format specifiers. A successful attack may crash the server or lead to arbitrary code execution. This may facilitate unauthorized access or privilege escalation with SYSTEM or superuser privileges.

Exploit / POC

VERITAS NetBackup Java User-Interface Remote Format String Vulnerability

Exploits for Windows, Linux, and Mac OS X platforms have been supplied by <[email protected]> & <[email protected]>.

VERITAS-Linux.pl.gpg:

pass: allaroundthemulberrybush

VERITAS-OSX.pl.gpg:

pass: themonkeychasedtheweasel

VERITAS-WIN32.pl.gpg:

pass: apennyforaneedle

The following exploit is available to members of the Immunity Partner's Program:

https://www.immunityinc.com/downloads/immpartners/netbackup_javaui.tgz

UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

Solution / Fix

VERITAS NetBackup Java User-Interface Remote Format String Vulnerability

Solution:
Fixes are available.


Veritas Software NetBackup DataCenter 4.5 FP

Veritas Software NetBackup DataCenter 4.5 MP

Veritas Software NetBackup BusinesServer 4.5 FP

Veritas Software NetBackup BusinesServer 4.5 MP

Veritas Software NetBackup Enterprise Server 5.0

Veritas Software NetBackup Server 5.0

Veritas Software NetBackup Server 5.0

Veritas Software NetBackup Enterprise Server 5.1

Veritas Software NetBackup Server 5.1

Veritas Software NetBackup Server 5.1

Veritas Software NetBackup Server 6.0

Veritas Software NetBackup Enterprise Server 6.0

References

VERITAS NetBackup Java User-Interface Remote Format String Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report