Symantec Veritas NetBackup Java Administration GUI Remote Privilege Escalation Vulnerability
BID:31221
Info
Symantec Veritas NetBackup Java Administration GUI Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 31221 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4339 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 24 2008 12:00AM |
| Updated: | Apr 16 2015 05:54PM |
| Credit: | Noonan of Sun Microsystems |
| Vulnerable: |
Symantec Veritas NetBackup Server 6.5 Symantec Veritas NetBackup Server 6.0 Symantec Veritas NetBackup Server 5.1 Symantec Veritas NetBackup Enterprise Server 6.5 Symantec Veritas NetBackup Enterprise Server 6.0 Symantec Veritas NetBackup Enterprise Server 5.1 Hitachi JP1/VERITAS NetBackup 6.5 08-13 (Windows) Hitachi JP1/VERITAS NetBackup 6.5 08-12 (windows) Hitachi JP1/VERITAS NetBackup 6.5 08-11 (Windows) Hitachi JP1/VERITAS NetBackup 6.5 08-10 (Windows) Hitachi JP1/VERITAS NetBackup 6.0 07-67 (Windows) Hitachi JP1/VERITAS NetBackup 6.0 07-66 (Windows) Hitachi JP1/VERITAS NetBackup 6.0 07-65 (Windows) Hitachi JP1/VERITAS NetBackup 6.0 07-64 (Windows) Hitachi JP1/VERITAS NetBackup 6.0 07-63 (Windows) Hitachi JP1/VERITAS NetBackup 6.0 07-62 (Windows) Hitachi JP1/VERITAS NetBackup 6.0 07-61 (Windows) Hitachi JP1/VERITAS NetBackup 6.0 07-60 (Windows) Hitachi JP1/VERITAS NetBackup 5.1 07-15 (Windows) Hitachi JP1/VERITAS NetBackup 5.1 07-14 (Windows) Hitachi JP1/VERITAS NetBackup 5.1 07-13 (Windows) Hitachi JP1/VERITAS NetBackup 5.1 07-12 (Windows) Hitachi JP1/VERITAS NetBackup 5.1 07-11 (Windows) Hitachi JP1/VERITAS NetBackup 5.1 07-10 (Windows) Hitachi JP1/VERITAS NetBackup 5 07-02 (Windows) Hitachi JP1/VERITAS NetBackup 5 07-01 (Windows) Hitachi JP1/VERITAS NetBackup 5 07-00 (Windows) |
| Not Vulnerable: |
Symantec Veritas NetBackup Server 6.5.2 Symantec Veritas NetBackup Server 6.0 MP7 Symantec Veritas NetBackup Server 5.1 MP7 Symantec Veritas NetBackup Enterprise Server 6.5.2 Symantec Veritas NetBackup Enterprise Server 6.0 MP7 Symantec Veritas NetBackup Enterprise Server 5.1 MP7 |
Discussion
Symantec Veritas NetBackup Java Administration GUI Remote Privilege Escalation Vulnerability
Symantec Veritas NetBackup Server and Symantec Veritas NetBackup Enterprise Server are prone to a remote privilege escalation vulnerability that occurs in the Java administration GUI (jnbSA).
Remote authorized attackers who have access to the GUI can exploit this issue to execute arbitrary commands with elevated privileges. Successfully exploiting this issue may compromise the affected computer.
Symantec Veritas NetBackup Server and Symantec Veritas NetBackup Enterprise Server are prone to a remote privilege escalation vulnerability that occurs in the Java administration GUI (jnbSA).
Remote authorized attackers who have access to the GUI can exploit this issue to execute arbitrary commands with elevated privileges. Successfully exploiting this issue may compromise the affected computer.
Exploit / POC
Symantec Veritas NetBackup Java Administration GUI Remote Privilege Escalation Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Symantec Veritas NetBackup Java Administration GUI Remote Privilege Escalation Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
Symantec Veritas NetBackup Java Administration GUI Remote Privilege Escalation Vulnerability
References:
References:
- Veritas NetBackup Homepage (Symantec)
- Vulnerability in Elevating Privileges for the JP1/VERITAS NetBackup - JAVA Admin (Hitachi)
- Sun Security Advisory 239908 (Sun Microsystems)
- Symantec Veritas NetBackup Administration JAVA GUI Elevation of (Symantec)