PT-2008-2089 · Symantec+1 · Symantec Backup Exec System Recovery Manager+1

Titon

·

Published

2008-02-07

·

Updated

2018-10-15

·

CVE-2008-0457

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symantec Backup Exec System Recovery Manager versions 7.0 through 7.0.1
Description The issue is related to an unrestricted file upload vulnerability in the FileUpload class of the Symantec LiveState Apache Tomcat server. This vulnerability allows remote attackers to upload and execute arbitrary JSP files.
Recommendations For Symantec Backup Exec System Recovery Manager versions 7.0 through 7.0.1, consider restricting access to the FileUpload class as a temporary workaround until a patch is available.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0457

Affected Products

Apache Tomcat
Symantec Backup Exec System Recovery Manager