PT-2008-2089 · Symantec+1 · Symantec Backup Exec System Recovery Manager+1
Titon
·
Published
2008-02-07
·
Updated
2018-10-15
·
CVE-2008-0457
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Symantec Backup Exec System Recovery Manager versions 7.0 through 7.0.1
Description
The issue is related to an unrestricted file upload vulnerability in the FileUpload class of the Symantec LiveState Apache Tomcat server. This vulnerability allows remote attackers to upload and execute arbitrary JSP files.
Recommendations
For Symantec Backup Exec System Recovery Manager versions 7.0 through 7.0.1, consider restricting access to the FileUpload class as a temporary workaround until a patch is available.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Tomcat
Symantec Backup Exec System Recovery Manager