vendor:
NetBackup
by:
patrick
7.5
CVSS
HIGH
Remote Command Execution
CWE
Product Name: NetBackup
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2004-1389
CPE:
Platforms Tested: unix, win, linux
2004
VERITAS NetBackup Remote Command Execution
This module allows arbitrary command execution on an ephemeral port opened by Veritas NetBackup, whilst an administrator is authenticated. The port is opened and allows direct console access as root or SYSTEM from any source address.
Mitigation:
Apply the patch provided by the vendor.