CVE-2008-4339
Unspecified vulnerability in the Java Administration GUI (jnbSA) in Symantec Veritas NetBackup Server and NetBackup Enterprise Server 5.1 before MP7, 6.0 before MP7, and 6.5 before 6.5.2 allows remote authenticated users to gain privileges via unknown…
Does this matter?
Lower severity and a low EPSS score (2.05%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the Java Administration GUI (jnbSA) in Symantec Veritas NetBackup Server and NetBackup Enterprise Server 5.1 before MP7, 6.0 before MP7, and 6.5 before 6.5.2 allows remote authenticated users to gain privileges via unknown attack vectors related to "bpjava* binaries."
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 2.05% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- symantec/netbackup enterprise server · symantec/netbackup server
- Source
- cve@mitre.org
References
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-239908-1
- http://www.securityfocus.com/bid/31221
- http://www.securitytracker.com/id?1020928
- http://www.symantec.com/avcenter/security/Content/2008.09.24a.htmlPatch
- http://www.vupen.com/english/advisories/2008/2672
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45386
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-239908-1
- http://www.securityfocus.com/bid/31221
- http://www.securitytracker.com/id?1020928
- http://www.symantec.com/avcenter/security/Content/2008.09.24a.htmlPatch
- http://www.vupen.com/english/advisories/2008/2672
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45386
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.