Title : Symantec Veritas NetBackup Code Execution Vulnerabilities VUPEN ID : VUPEN/ADV-2008-2672 CVE ID : CVE-2007-6016 - CVE-2007-6017 - CVE-2008-4339 CWE ID : CWE-264
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-09-25
Technical Description
Multiple vulnerabilities have been identified in Symantec Veritas NetBackup, which could be exploited by attackers or malicious users to execute arbitrary code.
The first issue is caused by an error in the Java Administration GUI (jnbSA), which could allow an authenticated but non-privileged user to execute commands which would normally require a higher privilege to execute.