Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 does not properly restrict access to the listening port for the DBManager service, which allows remote attackers to bypass authentication and modify tasks or the Altiris Database via a connection to this service.
References
Link | Resource |
---|---|
http://secunia.com/advisories/36502 | Broken Link Vendor Advisory |
http://www.securityfocus.com/bid/36110 | Broken Link Third Party Advisory VDB Entry |
http://www.securitytracker.com/id?1022779 | Broken Link Third Party Advisory VDB Entry |
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090826_00 | Broken Link |
http://secunia.com/advisories/36502 | Broken Link Vendor Advisory |
http://www.securityfocus.com/bid/36110 | Broken Link Third Party Advisory VDB Entry |
http://www.securitytracker.com/id?1022779 | Broken Link Third Party Advisory VDB Entry |
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090826_00 | Broken Link |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:06
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/36502 - Broken Link, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/36110 - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id?1022779 - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090826_00 - Broken Link |
13 Feb 2024, 17:38
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-287 | |
References | (BID) http://www.securityfocus.com/bid/36110 - Broken Link, Third Party Advisory, VDB Entry | |
References | (SECTRACK) http://www.securitytracker.com/id?1022779 - Broken Link, Third Party Advisory, VDB Entry | |
References | (CONFIRM) http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090826_00 - Broken Link | |
References | (SECUNIA) http://secunia.com/advisories/36502 - Broken Link, Vendor Advisory |
Information
Published : 2009-09-08 23:30
Updated : 2024-11-21 01:06
NVD link : CVE-2009-3107
Mitre link : CVE-2009-3107
CVE.ORG link : CVE-2009-3107
JSON object : View
Products Affected
symantec
- altiris_deployment_solution
CWE
CWE-287
Improper Authentication