CVE-2009-3107

Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 does not properly restrict access to the listening port for the DBManager service, which allows remote attackers to bypass authentication and modify tasks or the Altiris Database via a connection to this service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:symantec:altiris_deployment_solution:6.9:*:*:*:*:*:*:*
cpe:2.3:a:symantec:altiris_deployment_solution:6.9:sp1:*:*:*:*:*:*
cpe:2.3:a:symantec:altiris_deployment_solution:6.9:sp2:*:*:*:*:*:*

History

13 Feb 2024, 17:38

Type Values Removed Values Added
References () http://secunia.com/advisories/36502 - Vendor Advisory () http://secunia.com/advisories/36502 - Broken Link, Vendor Advisory
References () http://www.securityfocus.com/bid/36110 - () http://www.securityfocus.com/bid/36110 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id?1022779 - () http://www.securitytracker.com/id?1022779 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090826_00 - () http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090826_00 - Broken Link
CWE CWE-264 CWE-287

Information

Published : 2009-09-08 23:30

Updated : 2024-02-13 17:38


NVD link : CVE-2009-3107

Mitre link : CVE-2009-3107

CVE.ORG link : CVE-2009-3107


JSON object : View

Products Affected

symantec

  • altiris_deployment_solution
CWE
CWE-287

Improper Authentication