CVE-2002-1117: Medium severity Symantec Veritas Backup Exec vulnerability
Published Oct 4, 2002
·Updated
Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.
Affected Software
1 affected component
Symantec Veritas Backup Exec<=8.5
Event History
Oct 4, 2002
CVE Published
04:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1117?
The severity of CVE-2002-1117 is considered high due to its potential to expose sensitive information.
2
How do I fix CVE-2002-1117?
To fix CVE-2002-1117, change the 'RestrictAnonymous' registry key for Microsoft Exchange 2000 to 1.
3
Which versions of Veritas Backup Exec are affected by CVE-2002-1117?
CVE-2002-1117 affects all versions of Veritas Backup Exec up to and including 8.5.
4
What risks are associated with CVE-2002-1117?
The risks associated with CVE-2002-1117 include unauthorized access to the SAM database and shared resources.
5
Is there a patch available for CVE-2002-1117?
There is no specific patch for CVE-2002-1117, but configuration changes can mitigate the vulnerability.