First published: Fri Oct 04 2002(Updated: )
Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Veritas Backup Exec | <=8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2002-1117 is considered high due to its potential to expose sensitive information.
To fix CVE-2002-1117, change the 'RestrictAnonymous' registry key for Microsoft Exchange 2000 to 1.
CVE-2002-1117 affects all versions of Veritas Backup Exec up to and including 8.5.
The risks associated with CVE-2002-1117 include unauthorized access to the SAM database and shared resources.
There is no specific patch for CVE-2002-1117, but configuration changes can mitigate the vulnerability.