First published: Thu Feb 07 2008(Updated: )
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Backup Exec System Recovery | =7.0 | |
Symantec Backup Exec System Recovery | =7.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0457 has a critical severity due to the potential for remote code execution through arbitrary file uploads.
To fix CVE-2008-0457, it is recommended to update to the latest version of Symantec Backup Exec System Recovery that addresses this vulnerability.
CVE-2008-0457 affects users of Symantec Backup Exec System Recovery versions 7.0 and 7.0.1.
The potential impacts of CVE-2008-0457 include unauthorized remote access and execution of malicious code on the server.
Yes, implementing strict file upload validations and using firewalls to restrict access to vulnerable services can mitigate the risks associated with CVE-2008-0457.