CVE-2002-1117
⚪ Do wiadomości
Błąd w Veritas Backup Exec umożliwia anonimowy dostęp do bazy SAM w Microsoft Exchange.
CVSS
5.0
EPSS
1.8%
Exploit
none
Vendor
symantec_veritas
Opis źródłowy (NVD)
Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 1.8% |
| Opublikowano (NVD) | 2002-10-04 04:00:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-09 19:16:40 UTC |
Referencje
- http://marc.info/?l=bugtraq&m=103134395124579&w=2 ([email protected])
- http://marc.info/?l=bugtraq&m=103134930629683&w=2 ([email protected])
- http://seer.support.veritas.com/docs/238618.htm ([email protected])
- http://www.osvdb.org/8230 ([email protected])
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10093 ([email protected])
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1036 ([email protected])