CVE Vulnerabilities

CVE-2009-3107

Improper Authentication

Published: Sep 08, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.8 MEDIUM
AV:A/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 does not properly restrict access to the listening port for the DBManager service, which allows remote attackers to bypass authentication and modify tasks or the Altiris Database via a connection to this service.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Altiris_deployment_solutionSymantec6.9 (including)6.9 (including)
Altiris_deployment_solutionSymantec6.9-sp1 (including)6.9-sp1 (including)
Altiris_deployment_solutionSymantec6.9-sp2 (including)6.9-sp2 (including)

Potential Mitigations

References