CVE Vulnerabilities

CVE-2009-3107

Improper Authentication

Published: Sep 08, 2009 | Modified: Feb 13, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.8 MEDIUM
AV:A/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 does not properly restrict access to the listening port for the DBManager service, which allows remote attackers to bypass authentication and modify tasks or the Altiris Database via a connection to this service.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Altiris_deployment_solution Symantec 6.9 (including) 6.9 (including)
Altiris_deployment_solution Symantec 6.9-sp1 (including) 6.9-sp1 (including)
Altiris_deployment_solution Symantec 6.9-sp2 (including) 6.9-sp2 (including)

Potential Mitigations

References