Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 uses weak permissions (Everyone: Read and Everyone: Change) for backup data files, which allows local users to obtain sensitive information or modify the outcome of a restore via direct access to these files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Backup_exec | Symantec | 2010 (including) | 2010 (including) |
Backup_exec | Symantec | 2010_r3-sp1 (including) | 2010_r3-sp1 (including) |
Backup_exec | Symantec | 2010_r3-sp2 (including) | 2010_r3-sp2 (including) |
Backup_exec | Symantec | 2012 (including) | 2012 (including) |
Backup_exec | Symantec | 2012-sp1 (including) | 2012-sp1 (including) |