Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 does not properly restrict access to the listening port for the DBManager service, which allows remote attackers to bypass authentication and modify tasks or the Altiris Database via a connection to this service.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-09-08 16:30
Updated : 2013-02-06 20:21
NVD link : CVE-2009-3107
Mitre link : CVE-2009-3107
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
symantec
- altiris_deployment_solution