PT-2009-5434 · Symantec · Symantec Altiris Deployment Solution

CVE-2009-3107

·

Published

2009-09-08

·

Updated

2024-02-13

CVSS v2.0

4.8

Medium

VectorAV:A/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Symantec Altiris Deployment Solution versions 6.9.x before 6.9 SP3 Build 430
Description: The issue is related to improper access restriction to the listening port for the DBManager service. This allows remote attackers to bypass authentication and modify tasks or the Altiris Database via a connection to this service.
Recommendations: For Symantec Altiris Deployment Solution versions 6.9.x before 6.9 SP3 Build 430, update to 6.9 SP3 Build 430 or later to resolve the issue. As a temporary workaround, consider restricting access to the DBManager service to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3107

Affected Products

Symantec Altiris Deployment Solution