CVE-2004-1389 EXPLOIT
6.0
MEDIUM · CVSS 2.0 · EPSS 9.9% (pctl 95)
Patch early
A public exploit exists.
Description
Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server 5.1, and NetBackup Server 5.0 and 5.1, allows attackers to execute arbitrary commands via the bpjava-susvc process, possibly related to the call-back feature.
Scoring
| CVSS | 6.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
| EPSS | 9.86% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| veritas | netbackup |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Veritas NetBackup - Remote Command Execution (Metasploit) | 2004-10-21 |
References
- http://secunia.com/advisories/12901/
- http://seer.support.veritas.com/docs/271727.htm
- http://www.ciac.org/ciac/bulletins/p-020.shtml
- http://www.kb.cert.org/vuls/id/685456
- http://www.securityfocus.com/bid/11494
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17811
- http://secunia.com/advisories/12901/
- http://seer.support.veritas.com/docs/271727.htm
- http://www.ciac.org/ciac/bulletins/p-020.shtml
- http://www.kb.cert.org/vuls/id/685456
- http://www.securityfocus.com/bid/11494
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17811
→ the Explorer · watch your stack · NVD