{
    "id": "CVE-2004-1389",
    "published": "2004-12-31 05:00:00",
    "last_modified": "2026-06-16 22:07:36",
    "cvss_score": "6.0",
    "cvss_severity": "MEDIUM",
    "cvss_version": "2.0",
    "cvss_vector": "AV:L/AC:H/Au:S/C:C/I:C/A:C",
    "cwe": null,
    "description": "Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server 5.1, and NetBackup Server 5.0 and 5.1, allows attackers to execute arbitrary commands via the bpjava-susvc process, possibly related to the call-back feature.",
    "epss_score": "0.09863",
    "epss_percentile": "0.95412",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-27 18:17:04",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "veritas",
            "product": "netbackup"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "9941",
            "title": "Veritas NetBackup - Remote Command Execution (Metasploit)",
            "date": "2004-10-21",
            "url": "https://www.exploit-db.com/exploits/9941"
        }
    ],
    "refs_list": [
        "http://secunia.com/advisories/12901/",
        "http://seer.support.veritas.com/docs/271727.htm",
        "http://www.ciac.org/ciac/bulletins/p-020.shtml",
        "http://www.kb.cert.org/vuls/id/685456",
        "http://www.securityfocus.com/bid/11494",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/17811",
        "http://secunia.com/advisories/12901/",
        "http://seer.support.veritas.com/docs/271727.htm",
        "http://www.ciac.org/ciac/bulletins/p-020.shtml",
        "http://www.kb.cert.org/vuls/id/685456",
        "http://www.securityfocus.com/bid/11494",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/17811"
    ]
}