peter bassill · operator
$ cve CVE-2008-0457 JSON

CVE-2008-0457 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 11.9% (pctl 96)

Patch early

A public exploit exists.

Description

Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS11.86% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2008-02-07
Last modified2026-06-16

Affected (1)

VendorProduct
symantecbackupexec system recovery

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD