Arbitrary RPC call Vulnerability (CVE-2015-6552)
Arbitrary RPC call Vulnerability (CVE-2015-6552)
Release date:
Updated on:
Affected Systems:
Veritas Backup Exec 7.x - 7.5.0.7
Veritas Backup Exec 7.7.x < 7.7.2
Veritas Backup Exec 7.6.1.x - 7.6.1.2
Veritas Backup Exec 7.6.0.x - 7.6.0.4
Veritas NetBackup Appliance <= 2.5.4
Veritas NetBackup Appliance 2.7.x < 2.7.2
Veritas NetBackup Appliance 2.6.1.x <= 2.6.1.2
Veritas NetBackup Appliance 2.6.0.x <= 2.6.0.4
Description:
CVE (CAN) ID: CVE-2015-6552
Veritas Backup Exec is a data protection and system recovery solution.
Veritas maid, 7.7.6.0.4, 7.6.1.x-7.6.1.2, 7.7.x <7.7.2, NetBackup Appliance <= 2.5.4, 2.6.0.x <= 2.6.0.4, 2.6.1.x <= 2.6.1.2, 2.7.x <2.7.2, management service protocols have security vulnerabilities. Remote attackers can call RPC as needed.
<* Source: Emilien Girault
*>
Suggestion:
Vendor patch:
Veritas
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.veritas.com/content/support/en_US/security/VTS16-001.html
This article permanently updates the link address: