Risk: High
A high-risk vulnerability has been discovered in the VERITAS Software Backup Exec Web Administration Console (BEWAC) which can allow for remote code execution.
Affected Products include:
- Backup Exec 10.0 for Windows Servers rev. 5484
- Backup Exec 9.1 for Windows Servers rev. 4691
- Backup Exec 9.0 for Windows Servers rev. 4454
- Backup Exec 9.0 for Windows Servers rev. 4367
NGSSoftware are going to withhold details of this flaw for three months. Full details will be published on the 23rd September 2005. This three month window will allow users of Veritas Backup Exec Server the time needed to apply the patch before the details are released to the general public.