ID |
CVE-2013-4677
|
Sažetak |
Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 uses weak permissions (Everyone: Read and Everyone: Change) for backup data files, which allows local users to obtain sensitive information or modify the outcome of a restore via direct access to these files. |
Reference |
|
CVSS |
Base: | 4.3 |
Impact: | 6.4 |
Exploitability: | 3.1 |
|
Pristup |
Vektor | Složenost | Autentikacija |
LOCAL |
LOW |
SINGLE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
PARTIAL |
PARTIAL |
PARTIAL |
|
CVSS vektor |
AV:L/AC:L/Au:S/C:P/I:P/A:P |
Zadnje važnije ažuriranje |
22-08-2013 - 06:54 |
Objavljeno |
05-08-2013 - 13:22 |