Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-3035

EPSS 0.09% · P26
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-3035

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt SQL Server credentials and certain discovery credentials, and stores this key on the Notification Server machine, which allows local users to obtain sensitive information and possibly execute arbitrary code by decrypting and using these credentials.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Symantec Altiris Notification Server静态加密密钥非授权访问漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Symantec Altiris产品为Symantec所提供的IT生命周期管理解决方案。 Altiris产品所使用的Notification Server的Web控制台存储了管理员所输入凭据的静态加密密钥,本地用户可以读取这个凭据用户非授权访问发现信息,或在服务器上获得权限提升;此外如果系统配置为使用SQL服务器凭据进行数据库访问,这还可能导致非授权访问Notification Server数据库上的信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-3035

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-3035

登录查看更多情报信息。

Same Patch Batch · n/a · 2010-02-02 · 12 CVEs total

CVE-2010-0442PostgreSQL bitsubstr函数远程溢出漏洞
CVE-2010-0472IBM DB2 kuddb2服务远程拒绝服务漏洞
CVE-2010-0467Joomla!路径遍历漏洞
CVE-2010-0468PaperThin CommonSpot Content Server "utilities/longproc.cfm"跨站脚本攻击漏洞
CVE-2010-0469Files2Links F2L 3000 SQL注入漏洞
CVE-2010-0470康全电讯CT-5071T ADSL路由器srvName参数跨站脚本漏洞
CVE-2010-0471Enano CMS 评论提交页面SQL注入漏洞
CVE-2009-4013Debian Lintian多个目录遍历漏洞
CVE-2009-4014Debian Lintian 多个格式化字符串漏洞
CVE-2009-4015Debian Lintian 多个代码注入漏洞
CVE-2010-0010Apache mod_proxy模块HTTP分块编码整数溢出漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-3035

No comments yet


Leave a comment