Impact of CVE-2012-2552, CVE-2011-1280, CVE-2015-0204 and CVE-2013-2566 on Backup Exec

book

Article ID: 100015202

calendar_today

Updated On:

Resolution

Impact of “CVE-2012-2552 - Microsoft SQL Server Report Manager Unspecified XSS” on Backup Exec

Backup Exec is not impacted by this vulnerability
Backup Exec redistributes and Installs Microsoft SQL Server 2008 R2 SP2 Express Edition and does not install or use the Reporting Services.  


Impact of “CVE-2011-1280 - Microsoft SQL Server XML External Entities Resolution Vulnerability” on Backup Exec
Backup Exec is not impacted by this vulnerability
Backup Exec redistributes and Installs Microsoft SQL Server 2008 R2 SP2.
The version of Sqlservr.exe is 2009.100.4000.0 and does not fall in the version range specified for the vulnerability.


Impact of “CVE-2015-0204 - FREAK Vulnerability - Another SSL/TLS issue” on Backup Exec
Backup Exec is not impacted by this vulnerability
Backup Exec generates a minimum of 1024-bit RSA Key size so there is no chance of an attack requesting to downgrade to a weaker key. 


Impact of “CVE-2013-2566 - SSL: RC4 Algorithm Pseudo-random Character Generation Weakness Plaintext Content” on Backup Exec
Backup Exec is impacted by this vulnerability.
The vulnerability has a low CVSS score with high Access Complexity, the severity may be on the lower side.

Veritas Corporation has acknowledged that the above-mentioned issue is present in the current version(s) of the product(s) mentioned at the end of this article. Veritas Corporation is committed to product quality and satisfied customers.

There are currently no plans to address this issue by way of a patch or hotfix in the current or previous versions of the software at the present time. This issue may be resolved in a future major revision of the software at a later time. However, this particular issue is not currently scheduled for any release.  If you feel this issue has a direct business impact for you and your continued use of the product, please contact your Veritas Sales representative or the Veritas Sales group to discuss these concerns.  For information on how to contact Veritas Sales, please see https://www.veritas.com 

Please be sure to refer back to this document periodically as any changes to the status of the issue will be reflected here.

 


Issue/Introduction

  • Impact of “CVE-2012-2552 - Microsoft SQL Server Report Manager Unspecified XSS” on Backup Exec
  • Impact of “CVE-2011-1280 - Microsoft SQL Server XML External Entities Resolution Vulnerability” on Backup Exec
  • Impact of “CVE-2015-0204 - FREAK Vulnerability - Another SSL/TLS issue” on Backup Exec
  • Impact of “CVE-2013-2566 - SSL: RC4 Algorithm Pseudo-random Character Generation Weakness Plaintext Content” on Backup Exec

Additional Information

ETrack: 3743606