CVE ID: CVE-2024-38475
Severity: Critical
CVSS v3.1 Base Score 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
CWE-116: Improper Encoding or Escaping of Output
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.
CVE ID: CVE-2025-24813
Severity: Critical
CVSS v3.1 Base Score 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CWE-44: Path Equivalence: 'file.name' (Internal Dot)
CWE-502: Deserialization of Untrusted Data
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and other impacts have been found in Apache Tomcat 10.1.34 and earlier. The attack requires write enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) and other knowledge.
Backup Exec Desktop Laptop Option versions: 9.7, 9.8, 9.8.1, 9.8.2, 9.8.3 and 9.9. Earlier unsupported versions may be affected as well.
Customers under a current maintenance contract should select the “Run Veritas Update” option in the Tools menu of the DLO Administration Console to update both Apache HTTP Server and Apache Tomcat. For further information see:
Following this guidance will update Apache HTTP Server and Tomcat to the latest available versions.
For questions or problems regarding these vulnerabilities please contact Backup Exec Technical Support (https://supportbackupexec.cloud.com/support-home/home)
The information on this page is being provided to you on an "AS IS" and "AS-AVAILABLE" basis. The issues described on this page may or may not impact your system(s). Cloud Software Group, Inc. and its subsidiaries (collectively, "Cloud SG") make no representations, warranties, or guarantees as to the information contained herein. ANY AND ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING, WITHOUT LIMITATION, INCLUDING, BUT NOT LIMITED TO, IMPLIED WARRANTIES OF MERCHANTABILITY, NON-INFRINGEMENT AND FITNESS FOR A PARTICULAR PURPOSE ARE HEREBY DISCLAIMED. BY ACCESSING THIS PAGE, YOU ACKNOWLEDGE THAT CLOUD SG SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE OUT OF YOUR USE OR FAILURE TO USE THE INFORMATION CONTAINED HEREIN. Cloud SG reserves the right to change or update the information on this page at any time. We accordingly recommend that you always view the latest version of this page. The information contained herein is being provided to you under the terms of your applicable customer agreement with Cloud SG, and may be used only for the purposes contemplated by such agreement. If you do not have such an agreement with Cloud SG, this information is provided under the cloud.com Terms of Use, and may be used only for the purposes contemplated by such Terms of Use.
Vulnerabilities were discovered in Backup Exec Desktop Laptop Option (DLO) version 9.9 and prior due to the inclusion of versions of Apache HTTP Server and Apache Tomcat which have been found to have vulnerabilities. These vulnerabilities have been recently added to the CISA published Known Exploitable Vulnerability (KEV) catalog, and customers should upgrade these components using the Remediation guidance below as soon as possible.
| Issue | Description | Severity | CVE ID |
|---|---|---|---|
|
1. Apache HTTP Server |
Improper Escaping of Output Vulnerability |
Critical |
|
|
2. Apache Tomcat |
PUT Vulnerability |
Critical |