Backup Exec Desktop Laptop Option (DLO) Apache HTTP Server and Tomcat Vulnerabilities

book

Article ID: 100076801

calendar_today

Updated On:

Description

Issue 1: Apache HTTP Server

CVE ID: CVE-2024-38475

Severity: Critical

CVSS v3.1 Base Score 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

CWE-116: Improper Encoding or Escaping of Output

Description

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.

Issue 2: Apache Tomcat

CVE ID: CVE-2025-24813

Severity: Critical

CVSS v3.1 Base Score 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CWE-44: Path Equivalence: 'file.name' (Internal Dot)

CWE-502: Deserialization of Untrusted Data

Description

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and other impacts have been found in Apache Tomcat 10.1.34 and earlier.  The attack requires write enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) and other knowledge.

Affected Versions

Backup Exec Desktop Laptop Option versions: 9.7, 9.8, 9.8.1, 9.8.2, 9.8.3 and 9.9. Earlier unsupported versions may be affected as well.

Remediation

Customers under a current maintenance contract should select the “Run Veritas Update” option in the Tools menu of the DLO Administration Console to update both Apache HTTP Server and Apache Tomcat.  For further information see:

https://docs.backupexec.com/content/dam/backupexec/us/en/dlo-userdocs/downloads/pdf/DLO_97_VxUpdate.pdf  

Following this guidance will update Apache HTTP Server and Tomcat to the latest available versions.

Questions

For questions or problems regarding these vulnerabilities please contact Backup Exec Technical Support (https://supportbackupexec.cloud.com/support-home/home)

Environment

The information on this page is being provided to you on an "AS IS" and "AS-AVAILABLE" basis. The issues described on this page may or may not impact your system(s). Cloud Software Group, Inc. and its subsidiaries (collectively, "Cloud SG") make no representations, warranties, or guarantees as to the information contained herein. ANY AND ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING, WITHOUT LIMITATION, INCLUDING, BUT NOT LIMITED TO, IMPLIED WARRANTIES OF MERCHANTABILITY, NON-INFRINGEMENT AND FITNESS FOR A PARTICULAR PURPOSE ARE HEREBY DISCLAIMED. BY ACCESSING THIS PAGE, YOU ACKNOWLEDGE THAT CLOUD SG SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE OUT OF YOUR USE OR FAILURE TO USE THE INFORMATION CONTAINED HEREIN. Cloud SG reserves the right to change or update the information on this page at any time. We accordingly recommend that you always view the latest version of this page. The information contained herein is being provided to you under the terms of your applicable customer agreement with Cloud SG, and may be used only for the purposes contemplated by such agreement. If you do not have such an agreement with Cloud SG, this information is provided under the cloud.com Terms of Use, and may be used only for the purposes contemplated by such Terms of Use.

Issue/Introduction

Description

Vulnerabilities were discovered in Backup Exec Desktop Laptop Option (DLO) version 9.9 and prior due to the inclusion of versions of Apache HTTP Server and Apache Tomcat which have been found to have vulnerabilities. These vulnerabilities have been recently added to the CISA published Known Exploitable Vulnerability (KEV) catalog, and customers should upgrade these components using the Remediation guidance below as soon as possible.

Issue Description Severity CVE ID

1. Apache HTTP Server

Improper Escaping of Output Vulnerability

Critical

CVE-2024-38475

2. Apache Tomcat

PUT Vulnerability

Critical

CVE-2025-24813

Additional Information

Revision History

  • 1.0: May 28, 2025: Initial version