CVE-2008-4339
Status: ModifiedMedium (6.5)—
Unspecified vulnerability in the Java Administration GUI (jnbSA) in Symantec Veritas NetBackup Server and NetBackup Enterprise Server 5.1 before MP7, 6.0 before MP7, and 6.5 before 6.5.2 allows remote authenticated users to gain privileges via unknown attack vectors related to "bpjava* binaries."
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P
- Base score: 6.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 2.05%
- Percentile among all scored CVEs: 81
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- CWE-264
References
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-239908-1
- http://www.securityfocus.com/bid/31221
- http://www.securitytracker.com/id?1020928
- http://www.symantec.com/avcenter/security/Content/2008.09.24a.html
- http://www.vupen.com/english/advisories/2008/2672
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45386
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-239908-1
- http://www.securityfocus.com/bid/31221
- http://www.securitytracker.com/id?1020928
- http://www.symantec.com/avcenter/security/Content/2008.09.24a.html
- http://www.vupen.com/english/advisories/2008/2672
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45386
Raw JSON (NVD)
Show
{
"id": "CVE-2008-4339",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-09-30T17:22:09.443",
"references": [
{
"url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-239908-1",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/31221",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1020928",
"source": "cve@mitre.org"
},
{
"url": "http://www.symantec.com/avcenter/security/Content/2008.09.24a.html",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2672",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45386",
"source": "cve@mitre.org"
},
{
"url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-239908-1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/31221",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1020928",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.symantec.com/avcenter/security/Content/2008.09.24a.html",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2672",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45386",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Unspecified vulnerability in the Java Administration GUI (jnbSA) in Symantec Veritas NetBackup Server and NetBackup Enterprise Server 5.1 before MP7, 6.0 before MP7, and 6.5 before 6.5.2 allows remote authenticated users to gain privileges via unknown attack vectors related to \"bpjava* binaries.\""
},
{
"lang": "es",
"value": "Vulnerabilidad no especificada en Java Administration GUI (jnbSA) de Symantec Veritas NetBackup Server y NetBackup Enterprise Server v5.1 antes de MP7, v6.0 antes de MP7, y v6.5 antes de v6.5.2 permite a usuarios autenticados obtener privilegios a través de vectores de ataque desconocidos relacionados a \"binarios bpjava*\""
}
],
"lastModified": "2026-06-16T22:57:37.950",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:symantec:netbackup_enterprise_server:5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "41EACE89-5A6D-44C6-8E58-F3773FA24F5C"
},
{
"criteria": "cpe:2.3:a:symantec:netbackup_enterprise_server:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "557DE286-5961-46B0-AB74-1FAB81214200"
},
{
"criteria": "cpe:2.3:a:symantec:netbackup_enterprise_server:6.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16280E59-273D-4A09-A7A0-24C102746715"
},
{
"criteria": "cpe:2.3:a:symantec:netbackup_server:5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C6C3B5DE-1376-4079-B16D-2DF63BB1B7D5"
},
{
"criteria": "cpe:2.3:a:symantec:netbackup_server:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "691FB20C-C2F7-4E04-9296-CDB3289FEA7B"
},
{
"criteria": "cpe:2.3:a:symantec:netbackup_server:6.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0A3134C1-5569-4161-8251-4B6055858977"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}