Vulnerability record · CVE-2005-2715 · published 12 October 2005
CVE-2005-2715: VERITAS NetBackup bpjava-msvc daemon format string RCE
SSymantec Veritas · Netbackup Data And Business Center
The bpjava-msvc daemon in VERITAS NetBackup Data and Business Center 4.5FP/4.5MP and NetBackup Enterprise/Server/Client 5.0, 5.1 and 6.0 contains a format string vulnerability reachable through the COMMAND_LOGON_TO_MSERVER command. A remote, unauthenticated attacker can supply crafted format specifiers that corrupt memory and execute arbitrary code on the backup server.
Description
Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, and NetBackup Enterprise/Server/Client 5.0, 5.1, and 6.0, allows remote attackers to execute arbitrary code via the COMMAND_LOGON_TO_MSERVER command.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication and full confidentiality, integrity and availability impact, plus public exploit references and very high EPSS.
What it is
The bpjava-msvc daemon in VERITAS NetBackup Data and Business Center 4.5FP/4.5MP and NetBackup Enterprise/Server/Client 5.0, 5.1 and 6.0 contains a format string vulnerability reachable through the COMMAND_LOGON_TO_MSERVER command. A remote, unauthenticated attacker can supply crafted format specifiers that corrupt memory and execute arbitrary code on the backup server.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the bpjava-msvc service, typically root or SYSTEM on the backup host. That host holds backup credentials and data for the whole environment, so compromise can cascade to managed clients.
Attack surface
Reachable over the network via the Java user interface service port; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The attacker only needs to send a crafted COMMAND_LOGON_TO_MSERVER request to the daemon.
Exploitation
Not listed in CISA KEV, but EPSS is 0.60356 (99.1st percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware association is documented.
What to do
- Apply the vendor patches referenced in the Symantec, VERITAS and Sun advisories for the affected NetBackup versions.
- Restrict network access to the bpjava-msvc service port to trusted management hosts using firewall rules or host-based ACLs.
- Disable or stop the bpjava-msvc daemon on hosts that do not require the Java user interface service.
- Segment backup servers from general user and internet-facing networks to limit reachable attack paths.
- Monitor vendor advisories for the affected 4.5/5.x/6.0 branches, which are long past end of support.
Detection
- Inspect bpjava-msvc service logs for malformed or unexpected COMMAND_LOGON_TO_MSERVER requests and format-specifier characters in command arguments.
- Alert on unexpected child processes or shell spawns originating from the bpjava-msvc daemon process.
- Monitor network traffic to the bpjava-msvc port for connections from hosts outside the approved backup management range.
- Baseline and watch for crashes or restarts of the bpjava-msvc service, which can accompany format string exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-2715 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2005-2715), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.