← Vulnerability feed

Vulnerability record · CVE-2008-0457 · published 7 February 2008

CVE-2008-0457: Symantec backupexec system recovery improper input validation vulnerability

Symantec · Backupexec System Recovery

Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.

10.0 CVSS 2.0 High EPSS 12% · top 4.0% CWE-20 · Improper input validation
10.0CVSS 2.0 base score
12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-0457 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2007-4347Symantec backupexec system recovery vulnerabilityMultiple integer overflows in the Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.…EPSS 2.9%7.2CVE-2007-2359Symantec backupexec system recovery vulnerabilityBuffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recover…EPSS 0.41%6.8CVE-2007-2360Symantec backupexec system recovery vulnerabilitySymantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore poi…EPSS 0.34%5.0CVE-2008-2512Symantec backupexec system recovery path traversal vulnerabilityDirectory traversal vulnerability in Symantec Backup Exec System Recovery Manager 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to re…EPSS 2.8%5.0CVE-2007-4346Symantec backupexec system recovery vulnerabilityThe Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allows remote attackers t…EPSS 2.6%4.9CVE-2007-2361Symantec backupexec system recovery vulnerabilitySymantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore poi…EPSS 0.34%4.4CVE-2012-0305Symantec backupexec system recovery vulnerabilityUntrusted search path vulnerability in Symantec System Recovery 2011 before SP2 and Backup Exec System Recovery 2010 before SP5 allows local users to…EPSS 0.43%9.5CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV

Source: NIST National Vulnerability Database (record CVE-2008-0457), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.