CVE-2005-2715Disclosure(symantec_veritas / netbackup_data_and_business_center)

LOWCVSS 10.0 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, and NetBackup Enterprise/Server/Client 5.0, 5.1, and 6.0, allows remote attackers to execute arbitrary code via the COMMAND_LOGON_TO_MSERVER command.

1.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netbackup_data_and_business_center
  • netbackup_enterprise_server_client

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
netbackup_data_and_business_centernetbackup_enterprise_server_client

5 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-23: 1PoC Mentioned / Linked · 2026-02-23: 102-23
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • KF@d0tslash
    Disclosure

    God I'm old... did you know I was literally the first *public* @thezdi Zero Day exploit poster child purchase back in 2005 well before @trendaisecurity bought them? ZDI-CAN-001, ZDI-05-001, CVE-2005-2715 for Veritas Netbackup. https://www.zerodayinitiative.com/advisories/ZDI-05-001/ https://t.co/7PiwzZGU3k

    Post summary

    The tweet highlights the first public Zero Day exploit poster child, referencing CVE-2005-2715 for Veritas Netbackup and linking to the ZDI advisory, indicating a historical disclosure of the vulnerability.

    00050289
    10.6K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appsymantec_veritasnetbackup_data_and_business_center4.5fp--
Appsymantec_veritasnetbackup_data_and_business_center4.5mp--
Appsymantec_veritasnetbackup_enterprise_server_client5.0--
Appsymantec_veritasnetbackup_enterprise_server_client5.1--
Appsymantec_veritasnetbackup_enterprise_server_client6.0--

Explore more