PT-2007-1653 · Computer Associates · Ca Brightstor Arcserve Backup+2
Publicado
2007-01-11
·
Atualizado
2021-04-07
·
CVE-2007-0169
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Computer Associates (CA) BrightStor ARCserve Backup versions 9.01 through 11.5
Computer Associates (CA) Enterprise Backup version 10.5
Computer Associates (CA) Server/Business Protection Suite version r2
Description
The issue allows remote attackers to execute arbitrary code via RPC requests with crafted data for specific opnums in the Message Engine RPC service or the Tape Engine service. Specifically, the opnums affected are 0x2F, 0x75 in the Message Engine RPC service, and 0xCF in the Tape Engine service.
Recommendations
For Computer Associates (CA) BrightStor ARCserve Backup versions 9.01 through 11.5, update to a version outside of this range to mitigate the risk.
For Computer Associates (CA) Enterprise Backup version 10.5, update to a version outside of this range to mitigate the risk.
For Computer Associates (CA) Server/Business Protection Suite version r2, update to a version outside of this range to mitigate the risk.
As a temporary workaround, consider restricting access to the Message Engine RPC service and the Tape Engine service to minimize the risk of exploitation.
Exploit
Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ca Brightstor Arcserve Backup
Ca Enterprise Backup
Ca Server/Business Protection Suite