PT-2011-4280 · Hewlett Packard · Hp Data Protector Notebook Extension+1
Publicado
2011-10-19
·
Atualizado
2016-11-22
·
CVE-2011-3160
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
HP Data Protector Notebook Extension version 6.20
HP Data Protector for Personal Computers version 7.0
Description
The issue allows remote attackers to execute arbitrary code. It is also described as a remote SQL injection vulnerability in the Policy Server LogCopyOperation.
Recommendations
For HP Data Protector Notebook Extension version 6.20, update to a version that fixes the remote code execution issue.
For HP Data Protector for Personal Computers version 7.0, update to a version that fixes the remote code execution issue.
As a temporary workaround, consider restricting access to the Policy Server LogCopyOperation to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Hp Data Protector Notebook Extension
Hp Data Protector For Personal Computers