PT-2007-1653 · Computer Associates · Ca Brightstor Arcserve Backup+2

Published

2007-01-11

·

Updated

2021-04-07

·

CVE-2007-0169

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Computer Associates (CA) BrightStor ARCserve Backup versions 9.01 through 11.5 Computer Associates (CA) Enterprise Backup version 10.5 Computer Associates (CA) Server/Business Protection Suite version r2
Description The issue allows remote attackers to execute arbitrary code via RPC requests with crafted data for specific opnums in the Message Engine RPC service or the Tape Engine service. Specifically, the opnums affected are 0x2F, 0x75 in the Message Engine RPC service, and 0xCF in the Tape Engine service.
Recommendations For Computer Associates (CA) BrightStor ARCserve Backup versions 9.01 through 11.5, update to a version outside of this range to mitigate the risk. For Computer Associates (CA) Enterprise Backup version 10.5, update to a version outside of this range to mitigate the risk. For Computer Associates (CA) Server/Business Protection Suite version r2, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the Message Engine RPC service and the Tape Engine service to minimize the risk of exploitation.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-0169

Affected Products

Ca Brightstor Arcserve Backup
Ca Enterprise Backup
Ca Server/Business Protection Suite