PT-2007-6402 · Ca · Ca Brightstor Arcserve Backup+1
Published
2007-10-13
·
Updated
2021-04-09
·
CVE-2007-5331
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
CA BrightStor ARCServe BackUp versions 9.01 through 11.5
CA Enterprise Backup version 10.5
Description:
The issue allows remote attackers to execute arbitrary code via a malformed ONRPC protocol request for operation 0x76, which causes ARCserve Backup to dereference arbitrary pointers.
Recommendations:
For CA BrightStor ARCServe BackUp versions 9.01 through 11.5, update to a version that fixes the issue with the ONRPC protocol request.
For CA Enterprise Backup version 10.5, update to a version that fixes the issue with the ONRPC protocol request.
As a temporary workaround, consider restricting access to the ONRPC protocol to minimize the risk of exploitation.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ca Brightstor Arcserve Backup
Ca Enterprise Backup