CVE-2011-0921
N/A
N/A
Summary
crs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, and username, which allows remote attackers to execute arbitrary code by sending unspecified data over TCP, related to the webreporting client, the applet domain, and the java username.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-hp
- http://marc.info/?l=bugtraq&m=130391284726795&w=2
- http://www.vupen.com/english/advisories/2011/0308
- http://marc.info/?l=bugtraq&m=130391284726795&w=2
- http://zerodayinitiative.com/advisories/ZDI-11-057/
- http://www.securityfocus.com/bid/46234
References
- http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-hp
- http://marc.info/?l=bugtraq&m=130391284726795&w=2
- http://www.vupen.com/english/advisories/2011/0308
- http://marc.info/?l=bugtraq&m=130391284726795&w=2
- http://zerodayinitiative.com/advisories/ZDI-11-057/
- http://www.securityfocus.com/bid/46234
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.