Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

APP:HPOV:HP-DPBC-DIR-TRAV

Severity

High

Recommended

Yes

Recommended Action

Drop

Category

APP

Keywords

Data Protector Backup Client Service

Release Date

2011/06/20

Update Number

1942

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+

APP: HP Data Protector Backup Client Service GET_FILE Directory Traversal


A directory traversal vulnerability exists in HP Data Protector Backup Client Service. The vulnerability is due to insufficient sanitization in the processing of the GET_FILE messages. Remote unauthenticated attackers could exploit this vulnerability by sending a crafted request message to the target service. Successful exploitation would allow attackers to download and view arbitrary files from the target server.

Extended Description

HP OpenView Storage Data Protector is prone to multiple buffer-overflow vulnerabilities and an information-disclosure vulnerability. An attacker can exploit these issues to execute arbitrary code with SYSTEM-level privileges and obtain potentially sensitive information. Successful exploits will completely compromise an affected computer.

Affected Products

  • HP OpenView Storage Data Protector 6.0
  • HP OpenView Storage Data Protector 6.1
  • HP OpenView Storage Data Protector 6.10
  • HP OpenView Storage Data Protector 6.11

References

  • BugTraq: 47638
  • CVE: CVE-2011-1736

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy & Policy
Legal Notices
Copyright© 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out