Short Name |
APP:HPOV:HP-DPBC-DIR-TRAV |
|---|---|
Severity |
High |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
APP |
Keywords |
Data Protector Backup Client Service |
Release Date |
2011/06/20 |
Update Number |
1942 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+ |
A directory traversal vulnerability exists in HP Data Protector Backup Client Service. The vulnerability is due to insufficient sanitization in the processing of the GET_FILE messages. Remote unauthenticated attackers could exploit this vulnerability by sending a crafted request message to the target service. Successful exploitation would allow attackers to download and view arbitrary files from the target server.
HP OpenView Storage Data Protector is prone to multiple buffer-overflow vulnerabilities and an information-disclosure vulnerability. An attacker can exploit these issues to execute arbitrary code with SYSTEM-level privileges and obtain potentially sensitive information. Successful exploits will completely compromise an affected computer.