First published: Mon Oct 01 2007(Updated: )
Multiple SQL injection vulnerabilities in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary SQL commands via CsAgent service commands with opcodes (1) 0x07, (2) 0x08, (3) 0x09, (4) 0x1E, (5) 0x32, (6) 0x36, (7) 0x40, and possibly others.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Brightstor Hierarchical Storage Manager | <=11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5084 has a severity rating that indicates a critical risk due to its SQL injection vulnerabilities.
To mitigate CVE-2007-5084, upgrade to BrightStor Hierarchical Storage Manager version 11.6 or later.
Exploitation of CVE-2007-5084 could allow remote attackers to execute arbitrary SQL commands affecting the integrity and confidentiality of data.
CVE-2007-5084 affects versions of CA BrightStor Hierarchical Storage Manager up to 11.5.
CVE-2007-5084 can be exploited by remote attackers with access to the CsAgent service commands.