CVE-2008-4397: Path Traversal
Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to execute arbitrary commands via a .. (dot dot) in an RPC call with opnum 0x10A.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4397?
CVE-2008-4397 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2008-4397?
To mitigate CVE-2008-4397, it is recommended to apply the latest patches provided by CA for the affected versions of ARCserve Backup.
What software is affected by CVE-2008-4397?
CVE-2008-4397 affects CA ARCserve Backup versions r11.1 through r12.0, along with specific editions of the Business Protection Suite.
Can CVE-2008-4397 be exploited remotely?
Yes, CVE-2008-4397 can be exploited remotely by attackers utilizing a malicious RPC call with directory traversal techniques.
What types of attacks can be performed using CVE-2008-4397?
CVE-2008-4397 allows attackers to execute arbitrary commands on the affected systems, leading to potential unauthorized access or data loss.