First published: Wed Feb 09 2011(Updated: )
crs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, and username, which allows remote attackers to execute arbitrary code by sending unspecified data over TCP, related to the webreporting client, the applet domain, and the java username.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Data Protector |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0921 is considered a high severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2011-0921, ensure that you have applied the latest patches released by HP for Data Protector.
CVE-2011-0921 affects HP Data Protector, particularly the crs.exe component within the Cell Manager Service.
Yes, CVE-2011-0921 can be exploited remotely by attackers sending malicious data over TCP.
CVE-2011-0921 can lead to arbitrary code execution, which may compromise the affected system.