CVE-2011-0922: Input Validation
Published Feb 9, 2011
·Updated
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXECSETUP command that references a UNC share pathname.
Affected Software
1 affected component
HP Data Protector
Event History
Feb 9, 2011
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0922?
CVE-2011-0922 is considered to have a high severity due to the potential for remote code execution.
2
How do I fix CVE-2011-0922?
To fix CVE-2011-0922, ensure that you apply the latest security patches released by HP for Data Protector.
3
What vulnerabilities does CVE-2011-0922 introduce?
CVE-2011-0922 introduces a vulnerability that allows attackers to execute arbitrary programs on affected systems.
4
Which versions of HP Data Protector are affected by CVE-2011-0922?
CVE-2011-0922 affects all versions of HP Data Protector prior to the security updates provided by HP.
5
What is the attack vector for CVE-2011-0922?
The attack vector for CVE-2011-0922 involves using a crafted EXEC_SETUP command that references a malicious UNC share pathname.