First published: Wed Feb 09 2011(Updated: )
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that references a UNC share pathname.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Data Protector |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0922 is considered to have a high severity due to the potential for remote code execution.
To fix CVE-2011-0922, ensure that you apply the latest security patches released by HP for Data Protector.
CVE-2011-0922 introduces a vulnerability that allows attackers to execute arbitrary programs on affected systems.
CVE-2011-0922 affects all versions of HP Data Protector prior to the security updates provided by HP.
The attack vector for CVE-2011-0922 involves using a crafted EXEC_SETUP command that references a malicious UNC share pathname.