First published: Wed Feb 09 2011(Updated: )
The client in HP Data Protector does not verify the contents of files associated with the EXEC_CMD command, which allows remote attackers to execute arbitrary script code by providing this code with a trusted filename, as demonstrated by omni_chk_ds.sh.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Storage Data Protector |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0924 has a medium severity rating due to the potential for arbitrary code execution by remote attackers.
To fix CVE-2011-0924, ensure you are using an updated version of HP Data Protector that addresses this vulnerability.
The potential impacts of CVE-2011-0924 include unauthorized remote code execution, which can lead to data breaches and system compromise.
Users of HP Data Protector are affected by CVE-2011-0924 if they have not implemented the necessary security updates.
CVE-2011-0924 can be exploited by providing arbitrary script code with a trusted filename related to the EXEC_CMD command.