CVE-2011-2397: Input Validation
Published Dec 5, 2011
·Updated
The Agent service in Iron Mountain Connected Backup 8.4 allows remote attackers to execute arbitrary code via a crafted opcode 13 request that triggers use of the LaunchCompoundFileAnalyzer class to send request data to the System.getRunTime.exec method.
Affected Software
1 affected component
Ironmountain Connected Backup=8.4
Event History
Dec 5, 2011
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2397?
CVE-2011-2397 is classified as a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2011-2397?
To fix CVE-2011-2397, update Iron Mountain Connected Backup to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2011-2397?
CVE-2011-2397 affects users of Iron Mountain Connected Backup version 8.4.
4
What kind of attack does CVE-2011-2397 allow?
CVE-2011-2397 allows remote attackers to execute arbitrary code through a crafted opcode 13 request.
5
What component is vulnerable in CVE-2011-2397?
The Agent service is the vulnerable component in CVE-2011-2397 that facilitates the exploitation.