CVE-2014-5160: Path Traversal
DISPUTED Multiple directory traversal vulnerabilities in crs.exe in the Cell Request Service in HP Data Protector allow remote attackers to create arbitrary files via an opcode-1091 request, or create or delete arbitrary files via an opcode-305 request. NOTE: the vendor reportedly asserts that this behavior is "by design."
Affected Software
Event History
Frequently Asked Questions
What are the security implications of CVE-2014-5160?
CVE-2014-5160 allows remote attackers to create, delete, or manipulate arbitrary files on affected HP Data Protector installations.
Which versions of HP Data Protector are affected by CVE-2014-5160?
CVE-2014-5160 affects HP Data Protector versions 6.10 and 6.11.
How can I mitigate the risks associated with CVE-2014-5160?
To mitigate CVE-2014-5160, apply the latest patches provided by HP for the affected Data Protector versions.
Is there a way to detect exploitation of CVE-2014-5160 in systems?
Monitoring logs for unusual file creation or deletion requests can help detect potential exploitation of CVE-2014-5160.
What authentication measures are recommended to protect against CVE-2014-5160?
Implementing strong authentication mechanisms and limiting access to the Cell Request Service can help protect against CVE-2014-5160.