CVE-2016-2004: Critical severity hp storage data protector vulnerability
HPE Data Protector before 7.03108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2623.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2004?
CVE-2016-2004 is considered a critical vulnerability that allows remote attackers to execute arbitrary code due to a lack of authentication.
How do I fix CVE-2016-2004?
To fix CVE-2016-2004, upgrade HPE Data Protector to version 7.03_108 or later, 8.15 or later, or 9.06 or later.
What versions of HPE Data Protector are affected by CVE-2016-2004?
HPE Data Protector versions before 7.03_108, 8.x before 8.15, and 9.x before 9.06 are affected by CVE-2016-2004.
Is there a workaround for CVE-2016-2004?
There are no known effective workarounds for CVE-2016-2004 aside from upgrading to a patched version.
What causes CVE-2016-2004?
CVE-2016-2004 exists due to an incomplete fix for a previous vulnerability, CVE-2014-2623, which resulted in insufficient authentication.