First published: Thu Apr 21 2016(Updated: )
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2623.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Data Protector | >=7.0<7.03_108 | |
HP Data Protector | >=8.0<8.15 | |
HP Data Protector | >=9.0<9.06 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2004 is considered a critical vulnerability that allows remote attackers to execute arbitrary code due to a lack of authentication.
To fix CVE-2016-2004, upgrade HPE Data Protector to version 7.03_108 or later, 8.15 or later, or 9.06 or later.
HPE Data Protector versions before 7.03_108, 8.x before 8.15, and 9.x before 9.06 are affected by CVE-2016-2004.
There are no known effective workarounds for CVE-2016-2004 aside from upgrading to a patched version.
CVE-2016-2004 exists due to an incomplete fix for a previous vulnerability, CVE-2014-2623, which resulted in insufficient authentication.