CVE-2008-4397

Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to execute arbitrary commands via a .. (dot dot) in an RPC call with opnum 0x10A.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:broadcom:arcserve_backup:r12.0:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:business_protection_suite:r2:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:server_protection_suite:r2:*:*:*:*:*:*:*
cpe:2.3:a:ca:arcserve_backup:r11.1:*:*:*:*:*:*:*
cpe:2.3:a:ca:arcserve_backup:r11.5:*:*:*:*:*:*:*
cpe:2.3:a:ca:business_protection_suite:r2:*:microsoft_small_business_server_premium:*:*:*:*:*
cpe:2.3:a:ca:business_protection_suite:r2:*:microsoft_small_business_server_standard:*:*:*:*:*

History

21 Nov 2024, 00:51

Type Values Removed Values Added
References () http://secunia.com/advisories/32220 - Vendor Advisory () http://secunia.com/advisories/32220 - Vendor Advisory
References () http://securityreason.com/securityalert/4412 - () http://securityreason.com/securityalert/4412 -
References () http://www.securityfocus.com/archive/1/497218 - () http://www.securityfocus.com/archive/1/497218 -
References () http://www.securityfocus.com/archive/1/497281/100/0/threaded - () http://www.securityfocus.com/archive/1/497281/100/0/threaded -
References () http://www.securityfocus.com/bid/31684 - () http://www.securityfocus.com/bid/31684 -
References () http://www.securitytracker.com/id?1021032 - () http://www.securitytracker.com/id?1021032 -
References () http://www.vupen.com/english/advisories/2008/2777 - () http://www.vupen.com/english/advisories/2008/2777 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/45774 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/45774 -
References () https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=188143 - Patch, Vendor Advisory () https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=188143 - Patch, Vendor Advisory

Information

Published : 2008-10-14 21:10

Updated : 2024-11-21 00:51


NVD link : CVE-2008-4397

Mitre link : CVE-2008-4397

CVE.ORG link : CVE-2008-4397


JSON object : View

Products Affected

broadcom

  • arcserve_backup
  • server_protection_suite
  • business_protection_suite

ca

  • business_protection_suite
  • arcserve_backup
CWE
CWE-20

Improper Input Validation

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')