CVE-2011-0921

crs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, and username, which allows remote attackers to execute arbitrary code by sending unspecified data over TCP, related to the webreporting client, the applet domain, and the java username.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hp:data_protector:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:25

Type Values Removed Values Added
References () http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-hp - () http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-hp -
References () http://marc.info/?l=bugtraq&m=130391284726795&w=2 - () http://marc.info/?l=bugtraq&m=130391284726795&w=2 -
References () http://www.securityfocus.com/bid/46234 - () http://www.securityfocus.com/bid/46234 -
References () http://www.vupen.com/english/advisories/2011/0308 - Vendor Advisory () http://www.vupen.com/english/advisories/2011/0308 - Vendor Advisory
References () http://zerodayinitiative.com/advisories/ZDI-11-057/ - () http://zerodayinitiative.com/advisories/ZDI-11-057/ -

Information

Published : 2011-02-09 01:00

Updated : 2025-04-11 00:51


NVD link : CVE-2011-0921

Mitre link : CVE-2011-0921

CVE.ORG link : CVE-2011-0921


JSON object : View

Products Affected

hp

  • data_protector
CWE
CWE-20

Improper Input Validation