crs.exe in the Cell Manager Service in the client in...
Vulnerability Description
crs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, and username, which allows remote attackers to execute arbitrary code by sending unspecified data over TCP, related to the webreporting client, the applet domain, and the java username.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-0921
Credits & Attribution
No credits recorded in the NVD database.
References
- http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-hp
- http://marc.info/?l=bugtraq&m=130391284726795&w=2
- http://www.vupen.com/english/advisories/2011/0308
- http://marc.info/?l=bugtraq&m=130391284726795&w=2
- http://zerodayinitiative.com/advisories/ZDI-11-057/
- http://www.securityfocus.com/bid/46234
More from hp
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.