Computer Associates ARCserve Backup Multiple Remote Vulnerabilities
BID:31684
Info
Computer Associates ARCserve Backup Multiple Remote Vulnerabilities
| Bugtraq ID: | 31684 |
| Class: | Unknown |
| CVE: |
CVE-2008-4397 CVE-2008-4398 CVE-2008-4399 CVE-2008-4400 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2008 12:00AM |
| Updated: | Dec 02 2009 06:24PM |
| Credit: | The vendor credits Haifei Li of Fortinet's FortiGuard Global Security Research Team, Vulnerability Research Team of Assurent Secure Technologies, a TELUS Company, and Greg Linares of eEye Digital Security for discovering these vulnerabilities. |
| Vulnerable: |
Computer Associates Server Protection Suite r2 Computer Associates Business Protection Suite for Microsoft SBS Std Ed r2 Computer Associates Business Protection Suite for Microsoft SBS Pre ed r2 Computer Associates Business Protection Suite r2 Computer Associates BrightStor Enterprise Backup 10.5 Computer Associates BrightStor ARCserve Backup for Windows (All) 11.5 Computer Associates BrightStor ARCserve Backup for Windows (All) 11.1 Computer Associates BrightStor ARCServe Backup for Windows 11.0 Computer Associates BrightStor ARCServe Backup 11.1 Computer Associates BrightStor ARCServe Backup r12.0 Windows Computer Associates BrightStor ARCServe Backup r12 Computer Associates BrightStor ARCServe Backup 11.5 |
| Not Vulnerable: |
Computer Associates BrightStor ARCServe Backup r12.0 Windows SP1 |
Discussion
Computer Associates ARCserve Backup Multiple Remote Vulnerabilities
Computer Associates ARCserve Backup is prone to multiple remote vulnerabilities.
Successful exploits allow remote attackers to cause denial-of-service conditions or to execute arbitrary commands in the context of the affected application. This may result in a complete compromise of affected computers.
The following applications are affected:
CA BrightStor ARCserve Backup r11.1, r11.5, r12.0 for Windows
CA Server Protection Suite r2
CA Business Protection Suite r2
CA Business Protection Suite for Microsoft Small Business Server Standard Edition r2
CA Business Protection Suite for Microsoft Small Business Server Premium Edition r2
Computer Associates ARCserve Backup is prone to multiple remote vulnerabilities.
Successful exploits allow remote attackers to cause denial-of-service conditions or to execute arbitrary commands in the context of the affected application. This may result in a complete compromise of affected computers.
The following applications are affected:
CA BrightStor ARCserve Backup r11.1, r11.5, r12.0 for Windows
CA Server Protection Suite r2
CA Business Protection Suite r2
CA Business Protection Suite for Microsoft Small Business Server Standard Edition r2
CA Business Protection Suite for Microsoft Small Business Server Premium Edition r2
Exploit / POC
Computer Associates ARCserve Backup Multiple Remote Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Computer Associates ARCserve Backup Multiple Remote Vulnerabilities
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Computer Associates Business Protection Suite r2
Computer Associates BrightStor ARCServe Backup r12.0 Windows
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Computer Associates Business Protection Suite r2
-
Computer Associates RO02398
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=sear ch&searchID=RO02398
Computer Associates BrightStor ARCServe Backup r12.0 Windows
-
Computer Associates RO01340
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=sear ch&searchID=RO01340
References
Computer Associates ARCserve Backup Multiple Remote Vulnerabilities
References:
References:
- Computer Associates Homepage (Computer Associates)
- Security Notice for CA ARCserve Backup (Computer Associates)
- CA ARCserve Backup Multiple Vulnerabilities ("Williams, James K"
) - CA BrightStor ARCServe BackUp Message Engine Remote Command Injection Vulnerabil (cocoruder
)