Computer Associates ARCServe Insecure Default Network Share Vulnerability
BID:3342
Info
Computer Associates ARCServe Insecure Default Network Share Vulnerability
| Bugtraq ID: | 3342 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 16 2001 12:00AM |
| Updated: | Sep 16 2001 12:00AM |
| Credit: | Reported to bugtraq by ron <[email protected]> on September 16, 2001. |
| Vulnerable: |
Computer Associates ARCServe 2000 Advanced Edition 7.0 Computer Associates ARCServe 2000 Computer Associates ARCServe 6.61 |
| Not Vulnerable: | |
Discussion
Computer Associates ARCServe Insecure Default Network Share Vulnerability
ARCserve is an enterprise data backup and recovery solution from Computer Associates.
Default installations of this product have been found to create an insecure network share, leaving an open network directory available to any user in the domain.
Access to this share can allow malicious users to read sensitive system data or overwrite files which could interfere with backup operations or further compromise the host's security.
ARCserve is an enterprise data backup and recovery solution from Computer Associates.
Default installations of this product have been found to create an insecure network share, leaving an open network directory available to any user in the domain.
Access to this share can allow malicious users to read sensitive system data or overwrite files which could interfere with backup operations or further compromise the host's security.
Exploit / POC
Computer Associates ARCServe Insecure Default Network Share Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Computer Associates ARCServe Insecure Default Network Share Vulnerability
Solution:
Computer Associates have released a patch for Windows NT 4.0/Windows 2000 w/SP2a:
>>> ATTN: THIS FIX IS FOR NT 4.0/W2K ONLY <<<
ftp://ftp.ca.com/CAproducts/unicenter/arcserveitaent/0006/qo00945/QO00945.CA
Solution:
Computer Associates have released a patch for Windows NT 4.0/Windows 2000 w/SP2a:
>>> ATTN: THIS FIX IS FOR NT 4.0/W2K ONLY <<<
ftp://ftp.ca.com/CAproducts/unicenter/arcserveitaent/0006/qo00945/QO00945.CA
References
Computer Associates ARCServe Insecure Default Network Share Vulnerability
References:
References: