Computer Associates ARCserve D2D 'homepageServlet' Servlet Information Disclosure Vulnerability
BID:48897
Info
Computer Associates ARCserve D2D 'homepageServlet' Servlet Information Disclosure Vulnerability
| Bugtraq ID: | 48897 |
| Class: | Design Error |
| CVE: |
CVE-2011-3011 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2011 12:00AM |
| Updated: | Jan 03 2012 06:20PM |
| Credit: | rgod |
| Vulnerable: |
Computer Associates ARCserve D2D for Windows Server Standard Edition r15 Computer Associates ARCServe D2D r15 Computer Associates ARCserve Backup for Windows D2D Option Basic Edition r15 |
| Not Vulnerable: | |
Discussion
Computer Associates ARCserve D2D 'homepageServlet' Servlet Information Disclosure Vulnerability
Computer Associates ARCserve D2D is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks such as arbitrary code execution attack.
Computer Associates ARCserve D2D is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks such as arbitrary code execution attack.
Exploit / POC
Computer Associates ARCserve D2D 'homepageServlet' Servlet Information Disclosure Vulnerability
Attackers can use a browser to exploit this issue.
Example input is available. Please see the references for more information.
The following exploit code is available:
Attackers can use a browser to exploit this issue.
Example input is available. Please see the references for more information.
The following exploit code is available:
Solution / Fix
Computer Associates ARCserve D2D 'homepageServlet' Servlet Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
Computer Associates ARCserve D2D 'homepageServlet' Servlet Information Disclosure Vulnerability
References:
References:
- ARCserve D2D Homepage (Computer Associates)
- CA ARCserve D2D r15 GWT RPC Request Auth Bypass Credentials Disclosure and Comma (rgod)
- CA20110809-01: Security Notice for CA ARCserve D2D (Computer Associates)
- Solution Document for RO33517 (Computer Associates)
- Re: CA ARCserve D2D r15 GWT RPC Request Auth Bypass / Credentials ("Williams, James K"
) - HS11-025: Vulnerability in CA ARCserve D2D (HITACHI)