René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

98 lines
3.0 KiB
JSON

{
"id": "CVE-2011-0921",
"sourceIdentifier": "cve@mitre.org",
"published": "2011-02-09T01:00:09.557",
"lastModified": "2016-08-23T02:03:33.457",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "crs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, and username, which allows remote attackers to execute arbitrary code by sending unspecified data over TCP, related to the webreporting client, the applet domain, and the java username."
},
{
"lang": "es",
"value": "crs.exe de Cell Manager Service en el cliente de HP Data Protector no valida correctamente las credenciales asociadas con el nombre de host, dominio y nombre de usuario, que permite a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n mediante el env\u00edo de datos sin especificar a trav\u00e9s de TCP, relacionado con el cliente webreporting, el dominio del applet y el nombre de usuario Java."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 10.0
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:hp:data_protector:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BA2D6151-9F6C-4A0B-8A46-E53E65AFADA3"
}
]
}
]
}
],
"references": [
{
"url": "http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-hp",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=130391284726795&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/46234",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2011/0308",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://zerodayinitiative.com/advisories/ZDI-11-057/",
"source": "cve@mitre.org"
}
]
}