CVE-2008-4397

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
14/10/2008
Last modified:
09/04/2025

Description

Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to execute arbitrary commands via a .. (dot dot) in an RPC call with opnum 0x10A.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:arcserve_backup:r12.0:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:business_protection_suite:r2:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:server_protection_suite:r2:*:*:*:*:*:*:*
cpe:2.3:a:ca:arcserve_backup:r11.1:*:*:*:*:*:*:*
cpe:2.3:a:ca:arcserve_backup:r11.5:*:*:*:*:*:*:*
cpe:2.3:a:ca:business_protection_suite:r2:*:microsoft_small_business_server_premium:*:*:*:*:*
cpe:2.3:a:ca:business_protection_suite:r2:*:microsoft_small_business_server_standard:*:*:*:*:*