|
|
| |
Credit:
The information has been provided by Andrea Micalizzi aka rgod.
The original article can be found at: http://www.zerodayinitiative.com/advisories/ZDI-11-324/
|
| |
Vulnerable Systems:
* Hewlett-Packard Data Protector
Authentication is not required to exploit this vulnerability.
The flaw exists within the dpnepolicyservice component which exposes a DPNECentral Web Service on TCP port 80. This service contains a method RequestCopy which does not properly validate or sanitize the type field of a user supplied request. This value is later used when constructing a query fulfill provided request. A remote attacker can exploit this vulnerability to execute arbitrary queries under the context of the service.
Patch Availability:
Hewlett-Packard has issued an update to correct this vulnerability. More details can be found at:
https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03058866
CVE Information:
CVE-2011-3158
Disclosure Timeline:
2011-06-03 - Vulnerability reported to vendor
2011-11-07 - Coordinated public release of advisory
|
|
|