BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently execute arbitrary commands, via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://securityreason.com/securityalert/8338 | third party advisory |
https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=%7B7D3ACC0F-6C01-4BE2-B5C0-C430CEB45BE6%7D | |
http://www.securityfocus.com/archive/1/519234/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/48897 | vdb entry exploit |