← All CVEs

CVE-2008-4397

high · 10

Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to execute arbitrary commands via a .. (dot dot) in an RPC call with opnum 0x10A.

10
CVSS
80.5%
EPSS (exploit prob.)
100th
EPSS percentile
2008-10-14
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-20CWE-22

Affected products

VendorProductAffected versions
broadcomarcserve_backupr12.0
broadcombusiness_protection_suiter2
broadcomserver_protection_suiter2
caarcserve_backupr11.1
caarcserve_backupr11.5
cabusiness_protection_suiter2
cabusiness_protection_suiter2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-4397