Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to execute arbitrary commands via a .. (dot dot) in an RPC call with opnum 0x10A.
| Software | From | Fixed in |
|---|---|---|
| ca / business_protection_suite | r2 | r2.x |
| ca / arcserve_backup | r11.1 | r11.1.x |
| ca / arcserve_backup | r11.5 | r11.5.x |
| broadcom / arcserve_backup | r12.0 | r12.0.x |
| broadcom / business_protection_suite | r2 | r2.x |
| broadcom / server_protection_suite | r2 | r2.x |