Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 stores the backup agent user name and password in cleartext in the aremote.dmp file in the ARCSERVE$ hidden share, which allows local and remote attackers to gain privileges.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2001-09/0137.html | Vendor Advisory |
http://support.ca.com/Download/patches/asitnt/QO00945.html | Patch |
http://www.securityfocus.com/bid/3343 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7122 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2001-09-14 21:00
Updated : 2021-04-07 11:13
NVD link : CVE-2001-0960
Mitre link : CVE-2001-0960
JSON object : View
CWE
Products Affected
broadcom
- arcserve_backup_2000
- arcserve_backup
ca
- arcserve_backup_2000