This application requires Javascript for optimal performance.

HP.Data.Protector.Multple.Products.FinishedCopy.SQL.Injection

Release Date

Nov 26, 2011

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit a SQL Injection vulnerability in HP Data Protector Notebook Extension and HP Data Protector for Personal
Computers.

The vulnerability is a result of the application's failure to properly sanitize user input in the administrator interface. As a result, a remote attacker can leverage this vulnerability to execute arbitrary SQL queries on a target system.

Affected Products

HP Data Protector for Personal Computers 7.0 and prior
HP Data Protector Notebook Extension 6.20 and prior

Recommended Actions

Apply patches or fixes, available from the website:
https://h20565.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03058866&ac.
admitted=1321285525395.876444892.492883150

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-3162

Reference: VID-30407