RULE(RULE ID:709656)

Rule General Information
Release Date: 2016-07-04
Rule Name: HP Data Protector Opcode 1091 Directory Traversal Vulnerability -3 (CVE-2014-5160)
Severity:
CVE ID:
Rule Protection Details
Description: Multiple directory traversal vulnerabilities in crs.exe in the Cell Request Service in HP Data Protector allow remote attackers to create arbitrary files via an opcode-1091 request, or create or delete arbitrary files via an opcode-305 request.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows
Reference: ZeroDayInitiative:ZDI-14-262
ZeroDayInitiative:ZDI-14-263
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03781657