10
CVSSv2

CVE-2011-2397

Published: 05/12/2011 Updated: 29/08/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Agent service in Iron Mountain Connected Backup 8.4 allows remote malicious users to execute arbitrary code via a crafted opcode 13 request that triggers use of the LaunchCompoundFileAnalyzer class to send request data to the System.getRunTime.exec method.

Vulnerable Product Search on Vulmon Subscribe to Product

ironmountain connected backup 8.4