Check Point Reference: | CPAI-2009-099 |
Date Published: | 22 Jul 2009 |
Severity: | High |
Last Updated: | Tuesday 19 January, 2016 |
Source: | |
Industry Reference: | CVE-2009-1761 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | |
Vulnerability Description | Computer Associates (CA) provides a group of security and management products for enterprise as well as individual clients. A denial of service vulnerability exists in CA ARCserve Backup Message Engine. The vulnerability exists in CA ARCserve Message Engine. The vulnerability is due to insufficient checks on user supplied parameters when handling RPC messages. An unauthenticated remote attacker can exploit this vulnerability by sending malicious requests to the affected interface. |
This protection will detect and block specific RPC requests to the RCserve Message Engine with invalid parameters.
In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.
This protection's log will contain the following information:
Attack Name: CA Products Enforcement Violation.
Attack Information: CA ARCserve backup message engine denial of service