A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates BrightStor ARCserve Backup. User interaction is not required to exploit this vulnerability. The specific flaw exists in the Tape Engine RPC service which listens by default on TCP port 6503. Affected include BrightStor ARCserve Backup r11.5, BrightStor ARCserve Backup r11.1, BrightStor ARCserve Backup r11, BrightStor Enterprise Backup r10.5, and BrightStor ARCserve Backup v9.01.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/53617/ZDI-07-004.txt
Source: https://packetstormsecurity.com/files/53617/Zero-Day-Initiative-Advisory-07-04.html

