IBM (NYSE: IBM) announced that its Internet Security Systems (ISS) X-Force® research and development team has discovered and preemptively protected customers from two similar, but distinct vulnerabilities in CA Brightstor ARCserve. This product is a cross-platform backup and recovery solution for small- to medium-sized businesses that protects and helps ensure the availability of critical applications and data. The vulnerabilities discovered by X-Force can be exploited remotely with no user interaction required. Successful exploitation could grant the attacker administrative privileges on the target machine.
“CA Brightstor ARCserve is widely deployed in corporate environments,” said Pete Allor, director of intelligence for IBM Internet Security Systems. “Since it is normally used for the protection and recovery of mission-critical applications, and since these two vulnerabilities are not difficult to exploit, ISS recommends that companies using CA Brightstor ARCserve patch immediately.”
IBM ISS customers have been preemptively protected from these issues since November. By infusing its products and services with security intelligence from X-Force and the unique IBM Virtual Patch® technology, IBM designs its solution to protect customers before their business assets are impacted by online intrusions.
The X-Force security advisories on these vulnerabilities can be found at:
http://www.iss.net/threats/252.html
http://www.iss.net/threats/253.html
About IBM Internet Security Systems
IBM Internet Security Systems is the trusted security advisor to thousands of the world’s leading businesses and governments, providing preemptive protection for networks, desktops and servers. An established leader in security since 1994, the IBM Proventia® integrated security platform is designed to automatically protect against both known and unknown threats, helping to keep networks up and running and shielding customers from online attacks before they impact business assets. IBM Internet Security Systems products and services are based on the proactive security intelligence of its X-Force® research and development team – the unequivocal world authority in vulnerability and threat research. The Internet Security Systems product line is also complemented by comprehensive Managed Security Services and Professional Security Services. For more information, visit the Internet Security Systems Web site at www.iss.net or call 800-776-2362.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment