Loading
The client in HP Data Protector does not verify the contents of files associated with the EXEC_CMD command, which allows remote attackers to execute arbitrary script code by providing this code with a trusted filename, as demonstrated by omni_chk_ds.sh.
Use CWE-20, Hp vendor hub and Data Protector product page to widen CVE-2011-0924 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2011-0923, CVE-2017-5807 and CVE-2016-2008 for nearby disclosures in the same product family.