## https://sploitus.com/exploit?id=SAINT:1EEFF355DD77A575413B94508CDE604E
Added: 01/26/2011
CVE: [CVE-2010-0219](<https://vulners.com/cve/CVE-2010-0219>)
BID: [45625](<http://www.securityfocus.com/bid/45625>)
OSVDB: [70233](<http://www.osvdb.org/70233>)
### Background
[CA ARCserve D2D](<http://arcserve.com/gb/products/ca-arcserve-d2d.aspx>) is a disk-based backup solution.
### Problem
CA ARCserve D2D deploys Axis2 with default credentials which can be used to gain unauthorized access to the web application server. By then uploading a specially crafted axis2 service, an attacker could execute arbitrary commands on the system.
### Resolution
Change the password for the admin account in the axis2.xml file, which is found in the \Program Files\CA\ARCserve D2D\TOMCAT\webapps\WebServiceImpl\WEB-INF\conf folder.
### References
<http://www.securityfocus.com/archive/1/515494>
### Limitations
Exploit works on CA ARCserve D2D r15.
There may be a delay before the exploit succeeds.
### Platforms
Windows