BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently execute arbitrary commands, via unspecified vectors.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2011-2979
http://www.securityfocus.com/bid/48897
http://www.securityfocus.com/archive/1/519234/100/0/threaded