Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.31% | — | IBM Data Protection | 2/8/2019 | 17/6/2026 | IBM Spectrum Protect for Enterprise Resource Planning 7.1 and 8.1, if tracing is activated, the IBM Spectrum Protect node password may be displayed in plain text in the ERP trace file. IBM X-Force ID: 154280. | |
| Modificada | Media (4.3) | 0.21% | — | Dell Data Protection | Encryption | 5/12/2018 | 17/6/2026 | Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulnerability to access the unencrypted RegBack folder that contains back-ups of sensitive system files. | |
| Modificada | Media (6.7) | 1.0% | — | Dell EMC AvamarDell EMC Integrated Data Protection ApplianceVmware Vsphere Data Protection | 26/11/2018 | 17/6/2026 | 'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A malicious Avamar admin user may potentially be able to execute… | |
| Modificada | Media (6.5) | 0.83% | — | Dell EMC AvamarDell EMC Integrated Data Protection ApplianceVmware Vsphere Data Protection | 26/11/2018 | 17/6/2026 | Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected by an information exposure vulnerability. Avamar Java management console's SSL/TLS private key may be leaked in the Avamar Java management client package. The private… | |
| Modificada | Media (6.1) | 1.8% | — | Dell EMC AvamarDell EMC Integrated Data Protection ApplianceVmware Vsphere Data Protection | 26/11/2018 | 17/6/2026 | Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection vulnerability. A remote unauthenticated attacker could potentially exploit this… | |
| Modificada | Crítica (9.8) | 9.9% | — | Dell EMC AvamarDell EMC Integrated Data Protection ApplianceVmware Vsphere Data Protection | 26/11/2018 | 17/6/2026 | Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain a Remote Code Execution vulnerability. A remote unauthenticated attacker could potentially exploit… | |
| Modificada | Alta (7.5) | 2.4% | — | IBM Spectrum ProtectIBM Tivoli Storage ManagerIBM Spectrum Protect Manager FOR Virtual Environments Data Protection FOR VmwareIBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware+2 | 12/11/2018 | 17/6/2026 | IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871. | |
| Modificada | Alta (8.8) | 1.8% | — | Dell EMC Integrated Data Protection Appliance | 2/11/2018 | 17/6/2026 | Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin' that are protected with default passwords. These accounts have limited privileges and can access certain system files only. A malicious user with the knowledge of the default passwords may… | |
| Modificada | Alta (8.1) | 2.1% | — | Dell EMC Data Protection AdvisorDell EMC Integrated Data Protection Appliance | 10/8/2018 | 17/6/2026 | Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 contain a XML External Entity (XXE) Injection vulnerability in the REST API. An authenticated remote malicious user could potentially exploit this vulnerability to read certain… | |
| Modificada | Crítica (9.8) | 51% | 💥 Exploit | Dell EMC AvamarDell EMC Integrated Data Protection Appliance | 9/4/2018 | 17/6/2026 | Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the Local Download Service (LDLS)… | |
| Modificada | Crítica (9.8) | 2.1% | — | EMC Data Protection Advisor | 16/3/2018 | 17/6/2026 | EMC Data Protection Advisor 6.3.x before patch 67 and 6.4.x before patch 130 contains undocumented accounts with hard-coded passwords and various privileges. Affected accounts are: "Apollo System Test", "emc.dpa.agent.logon" and "emc.dpa.metrics.logon". An attacker with knowledge of the password could potentially use… | |
| Modificada | Alta (7.8) | 0.34% | — | EMC Data Protection Advisor | 12/3/2018 | 17/6/2026 | Dell EMC Data Protection Advisor versions prior to 6.3 Patch 159 and Dell EMC Data Protection Advisor versions prior to 6.4 Patch 110 contain a hardcoded database account with administrative privileges. The affected account is "apollosuperuser." An attacker with local access to the server where DPA Datastore Service… | |
| Modificada | Alta (8.8) | 8.2% | — | EMC Avamar ServerEMC Integrated Data Protection ApplianceEMC Networker | 5/1/2018 | 17/6/2026 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could access arbitrary files on the server file system in the context of… | |
| Modificada | Alta (8.8) | 5.5% | — | EMC Avamar ServerEMC Integrated Data Protection ApplianceEMC Networker | 5/1/2018 | 17/6/2026 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could potentially upload arbitrary maliciously crafted files in any… | |
| Modificada | Crítica (9.8) | 4.7% | — | EMC Avamar ServerEMC Integrated Data Protection ApplianceEMC Networker | 5/1/2018 | 17/6/2026 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote unauthenticated malicious user can potentially bypass application authentication and gain unauthorized root access to the… | |
| Modificada | Alta (8.8) | 6.7% | — | EMC Data Protection Advisor | 19/10/2017 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection Advisor 6.3.0. Authentication is required to exploit this vulnerability. The specific flaw exists within the EMC DPA Application service, which listens on TCP port 9002 by default. When parsing the… | |
| Modificada | Media (4.9) | 2.6% | — | EMC Data Protection Advisor | 9/7/2017 | 17/6/2026 | EMC Data Protection Advisor prior to 6.4 contains a path traversal vulnerability. A remote authenticated high privileged user may potentially exploit this vulnerability to access unauthorized information from the underlying OS server by supplying specially crafted strings in input parameters of the application. | |
| Modificada | Alta (8.8) | 2.3% | — | EMC Data Protection Advisor | 9/7/2017 | 17/6/2026 | EMC Data Protection Advisor prior to 6.4 contains multiple blind SQL injection vulnerabilities. A remote authenticated attacker may potentially exploit these vulnerabilities to gain information about the application by causing execution of arbitrary SQL commands. | |
| Modificada | Crítica (9.8) | 0.84% | — | Vmware Vsphere Data Protection | 7/6/2017 | 17/6/2026 | VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained. | |
| Modificada | Crítica (9.8) | 8.8% | 💥 Exploit | Vmware Vsphere Data Protection | 7/6/2017 | 17/6/2026 | VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance. | |
| Modificada | Alta (8.8) | 0.55% | — | IBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR VmwareIBM Tivoli Storage Flashcopy Manager FOR Vmware | 15/2/2017 | 17/6/2026 | IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1995545. | |
| Modificada | Alta (7.5) | 3.0% | — | Dell EMC Data Protection Advisor | 3/2/2017 | 17/6/2026 | EMC Data Protection Advisor 6.1.x, EMC Data Protection Advisor 6.2, EMC Data Protection Advisor 6.2.1, EMC Data Protection Advisor 6.2.2, EMC Data Protection Advisor 6.2.3 prior to patch 446 has a path traversal vulnerability that may potentially be exploited by malicious users to compromise the affected system. | |
| Modificada | Media (6.5) | 0.33% | — | IBM Tivoli Storage ManagerIBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware | 1/2/2017 | 17/6/2026 | IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local user. | |
| Modificada | Media (6.8) | 1.00% | — | IBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware | 1/2/2017 | 17/6/2026 | IBM Tivoli Storage Manager for Virtual Environments (VMware) could disclose the Windows domain credentials to a user with a high level of privileges. | |
| Modificada | Crítica (9.8) | 33% | 💥 Exploit | Vmware Vsphere Data Protection | 29/12/2016 | 17/6/2026 | VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attackers to obtain login access via an SSH session. |