EMC
EMC Avamar Server: vulnerabilidades y CVE
EMC Avamar Server tiene 13 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-15550 | Alta (8.8) | 8.2% | — | 5 ene 2018 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious… |
| CVE-2017-15549 | Alta (8.8) | 5.5% | — | 5 ene 2018 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious… |
| CVE-2017-15548 | Crítica (9.8) | 4.7% | — | 5 ene 2018 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote unauthenticated… |
| CVE-2017-4990 | Crítica (9.8) | 3.0% | — | 21 jun 2017 | In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any… |
| CVE-2017-4989 | Crítica (9.8) | 3.3% | — | 21 jun 2017 | In EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypass the authentication process to gain access to the system maintenance… |
| CVE-2016-0921 | Media (6.5) | 0.39% | — | 21 sept 2016 | Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use weak permissions for unspecified directories, which allows local users to obtain root access by replacing a script with… |
| CVE-2016-0920 | Alta (7.8) | 0.41% | — | 21 sept 2016 | Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root access via a crafted parameter to a command that is available in the sudo configuration. |
| CVE-2016-0905 | Media (6.7) | 0.43% | — | 21 sept 2016 | Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root privileges by leveraging admin access and entering a sudo command. |
| CVE-2016-0904 | Alta (8.6) | 1.4% | — | 21 sept 2016 | Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows remote attackers to defeat cryptographic… |
| CVE-2016-0903 | Crítica (9.1) | 3.4% | — | 21 sept 2016 | Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote attackers to spoof clients and read backup data via a modified… |
| CVE-2015-4527 | Alta (7.8) | 2.7% | — | 23 jul 2015 | Directory traversal vulnerability in EMC Avamar Server 7.x before 7.1.2 and Avamar Virtual Addition (AVE) 7.x before 7.1.2 allows remote attackers to read arbitrary files by using the Avamar Desktop/Laptop client… |
| CVE-2013-3275 | Media (4.3) | 0.81% | — | 19 jul 2013 | EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly restrict use of FRAME elements, which makes it easier for remote attackers to obtain sensitive… |
| CVE-2013-3274 | Alta (9) | 3.1% | — | 19 jul 2013 | EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly determine authorization for calls to Java RMI methods, which allows remote authenticated users to… |
Otros productos de EMC
RSA Authentication Manager · 25RSA Archer Egrc · 23Documentum Content Server · 21Networker · 20Isilon Onefs · 15Documentum Webtop · 13Documentum Taskspace · 12Documentum D2 · 12RSA Identity Management AND Governance · 11Documentum Administrator · 10Documentum WDK · 10RSA Adaptive Authentication On-premise · 10