EMC Avamar ADS and AVE unauthorized Data Access Vulnerability (CVE-2016-0906)
EMC Avamar ADS and AVE unauthorized Data Access Vulnerability (CVE-2016-0906)
Release date:
Updated on:
Affected Systems:
EMC Avamar <7.1.2
EMC Avamar 7.2.x <7.2.1
Description:
CVE (CAN) ID: CVE-2016-0906
EMC Avamar is a remote backup and recovery solution.
EMC Avamar <7.1.2, 7.2.x <7.2.1, and ADS and AVE have security vulnerabilities in web-restore interface implementation. Verified remote users can read or delete directories through the Linux backup-restore operation.
<* Source: EMC Product Security Response Center
*>
Suggestion:
Vendor patch:
EMC
---
The vendor has released a patch to fix this security problem. download the following version from the vendor's homepage:
EMC Avamar version 7.2.1 HOTFIX 256706
EMC Avamar version 7.1.2 HOTFIX 256730
Ftp: // avamar_ftp: anonymous () ftp avamar com/software/hotfixes/256706
Ftp: // avamar_ftp: anonymous () ftp avamar com/software/hotfixes/256730
This article permanently updates the link address: