CVE-2016-0906

The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remote authenticated users to read or delete directories via a Linux backup-restore operation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:emc:avamar:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:42

Type Values Removed Values Added
References () http://seclists.org/bugtraq/2016/Jul/33 - () http://seclists.org/bugtraq/2016/Jul/33 -
References () http://www.securitytracker.com/id/1036235 - () http://www.securitytracker.com/id/1036235 -

Information

Published : 2016-07-06 14:59

Updated : 2024-11-21 02:42


NVD link : CVE-2016-0906

Mitre link : CVE-2016-0906

CVE.ORG link : CVE-2016-0906


JSON object : View

Products Affected

emc

  • avamar
CWE
CWE-284

Improper Access Control