The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remote authenticated users to read or delete directories via a Linux backup-restore operation.
References
Configurations
History
21 Nov 2024, 02:42
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/bugtraq/2016/Jul/33 - | |
References | () http://www.securitytracker.com/id/1036235 - |
Information
Published : 2016-07-06 14:59
Updated : 2024-11-21 02:42
NVD link : CVE-2016-0906
Mitre link : CVE-2016-0906
CVE.ORG link : CVE-2016-0906
JSON object : View
Products Affected
emc
- avamar
CWE
CWE-284
Improper Access Control