CVE-2016-0906

HIGH

EMC Avamar <7.2.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remote authenticated users to read or delete directories via a Linux backup-restore operation.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036235
Mailing List mailing-list x_refsource_bugtraq
http://seclists.org/bugtraq/2016/Jul/33

Scores

CVSS v3 8.8
EPSS 0.0041
EPSS Percentile 61.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-284
Status published
Products (1)
emc/avamar < 7.2.1
Published Jul 06, 2016
Tracked Since Feb 18, 2026