This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Emc First view 2011-03-16
Product Avamar Last view 2016-07-06
Version 5.0.4-26 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:emc:avamar

Activity : Overall

Related : CVE

  Date Alert Description
8.8 2016-07-06 CVE-2016-0906

The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remote authenticated users to read or delete directories via a Linux backup-restore operation.

9.3 2013-05-03 CVE-2013-0945

EMC Avamar Client before 6.1.101-89 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

3.5 2013-05-03 CVE-2013-0944

The web-based file-restore interface in EMC Avamar Server before 6.1.0 allows remote authenticated users to read arbitrary files via a crafted URL.

7.2 2013-01-21 CVE-2012-2291

EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.

7.7 2011-09-19 CVE-2011-1740

EMC Avamar 4.x, 5.0.x, and 6.0.x before 6.0.0-592 allows remote authenticated users to modify client data or obtain sensitive information about product activities by leveraging privileged access to a different domain.

8.5 2011-03-16 CVE-2011-0648

Unspecified vulnerability in EMC Avamar before 5.0.4-30 allows remote authenticated users to gain privileges via unknown vectors.

CWE : Common Weakness Enumeration

%idName
40% (2) CWE-264 Permissions, Privileges, and Access Controls
20% (1) CWE-284 Access Control (Authorization) Issues
20% (1) CWE-200 Information Exposure
20% (1) CWE-20 Improper Input Validation

Open Source Vulnerability Database (OSVDB)

id Description
75462 EMC Avamar Domain Restrictions Bypass Cross-Domain Client Data Manipulation