CVE-2013-0944: Infoleak
Published May 3, 2013
·Updated
The web-based file-restore interface in EMC Avamar Server before 6.1.0 allows remote authenticated users to read arbitrary files via a crafted URL.
Affected Software
9 affected components
EMC Avamar=5.0
EMC Avamar=5.0-sp1
EMC Avamar=5.0-sp2
EMC Avamar=5.0.0-407
EMC Avamar=5.0.4-26
EMC Avamar=6.0
EMC Avamar=6.0.1
EMC Avamar=6.0.2
EMC Avamar=6.0.3
Event History
May 3, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0944?
CVE-2013-0944 has a medium severity rating, indicating it could lead to unauthorized file access by remote authenticated users.
2
How can I fix CVE-2013-0944?
To address CVE-2013-0944, upgrade EMC Avamar Server to version 6.1.0 or later.
3
What platforms are affected by CVE-2013-0944?
CVE-2013-0944 affects multiple versions of EMC Avamar Server, including 5.0, 5.0 SP1, 5.0 SP2, and 6.0 versions.
4
Who can exploit CVE-2013-0944?
CVE-2013-0944 can be exploited by remote authenticated users who have access to the web-based file-restore interface.
5
What types of files can be accessed due to CVE-2013-0944?
CVE-2013-0944 allows remote authenticated users to read arbitrary files on the server through crafted URLs.