CVE-2015-0515: Medium severity emc watch4net vulnerability
Published Jan 21, 2015
·Updated
Unrestricted file upload vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to execute arbitrary code by uploading and then accessing an executable file.
Affected Software
2 affected components
EMC Watch4Net<=6.5
EMC ViPR SRM<=3.6.0
Event History
Jan 21, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0515?
CVE-2015-0515 has a high severity level due to its potential for remote code execution by uploading malicious files.
2
How do I fix CVE-2015-0515?
To fix CVE-2015-0515, upgrade EMC M&R to version 6.5u1 or later or ViPR SRM to version 3.6.1 or later.
3
Who is affected by CVE-2015-0515?
CVE-2015-0515 affects users of EMC Watch4Net versions prior to 6.5u1 and EMC ViPR SRM versions prior to 3.6.1.
4
What types of attacks can occur due to CVE-2015-0515?
Attackers can exploit CVE-2015-0515 to upload and execute arbitrary code on affected systems.
5
Is authentication required to exploit CVE-2015-0515?
Yes, exploitation of CVE-2015-0515 requires remote authenticated user access.