First published: Thu Jul 23 2015(Updated: )
Directory traversal vulnerability in EMC Avamar Server 7.x before 7.1.2 and Avamar Virtual Addition (AVE) 7.x before 7.1.2 allows remote attackers to read arbitrary files by using the Avamar Desktop/Laptop client interface to send crafted parameters.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Avamar Server Virtual Edition | =7.1 | |
EMC Avamar Virtual Edition | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4527 has a high severity rating due to its potential to allow remote attackers to read arbitrary files.
To fix CVE-2015-4527, upgrade EMC Avamar Server and Avamar Virtual Edition to version 7.1.2 or later.
CVE-2015-4527 affects EMC Avamar Server versions 7.1 and prior, as well as Avamar Virtual Edition versions 7.1 and prior.
Yes, CVE-2015-4527 can be exploited remotely through crafted parameters sent via the Avamar Desktop/Laptop client interface.
CVE-2015-4527 allows access to arbitrary files, which can pose significant security risks.