CVE-2015-7253: OS Command Injection
Published Nov 4, 2015
·Updated
The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a cookie.
Affected Software
1 affected component
Commvault Edge Server=10-r2
Event History
Nov 4, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7253?
CVE-2015-7253 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2015-7253?
To fix CVE-2015-7253, update to the latest version of Commvault Edge Server that addresses this vulnerability.
3
What products are affected by CVE-2015-7253?
CVE-2015-7253 affects Commvault Edge Server version 10 R2.
4
What type of vulnerability is CVE-2015-7253?
CVE-2015-7253 is a remote command execution vulnerability.
5
Can CVE-2015-7253 be exploited remotely?
Yes, CVE-2015-7253 can be exploited remotely by attackers to execute arbitrary OS commands.