CVE-2016-0906: High severity emc avamar virtual edition vulnerability
Published Jul 6, 2016
·Updated
The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remote authenticated users to read or delete directories via a Linux backup-restore operation.
Affected Software
1 affected component
EMC Avamar<=7.2.1
Event History
Jul 6, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0906?
CVE-2016-0906 has a medium severity rating due to the potential for remote authenticated users to manipulate critical data.
2
How do I fix CVE-2016-0906?
To fix CVE-2016-0906, update your EMC Avamar software to version 7.2.2 or later.
3
Who is affected by CVE-2016-0906?
Organizations using EMC Avamar versions up to 7.2.1 are affected by CVE-2016-0906.
4
What is the impact of CVE-2016-0906?
The impact of CVE-2016-0906 includes unauthorized access to read or delete directories in the Avamar system.
5
Can CVE-2016-0906 be exploited remotely?
Yes, CVE-2016-0906 can be exploited by remote authenticated users, posing a security risk.