CVE-2016-6645: Input Validation
The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote authenticated users to execute arbitrary code via crafted input to the (1) GeneralCmdRequest, (2) PersistantDataRequest, or (3) GetCommandExecRequest class.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6645?
CVE-2016-6645 is classified as a high severity vulnerability that allows remote authenticated users to execute arbitrary code.
How do I fix CVE-2016-6645?
To remediate CVE-2016-6645, upgrade to EMC Unisphere for VMAX Virtual Appliance and Solutions Enabler Virtual Appliance version 8.3.0 or later.
What systems are affected by CVE-2016-6645?
CVE-2016-6645 affects versions 8.0, 8.1, 8.2 of EMC Unisphere and versions 8.0, 8.1, 8.2 of EMC Solutions Enabler.
Can CVE-2016-6645 be exploited remotely?
Yes, CVE-2016-6645 can be exploited remotely by authenticated users who provide crafted input to specific requests.
What is the impact of CVE-2016-6645?
The impact of CVE-2016-6645 includes the potential for unauthorized access and execution of arbitrary code in affected systems.