CVE-2017-15549: Malicious File Upload
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could potentially upload arbitrary maliciously crafted files in any location on the server file system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-15549?
CVE-2017-15549 is a vulnerability discovered in EMC Avamar Server, EMC NetWorker Virtual Edition (NVE), and EMC Integrated Data Protection Appliance.
What is the severity of CVE-2017-15549?
CVE-2017-15549 has a severity level of critical.
How does CVE-2017-15549 affect EMC Avamar Server?
CVE-2017-15549 affects EMC Avamar Server versions 7.1.x to 7.5.0.
How does CVE-2017-15549 impact EMC NetWorker Virtual Edition (NVE)?
CVE-2017-15549 impacts EMC NetWorker Virtual Edition (NVE) versions 9.0.x to 9.2.x.
How can I fix CVE-2017-15549?
To fix CVE-2017-15549, it is recommended to apply the necessary security patches provided by EMC.