CVE-2017-15550: Path Traversal
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could access arbitrary files on the server file system in the context of the running vulnerable application via Path traversal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15550?
The severity of CVE-2017-15550 is critical.
How can a remote authenticated malicious user exploit CVE-2017-15550?
A remote authenticated malicious user with low privileges can access arbitrary files on the server file system.
Which EMC products are affected by CVE-2017-15550?
EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0 are affected by CVE-2017-15550.
What is the Common Weakness Enumeration (CWE) ID for CVE-2017-15550?
The CWE ID for CVE-2017-15550 is 22.
Where can I find more information about CVE-2017-15550?
You can find more information about CVE-2017-15550 at the following references: [http://seclists.org/fulldisclosure/2018/Jan/17](http://seclists.org/fulldisclosure/2018/Jan/17), [http://www.securityfocus.com/bid/102358](http://www.securityfocus.com/bid/102358), [http://www.securitytracker.com/id/1040070](http://www.securitytracker.com/id/1040070).