EMC Avamar Data Store / Virtual Edition Unauthorized Data Access

Discussion in 'News Aggregator' started by Packet Storm, 7 Jul 2016.

  1. Packet Storm

    Packet Storm Guest

    EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) have released a fix for a vulnerability that may potentially lead to denial of service and data disclosure. When restoring backups of Linux Avamar clients using the web restore interface, a malicious Avamar Client user may read and/or delete critical directories on the Avamar Server. This may lead to a denial-of-service attack on the Avamar Server, or unauthorized access to Avamar Server data by the malicious Avamar Client user. All supported versions prior to 7.3.0 of EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) are affected.

    Continue reading...
     

Share This Page

Loading...