CVE-2017-15550

EUVD-2017-7002
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could access arbitrary files on the server file system in the context of the running vulnerable application via Path traversal.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
Affected Products (NVD)
VendorProductVersion
emcavamar_server
7.1-21:sp2
emcavamar_server
7.1-145:sp1
emcavamar_server
7.1-302
emcavamar_server
7.1-370
emcavamar_server
7.2-32:sp1
emcavamar_server
7.2-309
emcavamar_server
7.2-401
emcavamar_server
7.3-125:sp1
emcavamar_server
7.3-211
emcavamar_server
7.3-226
emcavamar_server
7.3-233
emcavamar_server
7.4-58:sp1
emcavamar_server
7.4-242
emcavamar_server
7.5-183
emcintegrated_data_protection_appliance
2.0
emcnetworker
9.0
emcnetworker
9.1
emcnetworker
9.2
𝑥
= Vulnerable software versions