Vulnerabilities > EMC > Avamar Server > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-09-21 CVE-2016-0921 Permissions, Privileges, and Access Controls vulnerability in EMC Avamar Server 7.2.0401/7.2.131/7.2.132
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use weak permissions for unspecified directories, which allows local users to obtain root access by replacing a script with a Trojan horse program.
local
emc CWE-264
6.9
2016-09-21 CVE-2016-0904 Information Exposure vulnerability in EMC Avamar Server 7.2.0401/7.2.131/7.2.132
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive client-server traffic information by leveraging knowledge of this key from another installation.
network
low complexity
emc CWE-200
5.0
2016-09-21 CVE-2016-0903 Information Exposure vulnerability in EMC Avamar Server 7.2.0401/7.2.131/7.2.132
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote attackers to spoof clients and read backup data via a modified client agent.
network
low complexity
emc CWE-200
6.4
2013-07-19 CVE-2013-3275 Improper Input Validation vulnerability in EMC Avamar Server and Avamar Server Virtual Edition
EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly restrict use of FRAME elements, which makes it easier for remote attackers to obtain sensitive information via a crafted web site, related to "cross frame scripting vulnerabilities."
network
emc CWE-20
4.3