Vulnerabilities > EMC

DATE CVE VULNERABILITY TITLE RISK
2017-02-03 CVE-2016-6649 Command Injection vulnerability in EMC Recoverpoint and Recoverpoint for Virtual Machines
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass the user interface and escalate his privileges to root.
local
low complexity
emc CWE-77
6.7
2017-02-03 CVE-2016-6648 Permission Issues vulnerability in EMC Recoverpoint and Recoverpoint for Virtual Machines
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file.
local
low complexity
emc CWE-275
4.4
2017-02-03 CVE-2016-0890 Information Exposure vulnerability in EMC Powerpath Virtual Appliance 2.0
EMC PowerPath Virtual (Management) Appliance 2.0, EMC PowerPath Virtual (Management) Appliance 2.0 SP1 is affected by a sensitive information disclosure vulnerability that may potentially be exploited by malicious users to compromise the affected system.
network
high complexity
emc CWE-200
6.4
2017-01-25 CVE-2016-8215 Cross-site Scripting vulnerability in EMC RSA Security Analytics
EMC RSA Security Analytics 10.5.3 and 10.6.2 contains fixes for a Reflected Cross-Site Scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system.
network
low complexity
emc CWE-79
6.1
2017-01-25 CVE-2016-8214 Permission Issues vulnerability in EMC Avamar Data Store and Avamar Virtual Edition
EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3.0 and 7.3.1 contain a vulnerability that may allow malicious administrators to compromise Avamar servers.
local
low complexity
emc CWE-275
6.7
2017-01-23 CVE-2016-9870 LDAP Injection vulnerability in EMC Isilon Onefs
EMC Isilon OneFS 8.0.0.0, EMC Isilon OneFS 7.2.1.0 - 7.2.1.2, EMC Isilon OneFS 7.2.0.x, EMC Isilon OneFS 7.1.1.0 - 7.1.1.10, and EMC Isilon OneFS 7.1.0.x is affected by an LDAP injection vulnerability that could potentially be exploited by a malicious user to compromise the system.
local
low complexity
emc CWE-90
6.7
2017-01-23 CVE-2016-8213 Cross-site Scripting vulnerability in EMC products
EMC Documentum WebTop Version 6.8, prior to P18 and Version 6.8.1, prior to P06; and EMC Documentum TaskSpace version 6.7SP3, prior to P02; and EMC Documentum Capital Projects Version 1.9, prior to P30 and Version 1.10, prior to P17; and EMC Documentum Administrator Version 7.0, Version 7.1, and Version 7.2 prior to P18 contain a Stored Cross-Site Scripting Vulnerability that could potentially be exploited by malicious users to compromise the affected system.
network
low complexity
emc CWE-79
6.1
2017-01-06 CVE-2016-9869 Permission Issues vulnerability in EMC Scaleio 2.0.1.0
An issue was discovered in EMC ScaleIO versions before 2.0.1.1.
local
low complexity
emc CWE-275
5.5
2017-01-06 CVE-2016-9868 7PK - Security Features vulnerability in EMC Scaleio 2.0.1.0
An issue was discovered in EMC ScaleIO versions before 2.0.1.1.
local
low complexity
emc CWE-254
5.5
2017-01-06 CVE-2016-9867 Permissions, Privileges, and Access Controls vulnerability in EMC Scaleio 2.0.1.0
An issue was discovered in EMC ScaleIO versions before 2.0.1.1.
local
low complexity
emc CWE-264
8.8