Vulnerabilities > EMC > High

DATE CVE VULNERABILITY TITLE RISK
2017-03-29 CVE-2017-4980 Path Traversal vulnerability in EMC Isilon Onefs
EMC Isilon OneFS is affected by a path traversal vulnerability that may potentially be exploited by attackers to compromise the affected system.
network
low complexity
emc CWE-22
7.5
2017-03-29 CVE-2017-4977 Information Exposure vulnerability in EMC RSA Archer Security Operations Management 1.3.1.51
EMC RSA Archer Security Operations Management with RSA Unified Collector Framework versions prior to 1.3.1.52 contain a sensitive information disclosure vulnerability that could potentially be exploited by malicious users to compromise an affected system.
local
high complexity
emc CWE-200
7.0
2017-03-21 CVE-2016-6650 Information Exposure vulnerability in EMC Recoverpoint and Recoverpoint for Virtual Machines
EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected system.
network
high complexity
emc CWE-200
7.5
2017-02-03 CVE-2016-9871 Permissions, Privileges, and Access Controls vulnerability in EMC Isilon Onefs
EMC Isilon OneFS 7.2.1.0 - 7.2.1.3, EMC Isilon OneFS 7.2.0.x, EMC Isilon OneFS 7.1.1.0 - 7.1.1.10, EMC Isilon OneFS 7.1.0.x is affected by a privilege escalation vulnerability that could potentially be exploited by attackers to compromise the affected system.
network
low complexity
emc CWE-264
7.2
2017-01-06 CVE-2016-9867 Permissions, Privileges, and Access Controls vulnerability in EMC Scaleio 2.0.1.0
An issue was discovered in EMC ScaleIO versions before 2.0.1.1.
local
low complexity
emc CWE-264
8.8
2016-11-15 CVE-2016-0909 Improper Input Validation vulnerability in EMC Avamar Data Store and Avamar Server Virtual Edition
EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3 and older contain a vulnerability that may expose the Avamar servers to potentially be compromised by malicious users.
local
low complexity
emc CWE-20
8.4
2016-10-05 CVE-2016-6645 Improper Input Validation vulnerability in multiple products
The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote authenticated users to execute arbitrary code via crafted input to the (1) GeneralCmdRequest, (2) PersistantDataRequest, or (3) GetCommandExecRequest class.
network
low complexity
emc dell CWE-20
8.8
2016-09-21 CVE-2016-0920 Command Injection vulnerability in EMC Avamar Server
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root access via a crafted parameter to a command that is available in the sudo configuration.
local
low complexity
emc CWE-77
7.8
2016-09-21 CVE-2016-0904 Information Exposure vulnerability in EMC Avamar Server
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive client-server traffic information by leveraging knowledge of this key from another installation.
network
low complexity
emc CWE-200
8.6
2016-09-18 CVE-2016-6641 Cross-site Scripting vulnerability in EMC Vipr SRM 3.6.0/3.6.4/3.7.1
Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
emc CWE-79
7.6