PT-2015-3336 · Novastor · Novabackup Datacenter

Publicado

2015-05-14

·

Atualizado

2017-04-19

·

CVE-2016-4899

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NovaBACKUP DataCenter versions prior to 09.06.03.0353
Description The issue concerns the datamover module in NovaBACKUP DataCenter for Linux, which is vulnerable to remote command execution. This is due to insufficient input validation, allowing a remote attacker to execute arbitrary commands.
Recommendations For versions prior to 09.06.03.0353, update to version 09.06.03.0353 or later to resolve the issue. As a temporary workaround, consider restricting access to the datamover module to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02476
CVE-2016-4899

Produtos afetados

Novabackup Datacenter