PT-2015-3337 · Novastor · Novabackup Datacenter

Published

2015-05-14

·

Updated

2017-04-19

·

CVE-2016-4898

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NovaBACKUP DataCenter versions prior to 09.06.03.0353
Description The issue concerns the datamover module in NovaBACKUP DataCenter for Linux, which is vulnerable to remote command execution. This is due to insufficient input validation, allowing a remote attacker to execute arbitrary commands.
Recommendations For versions prior to 09.06.03.0353, update to version 09.06.03.0353 or later to resolve the issue. As a temporary workaround, consider restricting access to the datamover module to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02477
CVE-2016-4898

Affected Products

Novabackup Datacenter