PT-2015-3337 · Novastor · Novabackup Datacenter
Published
2015-05-14
·
Updated
2017-04-19
·
CVE-2016-4898
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NovaBACKUP DataCenter versions prior to 09.06.03.0353
Description
The issue concerns the datamover module in NovaBACKUP DataCenter for Linux, which is vulnerable to remote command execution. This is due to insufficient input validation, allowing a remote attacker to execute arbitrary commands.
Recommendations
For versions prior to 09.06.03.0353, update to version 09.06.03.0353 or later to resolve the issue. As a temporary workaround, consider restricting access to the datamover module to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Novabackup Datacenter