PT-2016-4464 · Emc · Emc Data Domain Os
Published
2016-06-10
·
Updated
2017-01-11
·
CVE-2016-0910
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EMC Data Domain OS versions 5.5 through 5.5.4.0
EMC Data Domain OS versions 5.6 through 5.6.1.004
EMC Data Domain OS versions 5.7 through 5.7.2.0
Description
The issue allows local users to hijack arbitrary accounts due to the storage of session identifiers of GUI users in a world-readable file.
Recommendations
For versions 5.5 through 5.5.4.0, update to version 5.5.4.0 or later.
For versions 5.6 through 5.6.1.004, update to version 5.6.1.004 or later.
For versions 5.7 through 5.7.2.0, update to version 5.7.2.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emc Data Domain Os