PT-2018-2556 · Dell Emc · Dell Emc Avamar Client Manager+2

Jarrod Farncomb

·

Published

2018-11-20

·

Updated

2019-01-02

·

CVE-2018-11067

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dell EMC Avamar Server versions 7.2.0 through 7.5.1, 18.1 Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0 through 2.2
Description The issue is related to an open redirection vulnerability in the Dell EMC Avamar Client Manager component. A remote unauthenticated attacker could exploit this to redirect application users to arbitrary web URLs by tricking victims into clicking on maliciously crafted links. This could be used to conduct phishing attacks, causing users to unknowingly visit malicious sites.
Recommendations For Dell EMC Avamar Server versions 7.2.0 through 7.5.1 and 18.1, update to a version that includes a fix for the open redirection vulnerability. For Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0 through 2.2, update to a version that includes a fix for the open redirection vulnerability. As a temporary workaround, consider restricting access to the Avamar Client Manager component to minimize the risk of exploitation.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00975
CVE-2018-11067

Affected Products

Dell Emc Avamar Client Manager
Dell Emc Avamar Server
Dell Emc Integrated Data Protection Appliance