Vulnerability Description
EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authentication for Java API calls, which allows remote attackers to discover grid MCUser and GSAN passwords via a crafted call.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avamar Virtual Edition | 6.0 | All versions |
| Avamar Virtual Edition | 6.0.402 | All versions |
| Avamar Virtual Edition | 7.0 | All versions |
| Avamar Virtual Edition | 7.0.2-43 | All versions |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0147.html
- http://packetstormsecurity.com/files/128843/EMC-Avamar-Sensitive-Information-Dis
- http://packetstormsecurity.com/files/128850/VMware-Security-Advisory-2014-0011.h
- http://secunia.com/advisories/61663
- http://secunia.com/advisories/61950
- http://www.securityfocus.com/archive/1/533813/100/0/threaded
- http://www.securityfocus.com/bid/70709
- http://www.securitytracker.com/id/1031114
- http://www.securitytracker.com/id/1031118
- http://www.vmware.com/security/advisories/VMSA-2014-0011.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/97729
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0147.html
- http://packetstormsecurity.com/files/128843/EMC-Avamar-Sensitive-Information-Dis
- http://packetstormsecurity.com/files/128850/VMware-Security-Advisory-2014-0011.h
- http://secunia.com/advisories/61663
FAQ
What is CVE-2014-4624?
CVE-2014-4624 is a vulnerability with a CVSS score of 5.0 (MEDIUM). EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authentication for Java API calls, which allows remote attackers to discover grid MCUser and ...
How severe is CVE-2014-4624?
CVE-2014-4624 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-4624?
Check the references section above for vendor advisories and patch information. Affected products include: Avamar Virtual Edition 6.0, Avamar Virtual Edition 6.0.402, Avamar Virtual Edition 7.0, Avamar Virtual Edition 7.0.2-43.