| Vulnerability Name: | CVE-2014-4624 (CCN-97729) | ||||||||
| Assigned: | 2014-10-22 | ||||||||
| Published: | 2014-10-22 | ||||||||
| Updated: | 2018-10-09 | ||||||||
| Summary: | EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authentication for Java API calls, which allows remote attackers to discover grid MCUser and GSAN passwords via a crafted call. | ||||||||
| CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-264 | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: BUGTRAQ Type: UNKNOWN 20141022 ESA-2014-096: EMC Avamar Sensitive Information Disclosure Vulnerability Source: CCN Type: EMC Security Advisory ESA-2014-096 EMC Avamar Sensitive Information Disclosure Vulnerability Source: MITRE Type: CNA CVE-2014-4624 Source: MISC Type: UNKNOWN http://packetstormsecurity.com/files/128843/EMC-Avamar-Sensitive-Information-Disclosure.html Source: MISC Type: UNKNOWN http://packetstormsecurity.com/files/128850/VMware-Security-Advisory-2014-0011.html Source: SECUNIA Type: UNKNOWN 61663 Source: SECUNIA Type: UNKNOWN 61950 Source: BUGTRAQ Type: UNKNOWN 20141024 NEW VMSA-2014-0011 VMware vSphere Data Protection product update addresses a critical information disclosure vulnerability Source: BID Type: UNKNOWN 70709 Source: CCN Type: BID-70709 VMware vSphere Data Protection CVE-2014-4624 Information Disclosure Vulnerability Source: CCN Type: BID-70725 RETIRED: EMC Avamar CVE-2014-4624 Information Disclosure Vulnerability Source: SECTRACK Type: UNKNOWN 1031114 Source: SECTRACK Type: UNKNOWN 1031118 Source: CCN Type: VMware Security Advisory VMSA-2014-0011 VMware vSphere Data Protection product update addresses a critical information disclosure vulnerability Source: CONFIRM Type: UNKNOWN http://www.vmware.com/security/advisories/VMSA-2014-0011.html Source: XF Type: UNKNOWN vsphere-data-cve20144624-info-disc(97729) Source: XF Type: UNKNOWN vsphere-data-cve20144624-info-disc(97729) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||