The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote authenticated users to execute arbitrary code via crafted input to the (1) GeneralCmdRequest, (2) PersistantDataRequest, or (3) GetCommandExecRequest class.
oryginał ENCVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDell Emc Unisphere
APPDell8.08.18.1.28.2Emc Solutions Enabler
APPEmc8.08.0.38.18.1.28.2Emc Unisphere
APPEmc8.0.3
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCE
CWE
Powiązane podatności
CVE-2018-1183CRITICAL9.8PL ✓ten sam produkt
XXE Injection w komponentach ECOM systemów Dell EMC (RCE/ujawnienie danych)
CVE-2017-14375CRITICAL9.8PL ✓ten sam produkt
Pominięcie uwierzytelnienia w EMC Unisphere, Solutions Enabler, VASA i VMAX eManagement
CVE-2016-6646CRITICAL9.8PL ✓ten sam produkt
RCE w EMC Unisphere i Solutions Enabler Virtual Appliance przez vApp Manager
CVE-2016-0889CRITICAL9.8PL ✓ten sam produkt
Zapis do dowolnych plików w EMC Unisphere for VMAX Virtual Appliance
CVE-2015-0545HIGH10.0ten sam produkt
EMC Unisphere for VMAX 8.x before 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allow...