SB2016102006 - SQL injection in Dell EMC Avamar
Published: October 20, 2016 Updated: October 24, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) SQL injection (CVE-ID: CVE-2016-0909)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
The vulnerability allows a local user to gain elevated privileges on the target system.
The weakness is due to inproper validation of user input. By execution of PostgreSQL injection that allows them to gain elevated privileges.
Successful exploitation of the vulnerability results in privilege escalation on the vulnerable system.
Remediation
Install update from vendor's website.