SB2016102006 - SQL injection in Dell EMC Avamar



SB2016102006 - SQL injection in Dell EMC Avamar

Published: October 20, 2016 Updated: October 24, 2016

Security Bulletin ID SB2016102006
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) SQL injection (CVE-ID: CVE-2016-0909)

The vulnerability allows a local user to gain elevated privileges on the target system.
The weakness is due to inproper validation of user input. By execution of  PostgreSQL injection that allows them to gain elevated privileges.
Successful exploitation of the vulnerability results in privilege escalation on the vulnerable system.

Remediation

Install update from vendor's website.