SQL injection in Dell EMC Avamar



| Updated: 2016-10-24
Risk High
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2016-0909
CWE-ID CWE-89
Exploitation vector Local
Public exploit N/A
Vulnerable software

Client/Desktop applications / Software for system administration


Other

Vendor Dell

Security Bulletin

This security bulletin contains one high risk vulnerability.

1) SQL injection

EUVDB-ID: #VU1036

Risk: High

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]

CVE-ID: CVE-2016-0909

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Exploit availability: No

Description

The vulnerability allows a local user to gain elevated privileges on the target system.
The weakness is due to inproper validation of user input. By execution of  PostgreSQL injection that allows them to gain elevated privileges.
Successful exploitation of the vulnerability results in privilege escalation on the vulnerable system.

Mitigation

Update to version 7.4 or later.

Vulnerable software versions

:

CPE2.3 External links

https://seclists.org/bugtraq/2016/Oct/att-45/ESA-2016-111.txt


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###