CVE-2015-4527: Emc Avamar Server

High severity, CVSS 7.8. EPSS: 2.7% chance of exploitation in the next 30 days.

Directory traversal vulnerability in EMC Avamar Server 7.x before 7.1.2 and Avamar Virtual Addition (AVE) 7.x before 7.1.2 allows remote attackers to read arbitrary files by using the Avamar Desktop/Laptop client interface to send crafted parameters.

Affected products

  • Emc Avamar Server: version 7.1 only
  • Emc Avamar Server Virtual Edition: version 7.1 only

Published 2015-07-23. Last modified 2026-06-17.