CVE-2017-15550: Emc Avamar Server
High severity, CVSS 8.8. EPSS: 8.2% chance of exploitation in the next 30 days.
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could access arbitrary files on the server file system in the context of the running vulnerable application via Path traversal.
Affected products
- Emc Avamar Server: version 7.1-21 only; version 7.1-145 only; version 7.1-302 only; version 7.1-370 only; version 7.2-32 only; version 7.2-309 only; …
- Emc Integrated Data Protection Appliance: version 2.0 only
- Emc Networker: version 9.0 only; version 9.1 only; version 9.2 only
Published 2018-01-05. Last modified 2026-06-17.