Vulnerability index

Browse CVEs

300 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Avamar Server CRITICAL 9.1
CVE-2016-0903

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remot…

Fix: after 7.3.0
Fix from $2,300 2016-09-21
Vipr Srm MEDIUM 6.1
CVE-2016-6643

Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified …

Fix: after 3.7.1
Fix from $1,600 2016-09-18
Vipr Srm MEDIUM 6.1
CVE-2016-6642

Cross-site request forgery (CSRF) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to hijack the authentication of administrators f…

Fix: after 3.7.1
Fix from $1,600 2016-09-18
Vipr Srm HIGH 7.6
CVE-2016-6641

Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via un…

Fix: after 3.7.1
Fix from $1,950 2016-09-18
Vipr Srm CRITICAL 9.8
CVE-2016-0922

EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain acce…

Fix: after 3.7.1
Fix from $2,300 2016-09-18
Documentum D2 MEDIUM 5.3
CVE-2016-6644

EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of …

Fix: after 4.6
Fix from $1,600 2016-09-17
Authentication Manager Prime HIGH 8.1
CVE-2016-0915

The Self-Service Portal in EMC RSA Authentication Manager (AM) Prime Self-Service 3.0 and 3.1 before 3.1 1915.42871 allows remote authenticated users…

Mitigation only
Fix from $1,950 2016-08-22
Avamar HIGH 8.8
CVE-2016-0906

The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remo…

Fix: after 7.2.1
Fix from $1,950 2016-07-06
Rsa Archer Egrc MEDIUM 6.3
CVE-2016-0899

EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential informatio…

Mitigation only
Fix from $1,600 2016-07-04
Documentum Administrator MEDIUM 6.3
CVE-2016-0914

EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.…

Mitigation only
Fix from $1,600 2016-06-23
Networker CRITICAL 9.8
CVE-2016-0916EPSS 8%

EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary…

Fix: 8.2.2.6 / 9.0.0.6+
Fix from $2,300 2016-06-10
Data Domain Os HIGH 8.8
CVE-2016-0910

EMC Data Domain OS 5.5 before 5.5.4.0, 5.6 before 5.6.1.004, and 5.7 before 5.7.2.0 stores session identifiers of GUI users in a world-readable file,…

Fix: after 5.7.1.0
Fix from $1,950 2016-06-10
Isilon Onefs MEDIUM 6.7
CVE-2016-0908

EMC Isilon OneFS 7.1.x before 7.1.1.9 and 7.2.x before 7.2.1.2 allows local users to obtain root shell access by leveraging administrative privileges.

Mitigation only
Fix from $1,600 2016-06-04
Isilon Onefs MEDIUM 5.9
CVE-2016-0907

EMC Isilon OneFS 7.1.x and 7.2.x before 7.2.1.3 and 8.0.x before 8.0.0.1, and IsilonSD Edge OneFS 8.0.x before 8.0.0.1, does not require SMB signing …

Mitigation only
Fix from $1,600 2016-05-30
Rsa Authentication Manager MEDIUM 5.3
CVE-2016-0902

CRLF injection vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary HTTP headers and conduc…

Fix: after 8.1
Fix from $1,600 2016-05-07
Rsa Authentication Manager MEDIUM 6.1
CVE-2016-0901

Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script …

Fix: after 8.1
Fix from $1,600 2016-05-07
Rsa Authentication Manager MEDIUM 6.1
CVE-2016-0900

Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script …

Fix: after 8.1
Fix from $1,600 2016-05-07
Rsa Data Loss Prevention MEDIUM 6.3
CVE-2016-0894

EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote authenticated users to bypass intended object access restrictions via a modified paramet…

No fix yet
Fix from $1,600 2016-05-03
Rsa Data Loss Prevention MEDIUM 6.1
CVE-2016-0892

Cross-site scripting (XSS) vulnerability in EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote attackers to inject arbitrary web script or …

No fix yet
Fix from $1,600 2016-05-03
Vipr Srm HIGH 8.8
CVE-2016-0891

Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remote attackers to hijack the au…

Fix: after 3.6.4
Fix from $1,950 2016-04-20
Documentum D2 HIGH 8.8
CVE-2016-0888

EMC Documentum D2 before 4.6 lacks intended ACLs for configuration objects, which allows remote authenticated users to modify objects via unspecified…

Fix: after 4.5
Fix from $1,950 2016-04-07
Documentum Xcp MEDIUM 5.4
CVE-2016-0882

EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containin…

Mitigation only
Fix from $1,600 2016-02-12
Documentum Xcp MEDIUM 6.5
CVE-2016-0881

EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection…

Mitigation only
Fix from $1,600 2016-02-12
Vplex Geosynchrony HIGH 8.4
CVE-2015-6850

EMC VPLEX GeoSynchrony 5.4 SP1 before P3 and 5.5 before Patch 1 has a default password for the root account, which allows local users to gain privile…

No fix yet
Fix from $1,950 2015-12-28
Isilon Onefs HIGH 8.0
CVE-2015-4545

EMC Isilon OneFS 7.1 before 7.1.1.8, 7.2.0 before 7.2.0.4, and 7.2.1 before 7.2.1.1 allows remote authenticated administrators to bypass a SmartLock …

Fix: after 7.1.1.7
Fix from $1,950 2015-12-21
Networker HIGH 7.8
CVE-2015-6849

EMC NetWorker before 8.0.4.5, 8.1.x before 8.1.3.6, 8.2.x before 8.2.2.2, and 9.0 before build 407 allows remote attackers to cause a denial of servi…

Mitigation only
Fix from $1,950 2015-12-05
Isilon Onefs HIGH 8.5
CVE-2015-6848

EMC Isilon OneFS 7.1.x before 7.1.1.5, 7.2.0.x before 7.2.0.3, and 7.2.1.x before 7.2.1.1, when the RFC 2307 feature is configured but SFU is not uni…

Fix: after 7.1.1.0
Fix from $1,950 2015-11-27
Sourceone Email Supervisor MEDIUM 6.8
CVE-2015-6846

EMC SourceOne Email Supervisor before 7.2 uses hardcoded encryption keys, which makes it easier for attackers to obtain access by examining how a pro…

Fix: after 7.1
Fix from $1,600 2015-10-18
Sourceone Email Supervisor HIGH 7.5
CVE-2015-6845

EMC SourceOne Email Supervisor before 7.2 does not properly employ random values for session IDs, which makes it easier for remote attackers to obtai…

Fix: after 7.1
Fix from $1,950 2015-10-18
Sourceone Email Supervisor MEDIUM 5.0
CVE-2015-6843

Reviewer in EMC SourceOne Email Supervisor before 7.2 does not properly limit attempts to authenticate, which makes it easier for remote attackers to…

Fix: after 7.1
Fix from $1,600 2015-10-18