In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any directory which could allow the attacker to execute arbitrary code on the Avamar Server system.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.securityfocus.com/archive/1/540754/30/0/threaded | Third Party Advisory VDB Entry | 
| http://www.securityfocus.com/bid/99243 | Third Party Advisory VDB Entry | 
| http://www.securitytracker.com/id/1038718 | |
| http://www.securityfocus.com/archive/1/540754/30/0/threaded | Third Party Advisory VDB Entry | 
| http://www.securityfocus.com/bid/99243 | Third Party Advisory VDB Entry | 
| http://www.securitytracker.com/id/1038718 | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 03:26
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://www.securityfocus.com/archive/1/540754/30/0/threaded - Third Party Advisory, VDB Entry | |
| References | () http://www.securityfocus.com/bid/99243 - Third Party Advisory, VDB Entry | |
| References | () http://www.securitytracker.com/id/1038718 - | 
Information
                Published : 2017-06-21 20:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-4990
Mitre link : CVE-2017-4990
CVE.ORG link : CVE-2017-4990
JSON object : View
Products Affected
                emc
- avamar_server
CWE
                
                    
                        
                        CWE-434
                        
            Unrestricted Upload of File with Dangerous Type
