CVE-2018-11067Open Redirect in EMC Avamar

CWE-601Open Redirect3 documents3 sources
Severity
6.1MEDIUMNVD
EPSS
0.5%
top 33.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 26
Latest updateMay 14

Description

Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. The vulnerability could be used to conduct phish

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

CVEListV5dell_emc/avamar9 versions+8
NVDdell/emc_avamar9 versions+8
NVDvmware/vsphere_data_protection19 versions+18

Patches

🔴Vulnerability Details

2
GHSA
GHSA-56qv-9p9c-2q4v: Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 72022-05-14
CVEList
Dell EMC Avamar and Integrated Data Protection Appliance Open Redirection Vulnerability2018-11-26
CVE-2018-11067 — Open Redirect in Dell EMC Avamar | cvebase