7.2

CVE-2012-2291

EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.

Data is provided by the National Vulnerability Database (NVD)
EmcAvamar Version4.0
   ApplemacOS X
   HpHp-ux
EmcAvamar Version4.1
   ApplemacOS X
   HpHp-ux
EmcAvamar Version5.0
   ApplemacOS X
   HpHp-ux
EmcAvamar Version5.0 Updatesp1
   ApplemacOS X
   HpHp-ux
EmcAvamar Version5.0 Updatesp2
   ApplemacOS X
   HpHp-ux
EmcAvamar Version5.0.0-407
   ApplemacOS X
   HpHp-ux
EmcAvamar Version5.0.4-26
   ApplemacOS X
   HpHp-ux
EmcAvamar Version6.0
   ApplemacOS X
   HpHp-ux
EmcAvamar Plugin Version4.0 Update-
EmcAvamar Plugin Version5.0 Update-
EmcAvamar Plugin Version6.0 Update-
EmcAvamar Plugin Version6.1 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.071
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C