Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-15850 – Insecure permissions in Nakivo Backup & Replication Director version 9.4.

Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interface and gain root privileges. This occurs because the database containing the users of the web application and the password-recovery secret value is readable.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15850

Reference (s):

  • https://helpcenter.nakivo.com/display/RN/v10.3+Release+Notes
  • https://labs.f-secure.com/advisories/nakivo-backup-and-replication-multiple-vulnerabilities
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-8508 - Cross-site scripting (XSS) vulnerability in s_network.asp in the Denon AV

2021-current

CVE-2020-0297 - In devicepolicy service, there is a possible permission bypass due to an

2021-current

CVE-2020-14315 - A memory corruption vulnerability is present in bspatch as shipped in Col