Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-15850 – Insecure permissions in Nakivo Backup & Replication Director version 9.4.

Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interface and gain root privileges. This occurs because the database containing the users of the web application and the password-recovery secret value is readable.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15850

Reference (s):

  • https://helpcenter.nakivo.com/display/RN/v10.3+Release+Notes
  • https://labs.f-secure.com/advisories/nakivo-backup-and-replication-multiple-vulnerabilities
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-6594 - Unspecified vulnerability in the Oracle iLearning component in Oracle iLe

2021-current

CVE-2019-8457 - SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-b

2021-current

CVE-2020-12257 - rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because