EMC Data Domain OS 5.5 before 5.5.4.0, 5.6 before 5.6.1.004, and 5.7 before 5.7.2.0 stores session identifiers of GUI users in a world-readable file, which allows local users to hijack arbitrary accounts via unspecified vectors.
2016-06-10T01:59:01.537
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 8.8 (HIGH)
AV:L/AC:L/Au:S/C:P/I:P/A:P
3.1
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | emc | data_domain_os | ≤ 5.5.3.3 | Yes |
| Operating System | emc | data_domain_os | ≤ 5.6.1.0 | Yes |
| Operating System | emc | data_domain_os | ≤ 5.7.1.0 | Yes |