EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file. A malicious administrator with configuration privileges may access this sensitive system file and compromise the affected system.
2017-02-03T07:59:00.263
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 4.4 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | emc | recoverpoint | ≤ 4.4.1.0 | Yes |
Application | emc | recoverpoint_for_virtual_machines | ≤ 4.0 | Yes |