Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. The vulnerability could be used to conduct phishing attacks that cause users to unknowingly visit malicious sites.
References
Link Resource
http://www.securityfocus.com/bid/105969 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1042153 Third Party Advisory VDB Entry
https://seclists.org/fulldisclosure/2018/Nov/49 Mailing List Third Party Advisory
https://www.vmware.com/security/advisories/VMSA-2018-0029.html Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: dell

Published: 2018-11-20T00:00:00

Updated: 2018-11-27T16:57:01

Reserved: 2018-05-14T00:00:00


Link: CVE-2018-11067

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-11-26T20:29:00.297

Modified: 2019-01-02T18:21:53.210


Link: CVE-2018-11067

JSON object: View

cve-icon Redhat Information

No data.

CWE