Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interface and gain root privileges. This occurs because the database containing the users of the web application and the password-recovery secret value is readable.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-09-24T20:23:24

Updated: 2024-08-04T13:30:22.648Z

Reserved: 2020-07-20T00:00:00

Link: CVE-2020-15850

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-09-24T21:15:15.513

Modified: 2022-04-05T15:39:56.230

Link: CVE-2020-15850

cve-icon Redhat

No data.