Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
The server contains a protection mechanism that assumes that any URI that is accessed using HTTP GET will not cause a state change to the associated resource. This might allow attackers to bypass intended access restrictions and conduct resource modification and deletion attacks, since some applications allow GET to modify state.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Avamar | Dell | 19.4 (including) | 19.4 (including) |
| Avamar | Dell | 19.7 (including) | 19.7 (including) |
| Avamar | Dell | 19.8 (including) | 19.8 (including) |
| Avamar | Dell | 19.9 (including) | 19.9 (including) |
| Avamar | Dell | 19.10 (including) | 19.10 (including) |
| Avamar | Dell | 19.10-sp1 (including) | 19.10-sp1 (including) |
| Avamar | Dell | 19.12 (including) | 19.12 (including) |