VendorsEMCvplex_geosynchrony4.0
Vulnerabilities

EMC VPLEX GeoSynchrony 4.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2014-0632
Directory traversal vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote authenticated users to execute arbitrary code via unspecified vectors.
Published 2014-03-28 · Modified
9.0EPSS 0.045
CVE-2014-0633
The GUI in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not properly validate session-timeout values, which might make it easier for remote attackers to execute arbitrary code by leveraging an unattended workstation.
Published 2014-03-28 · Modified
7.7EPSS 0.008
CVE-2014-0635
Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vectors.
Published 2014-03-28 · Modified
7.5EPSS 0.012
CVE-2014-0634
EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
Published 2014-03-28 · Modified
6.0EPSS 0.010