Zmanda develops backup and recovery software, principally Amanda and ZRM for MySQL, that manages data protection across enterprise environments. The vendor's vulnerability profile centers on command-injection and input-validation weaknesses endemic to backup tools' need to parse user input and invoke system commands, alongside web-interface CSRF exposure in management consoles. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zmanda over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19469HIGH In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may d | Dec 1, 2019 | 8.8 | 26 | NO | NO |
CVE-2016-10730HIGH An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be | Oct 24, 2018 | 7.8 | 26 | NO | NO |
CVE-2016-10729HIGH An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional | Oct 24, 2018 | 7.8 | 26 | NO | NO |
CVE-2009-3102HIGH The doHotCopy subroutine in socket-server.pl in Zmanda Recovery Manager (ZRM) for MySQL 2.x before 2.1.1 allows remote attackers to execute arbitrary commands via vectors involving | Sep 8, 2009 | 10.0 | 25 | NO | NO |
CVE-2022-37704MEDIUM Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled ar | Apr 16, 2023 | 6.7 | 23 | NO | NO |
CVE-2023-30577HIGH AMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-3.5.4 mishandles argument checking for runtar.c, a different vulnerability than CVE-2022-37705. | Jul 26, 2023 | 7.8 | 22 | NO | NO |
CVE-2022-37705MEDIUM A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerable component is the runtar SUID program, which is a wrapper | Apr 16, 2023 | 6.7 | 22 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zmanda.
Media articles that mention a CVE ID that affects a product developed by Zmanda — matched by CVE ID, not by vendor name.