-
Unitrends response to limited support ticket access on support.unitrends.com
SUMMARY Unitrends addressed an issue of limited access to support tickets (new portal customers could see and access other new portal customers' Support cases that did not belong to them, until an account was associated with the user account) DESCRIPTION New users recently reported they have unauthorized visibility and…
-
CVE-2017-7282: Unitrends LFI in restore.php filename
CVE ID CVE-2017-7282 DESCRIPTION An issue in api/includes/restore.php allowed a Local File Inclusion when specifying a filename manually. RESOLUTION Unitrends Risk Assessment: None. Resolved with latest security update as of 04/14/2017. LINK TO ADVISORIES *…
-
CVE-2017-7895: kernel: NFSv3 server payload bounds checking of WRITE requests
CVE ID CVE-2017-7895 DESCRIPTION The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lacked certain checks for the end of a buffer. A remote attacker could trigger a pointer-arithmetic error or possibly cause other unspecified impacts using crafted requests related to fs/nfsd/nfs3xdr.c and…
-
Video: 10.2 UI : Easy to manage thousands of Backups
SUMMARY A review of new features added in Release 10.2 ISSUE With the updated 10.2 UI from Unitrends, it is Easy to Manage thousands of backup jobs. Fast, Powerful Filters Customize the view to manage Your way. See what you want to see. Watch this teaser video to see a quick review of the new features added with Release…
-
CVE-2016-5387: Apache HTTPD: Proxy header sets environment
CVE ID CVE-2016-5387 DESCRIPTION It was discovered that httpd used the value of the Proxy header from HTTP requests to initialize the HTTP_PROXY environment variable for CGI scripts, which in turn was incorrectly used by certain HTTP client implementations to configure the proxy for outgoing HTTP requests. A remote…
-
CVE-2014-2653 openssh: failure to check DNS SSHFP records in certain scenarios
CVE ID CVE-2014-2653 DESCRIPTION It was discovered that OpenSSH clients did not correctly verify DNS SSHFP records. A malicious server could use this flaw to force a connecting client to skip the DNS SSHFP record check and require the user to perform manual host verification of the DNS SSHFP record. CVSS2 Base Score 4.3…
-
Release Notes for Recovery Series and Unitrends Backup 10.3.5
DESCRIPTION This document describes fixes introduced in the 10.3.5 release. For upgrade instructions and considerations, reference the Upgrade Guide for Recovery Series, Recovery MAX, and Unitrends Backup. UI Enhancements The Login page and Global menu have been updated with a new, cleaner look. Fixes The table below lists…
-
Unitrends Compliance Manager Support Process
SUMMARY Unitrends Compliance Manager is a Unitrends-branded offering of RapidFire Tools' Audit Guru. The Unitrends Compliance Manager license provides advanced compliance capabilities for both HIPAA and GDPR to organizations to use within their own IT infrastructure. DESCRIPTION Support Process Unitrends Compliance Manager…
-
Release Notes for Recovery Series and Unitrends Backup 10.3.9
DESCRIPTION This document describes enhancements and fixes introduced in the 10.3.9 release. For upgrade instructions and considerations, reference the Upgrade Guide for Recovery Series, Recovery MAX, and Unitrends Backup. Security enhancements This release adds the following enhancements: * Events showing a password…
-
Image-Level & VM Instant Recovery appears to hang
SUMMARY Image-level and host-level (VM) Instant Recovery (IR) instances appear to hang after functioning without issue. ISSUE During instant recovery, when the guest VM writes data to its virtual disks, disk writes may be stored on the appliance until the VM disks are fully migrated. The underlying fuse processes…