Loading
In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any directory which could allow the attacker to execute arbitrary code on the Avamar Server system.
Use CWE-434, Emc vendor hub and Avamar Server product page to widen CVE-2017-4990 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-15548, CVE-2017-4989 and CVE-2016-0903 for nearby disclosures in the same product family.