Executive brief
Arcserve Unified Data Protection (UDP) contains a directory traversal vulnerability in the reportFileServlet and exportServlet servlets. Remote attackers can exploit this by sending crafted file paths to obtain sensitive information or cause a denial of service.
Affected products
- Arcserve Unified Data Protection (UDP) before 5.0 Update 4
Timeline
- 2015-05-29: disclosed: NVD Published Date
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2015-05-29: patched: Fixed in Arcserve UDP 5.0 Update 4