Junglewise Threat Intelligence

CVE-2015-4068: Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability

CVE-2015-4068 · Severity: critical · CVSS 9.1 · Exploited in the wild · Published 2022-03-25

Executive brief

Arcserve Unified Data Protection (UDP) contains a directory traversal vulnerability in the reportFileServlet and exportServlet servlets. Remote attackers can exploit this by sending crafted file paths to obtain sensitive information or cause a denial of service.

Affected products

  • Arcserve Unified Data Protection (UDP) before 5.0 Update 4

Timeline

  • 2015-05-29: disclosed: NVD Published Date
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2015-05-29: patched: Fixed in Arcserve UDP 5.0 Update 4