CVE-2015-4068: Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability
Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.
Other sources
Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arcserve Unified Data Protection (UDP)to a version that resolves this vulnerability.Fixed in 5.0 Update 4
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4068?
CVE-2015-4068 has a high severity rating due to its potential for sensitive information disclosure and denial of service.
How do I fix CVE-2015-4068?
To fix CVE-2015-4068, update Arcserve UDP to version 5.0 Update 4 or later.
What is the risk associated with CVE-2015-4068?
The risk consists of remote attackers exploiting the vulnerability to access sensitive information or disrupt service.
Which versions of Arcserve UDP are affected by CVE-2015-4068?
Arcserve UDP versions prior to 5.0 Update 4 are affected by CVE-2015-4068.
What specific components are vulnerable in CVE-2015-4068?
The vulnerable components in CVE-2015-4068 include the reportFileServlet and exportServlet servlets.