First published: Fri May 29 2015(Updated: )
Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arcserve Unified Data Protection | <=5.0 | |
Arcserve Unified Data Protection | ||
Arcserve Unified Data Protection | <5.0 | |
Arcserve Unified Data Protection | =5.0 | |
<5.0 | ||
=5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4068 has a high severity rating due to its potential for sensitive information disclosure and denial of service.
To fix CVE-2015-4068, update Arcserve UDP to version 5.0 Update 4 or later.
The risk consists of remote attackers exploiting the vulnerability to access sensitive information or disrupt service.
Arcserve UDP versions prior to 5.0 Update 4 are affected by CVE-2015-4068.
The vulnerable components in CVE-2015-4068 include the reportFileServlet and exportServlet servlets.