CVE-2015-4069: Infoleak
Published May 29, 2015
·Updated
The EdgeServiceImpl web service in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive credentials via a crafted SOAP request to the (1) getBackupPolicy or (2) getBackupPolicies method.
Affected Software
1 affected component
Arcserve Arcserve Unified Data Protection<=5.0
Event History
May 29, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4069?
CVE-2015-4069 has a medium severity rating due to the potential exposure of sensitive credentials.
2
How do I fix CVE-2015-4069?
To fix CVE-2015-4069, update Arcserve UDP to version 5.0 Update 4 or later.
3
What specific methods in CVE-2015-4069 are affected?
CVE-2015-4069 affects the getBackupPolicy and getBackupPolicies methods of the EdgeServiceImpl web service.
4
Can CVE-2015-4069 be exploited remotely?
Yes, CVE-2015-4069 can be exploited remotely by sending crafted SOAP requests.
5
What impact does CVE-2015-4069 have on system security?
CVE-2015-4069 allows remote attackers to obtain sensitive credentials, compromising system security.