CVE-2018-18658: Infoleak
Published Oct 26, 2018
·Updated
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-20 Unauthenticated Sensitive Information Disclosure via /UDPUpdates/Config/FullUpdateSettings.xml issue.
Affected Software
9 affected components
Arcserve UDP=6.0
Arcserve UDP=6.0-1
Arcserve UDP=6.0-2
Arcserve UDP=6.0-3
Arcserve UDP=6.5
Arcserve UDP=6.5-1
Arcserve UDP=6.5-2
Arcserve UDP=6.5-3
Arcserve UDP=6.5-4
Remediation
Event History
Oct 26, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue in Arcserve Unified Data Protection?
The vulnerability ID is CVE-2018-18658.
2
What is the severity of CVE-2018-18658?
The severity of CVE-2018-18658 is high with a severity value of 7.5.
3
How can this vulnerability be exploited?
This vulnerability can be exploited through unauthenticated sensitive information disclosure via /UDPUpdates/Config/FullUpdateSettings.xml.
4
What is the affected software?
The affected software is Arcserve Unified Data Protection (UDP) through version 6.5 Update 4.
5
Is there a fix available for CVE-2018-18658?
Yes, Arcserve provides fixes for this vulnerability. Please refer to their support articles for more information.