CVE-2015-4068
arcserve udp
Published 29 May 2015 · updated 17 Jun 2026 · Analyzed
9.1 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 25 Mar 2022, with a remediation deadline of 15 Apr 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.
References
- documentation.arcserve.com/Arcserve-UDP/Available/V5/ENU/Bookshelf_Files/HTML/Update%204/UDP_Update4_ReleaseNotes.html · Release Notes, Vendor Advisory
- www.securityfocus.com/bid/74845 · Broken Link, Third Party Advisory, VDB Entry
- www.zerodayinitiative.com/advisories/ZDI-15-241/ · Third Party Advisory, VDB Entry
- www.zerodayinitiative.com/advisories/ZDI-15-242/ · Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-4068 · US Government Resource