CVE-2015-4068criticalunder attackCWE-22

CVE-2015-4068

Published · Updated

70Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 9.1epss 64%
from disclosure to weapon
Published on NVDMay 29
CISA KEV+2492d
exploitation probability
64%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-04-15

Apply updates per vendor instructions.

In short

A flaw in Arcserve UDP allows attackers to access files outside their intended directory by sending specially crafted requests to specific servlets, potentially exposing sensitive data or crashing the service.

Technical detail

Directory traversal vulnerability in reportFileServlet and exportServlet allows unauthenticated remote attackers to escape file path restrictions via path manipulation (CWE-22), enabling unauthorized file access and DoS. Affects Arcserve UDP versions before 5.0 Update 4.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Affected products
n/a · n/a