CVE-2015-4068
critical · 9.1Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-03-25Remediation due 2022-04-15
Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.
9.1
CVSS
63.6%
EPSS (exploit prob.)
99th
EPSS percentile
2015-05-29
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| arcserve | udp | < 5.0 |
| arcserve | udp | 5.0 |
Check a specific version with /api/v1/cve/match.
References
- http://documentation.arcserve.com/Arcserve-UDP/Available/V5/ENU/Bookshelf_Files/HTML/Update%204/UDP_Update4_ReleaseNotes.html
- http://www.securityfocus.com/bid/74845
- http://www.zerodayinitiative.com/advisories/ZDI-15-241/
- http://www.zerodayinitiative.com/advisories/ZDI-15-242/
- http://documentation.arcserve.com/Arcserve-UDP/Available/V5/ENU/Bookshelf_Files/HTML/Update%204/UDP_Update4_ReleaseNotes.html
- http://www.securityfocus.com/bid/74845
- http://www.zerodayinitiative.com/advisories/ZDI-15-241/
- http://www.zerodayinitiative.com/advisories/ZDI-15-242/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-4068
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-4068