Back

CVE-2015-4068

CRITICAL CISA KEV

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.

Published: May 29, 2015 Modified: Apr 21, 2026
CWE-22 CWE-22

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: NONE Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected Products (2)

Vendor Product Version
arcserve udp * < 5.0
arcserve udp 5.0

GitHub Security Advisory GHSA-rcg3-4524-mq7j

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to...

Risk Scores

CVSS Score 9.1 / 10
EPSS Score 80.42%

Top 1% most likely to be exploited

Threat Score 90.5 / 100

CISA Known Exploited

Date Added: 2022-03-25
Due Date: 2022-04-15
Required Action:

Apply updates per vendor instructions.

Data Sources

NVD CISA KEV EPSS GitHub