CVE-2015-4068

CRITICAL KEV

Arcserve UDP < 5.0 Update 4 - Path Traversal via reportFileServlet or exportServlet

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2015-4068 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 25, 2022.

Description

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-15-242/
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/74845
Third Party Advisory, VDB Entry x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-15-241/

Scores

CVSS v3 9.1
EPSS 0.8042
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2022-03-25
VulnCheck KEV 2022-01-12
InTheWild.io 2022-03-25
ENISA EUVD EUVD-2015-4094
CWE
CWE-22
Status published
Products (2)
arcserve/udp 5.0
arcserve/udp < 5.0
Published May 29, 2015
KEV Added Mar 25, 2022
Tracked Since Feb 18, 2026