Critical severity9.1CISA KEVNVD Advisory· Published May 29, 2015· Updated Apr 21, 2026
CVE-2015-4068
CVE-2015-4068
Description
Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- documentation.arcserve.com/Arcserve-UDP/Available/V5/ENU/Bookshelf_Files/HTML/Update%204/UDP_Update4_ReleaseNotes.htmlnvdRelease NotesVendor Advisory
- www.securityfocus.com/bid/74845nvdBroken LinkThird Party AdvisoryVDB Entry
- www.zerodayinitiative.com/advisories/ZDI-15-241/nvdThird Party AdvisoryVDB Entry
- www.zerodayinitiative.com/advisories/ZDI-15-242/nvdThird Party AdvisoryVDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.