Lucene search

K
cveMitreCVE-2015-4068
HistoryMay 29, 2015 - 3:59 p.m.

CVE-2015-4068

2015-05-2915:59:23
CWE-22
mitre
web.nvd.nist.gov
848
In Wild
cve
2015
4068
directory traversal
vulnerability
arcserve
udp
remote attackers
sensitive information
denial of service

CVSS2

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:N/A:C

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

AI Score

6.5

Confidence

Low

EPSS

0.832

Percentile

98.5%

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.

Affected configurations

Nvd
Node
arcserveudpRange<5.0
OR
arcserveudpMatch5.0-
VendorProductVersionCPE
arcserveudp*cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*
arcserveudp5.0cpe:2.3:a:arcserve:udp:5.0:-:*:*:*:*:*:*

CVSS2

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:N/A:C

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

AI Score

6.5

Confidence

Low

EPSS

0.832

Percentile

98.5%