CVE-2015-4068: Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability

Critical severity, CVSS 9.1. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 63.6% chance of exploitation in the next 30 days.

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.

Affected products

  • Arcserve UDP: before 5.0 (fixed in 5.0); version 5.0 only

Published 2015-05-29. Last modified 2026-06-17.