CVE-2015-4069: Arcserve Unified Data Protection

High severity, CVSS 7.8. EPSS: 4.5% chance of exploitation in the next 30 days.

The EdgeServiceImpl web service in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive credentials via a crafted SOAP request to the (1) getBackupPolicy or (2) getBackupPolicies method.

Affected products

  • Arcserve Arcserve Unified Data Protection: up to and including 5.0

Published 2015-05-29. Last modified 2026-06-17.