Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Very High
CVE-2023-26258
Disclosure Date: July 03, 2023 (last updated October 08, 2023)
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.
2
Attacker Value
Unknown
CVE-2024-0801
Disclosure Date: March 13, 2024 (last updated April 01, 2024)
A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.
0
Attacker Value
Unknown
CVE-2024-0800
Disclosure Date: March 13, 2024 (last updated April 01, 2024)
A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.servlet.ImportNodeServlet.
0
Attacker Value
Unknown
CVE-2024-0799
Disclosure Date: March 13, 2024 (last updated April 01, 2024)
An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.
0
Attacker Value
Unknown
CVE-2023-42000
Disclosure Date: November 27, 2023 (last updated December 05, 2023)
Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed.
0
Attacker Value
Unknown
CVE-2023-41999
Disclosure Date: November 27, 2023 (last updated December 05, 2023)
An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that require authentication.
0
Attacker Value
Unknown
CVE-2023-41998
Disclosure Date: November 27, 2023 (last updated December 02, 2023)
Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files.
0
Attacker Value
Unknown
CVE-2020-27858
Disclosure Date: January 20, 2021 (last updated February 22, 2025)
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getNews method. Due to the improper restriction of XML External Entity (XXE) references, a specially-crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-11103.
0
Attacker Value
Unknown
CVE-2018-18660
Disclosure Date: October 26, 2018 (last updated November 27, 2024)
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-21 Reflected Cross-site Scripting via /authenticationendpoint/domain.jsp issue.
0
Attacker Value
Unknown
CVE-2018-18658
Disclosure Date: October 26, 2018 (last updated November 27, 2024)
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-20 Unauthenticated Sensitive Information Disclosure via /UDPUpdates/Config/FullUpdateSettings.xml issue.
0