{"id":"CVE-2015-4068","aliases":[],"url":"https://o3.security/vulnerability/CVE-2015-4068","summary":"Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to…","details":"Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.","published":"2015-05-29T15:00:00.000Z","modified":"2025-10-21T23:56:01.094Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"},"epss":{"score":0.63643,"percentile":0.99154,"asOf":"2026-08-27"},"cisaKev":{"dateAdded":"2022-03-25","dueDate":"2022-04-15","knownRansomwareCampaignUse":false},"exploitsKnown":1,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"http://www.zerodayinitiative.com/advisories/ZDI-15-242/"},{"type":"WEB","url":"http://www.securityfocus.com/bid/74845"},{"type":"WEB","url":"http://documentation.arcserve.com/Arcserve-UDP/Available/V5/ENU/Bookshelf_Files/HTML/Update%204/UDP_Update4_ReleaseNotes.html"},{"type":"WEB","url":"http://www.zerodayinitiative.com/advisories/ZDI-15-241/"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-4068"}],"provenance":{"sources":["OSV.dev","NVD","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2025-10-21T23:56:01.094Z"}}