Home/Product/arcserve udp
Product

arcserve udp

16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-34523
< 7.0
A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data Protectio
9.8CRITICAL
CVE-2025-34522
< 7.0
A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw
9.8CRITICAL
CVE-2025-34521
< 7.0
A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), wh
5.4MEDIUM
CVE-2025-34520
< 7.0
An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthor
9.8CRITICAL
CVE-2024-0801
all versions
A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.
7.5HIGH
CVE-2024-0800
all versions
A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.e
8.8HIGH
CVE-2024-0799
all versions
An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.c
9.8CRITICAL
CVE-2023-42000
< 9.2
Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUploa
9.8CRITICAL
CVE-2023-41999
< 9.2
An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authe
9.8CRITICAL
CVE-2023-41998
< 9.2
Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine
9.8CRITICAL
CVE-2023-26258
<= 9.0.6034
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl
9.8CRITICAL
CVE-2018-18660
< 6.5
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-21 Reflected Cross
6.1MEDIUM
CVE-2018-18659
all versions
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-19 Unauthenticated
7.5HIGH
CVE-2018-18658
all versions
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-20 Unauthenticated
7.5HIGH
CVE-2018-18657
all versions
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-18 Unauthenticated
7.5HIGH
CVE-2015-4068
< 5.0
Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or c
9.1CRITICAL
threatengine.sh