CVE-2015-4069
Arcserve Unified Data Protection Management Service EdgeServiceImpl getBackupPolicies Information Disclosure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The EdgeServiceImpl web service in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive credentials via a crafted SOAP request to the (1) getBackupPolicy or (2) getBackupPolicies method.
El servicio web EdgeServiceImpl en Arcserve UDP anterior a 5.0 Update 4 permite a atacantes remotos obtener información sensible a través de una solicitud SOAP manipulada al método (1) getBackupPolicy o (2) getBackupPolicies.
This vulnerability allows remote attackers to disclose information on vulnerable installations of Arcserve Unified Data Protection. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the getBackupPolicies method of the EdgeServiceImpl web service. By sending a crafted SOAP request, this method will return an individual application's backup policies which contains sensitive credentials. An attacker could use this to create an information disclosure under the context of the SYSTEM user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-05-22 CVE Reserved
- 2015-05-26 CVE Published
- 2024-08-06 CVE Updated
- 2024-10-02 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/74838 | Vdb Entry | |
http://www.zerodayinitiative.com/advisories/ZDI-15-243 | X_refsource_misc | |
http://www.zerodayinitiative.com/advisories/ZDI-15-244 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Arcserve Search vendor "Arcserve" | Arcserve Unified Data Protection Search vendor "Arcserve" for product "Arcserve Unified Data Protection" | <= 5.0 Search vendor "Arcserve" for product "Arcserve Unified Data Protection" and version " <= 5.0" | 3 |
Affected
|