CVE-2015-4069

high
Published 2015-05-29 · Modified 2026-05-06
CVSS v3
CVSS v2
7.8
VIR risk
7.8

Description

The EdgeServiceImpl web service in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive credentials via a crafted SOAP request to the (1) getBackupPolicy or (2) getBackupPolicies method.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://documentation.arcserve.com/Arcserve-UDP/Available/V5/ENU/Bookshelf_Files/HTML/Update%204/UDP_Update4_ReleaseNotes.html

Application impact

VendorProductVersionsFixed
arcservearcserve_unified_data_protection{"endIncluding":"5.0"}

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.