Arcserve UDP Agent Unauthenticated Path Traversal File Upload
Vulnerability Description
Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-42000
Credits & Attribution
No credits recorded in the NVD database.
More from Arcserve
View All →Affected Vendor
Arcserve
View all reports →