Arcserve Unified Data Protection - Authentication Bypass
An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin. References: https://www.tenable.com/security/research/tra-2024-07 https://nvd.nist.gov/vuln/detail/CVE-2024-0799 Remediation: Update to the latest version of Arcserve Unified Data Protection or apply security patches provided by the vendor.
Used 3k times · domain, subdomain, ipv4