Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Udp CRITICAL 9.8
CVE-2025-34522

A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered wi…

Fix: 7.0 / 10.2+
Fix from $2,300 2025-08-27
Udp CRITICAL 9.8
CVE-2025-34523

A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data Protection (UDP). This flaw …

Fix: 7.0 / 10.2+
Fix from $2,300 2025-08-27
Udp CRITICAL 9.8
CVE-2025-34520

An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to prot…

Fix: 7.0 / 10.2+
Fix from $2,300 2025-08-27
Udp MEDIUM 5.4
CVE-2025-34521

A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized use…

Fix: 7.0 / 10.2+
Fix from $1,600 2025-08-27
Udp CRITICAL 9.8
CVE-2024-0799

An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app…

No fix yet
Fix from $2,300 2024-03-13
Udp HIGH 8.8
CVE-2024-0800

A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.ser…

No fix yet
Fix from $1,950 2024-03-13
Udp HIGH 7.5
CVE-2024-0801EPSS 42%

A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.

No fix yet
Fix from $1,950 2024-03-13
Udp CRITICAL 9.8
CVE-2023-42000

Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthentic…

Fix: 9.2+
Fix from $2,300 2023-11-27
Udp CRITICAL 9.8
CVE-2023-41998EPSS 15%

Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows …

Fix: 9.2+
Fix from $2,300 2023-11-27
Udp CRITICAL 9.8
CVE-2023-41999

An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifie…

Fix: 9.2+
Fix from $2,300 2023-11-27
Udp CRITICAL 9.8
CVE-2023-26258EPSS 38%

Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID …

Fix: after 9.0.6034
Fix from $2,300 2023-07-03
D2d HIGH 7.5
CVE-2020-27858EPSS 74%

This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not…

Mitigation only
Fix from $1,950 2021-01-20
Udp HIGH 7.5
CVE-2018-18657

An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-18 Unauthenticated Sensitive Informat…

Patch available
Fix from $1,950 2018-10-26
Udp HIGH 7.5
CVE-2018-18658

An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-20 Unauthenticated Sensitive Informat…

Patch available
Fix from $1,950 2018-10-26
Udp HIGH 7.5
CVE-2018-18659

An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-19 Unauthenticated XXE in /management…

Patch available
Fix from $1,950 2018-10-26
Udp MEDIUM 6.1
CVE-2018-18660

An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-21 Reflected Cross-site Scripting via…

Fix: 6.5+
Fix from $1,600 2018-10-26
Arcserve Unified Data Protection HIGH 7.8
CVE-2015-4069

The EdgeServiceImpl web service in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive credentials via a crafted SOAP reques…

Fix: after 5.0
Fix from $1,950 2015-05-29
Udp CRITICAL 9.1
CVE-2015-4068 KEVEPSS 64%

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of se…

Fix: 5.0+
Fix from $2,300 2015-05-29
Brightstor HIGH 7.5
CVE-2006-6641

Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor P…

Fix: after 4.71
Fix from $1,950 2006-12-20