Microsoft · Windows · CVE-2015-2864
**Name of the Vulnerable Software and Affected Versions**
Retrospect versions prior to 10.0.2.119 on Windows
Retrospect versions prior to 12.0.2.116 on OS X
Retrospect versions prior to 10.0.2.104 on Linux
Retrospect Client versions prior to 10.0.2.119 on Windows
Retrospect Client versions prior to 12.0.2.116 on OS X
Retrospect Client versions prior to 10.0.2.104 on Linux
**Description**
The issue improperly generates password hashes, making it easier for remote attackers to bypass authentication and obtain access to backup files by leveraging a collision.
**Recommendations**
For Retrospect and Retrospect Client on Windows, update to version 10.0.2.119 or later.
For Retrospect and Retrospect Client on OS X, update to version 12.0.2.116 or later.
For Retrospect and Retrospect Client on Linux, update to version 10.0.2.104 or later.