PT-2024-15833 · Arcserve · Arcserve Unified Data Protection

Published

2024-03-13

·

Updated

2025-10-14

·

CVE-2024-0800

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arcserve Unified Data Protection versions 8.1 through 9.2
Description A path traversal issue exists in the edge-app-base-webui.jar, specifically affecting the ImportNodeServlet function. This issue is present in the mentioned versions of Arcserve Unified Data Protection.
Recommendations For versions 8.1 through 9.2, consider restricting access to the ImportNodeServlet function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-0800

Affected Products

Arcserve Unified Data Protection