Unauthenticated Sensitive Information Disclosure in Arcserve Unified Data Protection
CVE-2018-18658
7.5HIGH
What is CVE-2018-18658?
An unauthenticated sensitive information disclosure vulnerability exists in Arcserve Unified Data Protection (UDP) version 6.5 Update 4. This flaw allows attackers to access potentially sensitive configuration information through the endpoint /UDPUpdates/Config/FullUpdateSettings.xml. Successful exploitation can lead to exposure of critical data, compromising the confidentiality of the system. Consequently, organizations using this product should apply the necessary updates and follow security best practices.
