CVE Vulnerabilities

CVE-2024-0799

Improper Authentication

Published: Mar 13, 2024 | Modified: Oct 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Udp Arcserve 8.1 (including) 8.1 (including)
Udp Arcserve 9.2 (including) 9.2 (including)

Potential Mitigations

References