Improper Authentication in Unified Data Protection - CVE-2024-0799
Published: May 16, 2024
Unified Data Protection
Arcserve
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin. A remote attacker can bypass authentication process and gain unauthorized access to the application.