An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.
| Software | From | Fixed in |
|---|---|---|
| arcserve / udp | 8.1 | 8.1.x |
| arcserve / udp | 9.2 | 9.2.x |