Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Serv\-U
(Solarwinds)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 31 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-07-14 | CVE-2021-35211 | Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability. | Serv\-U | 10.0 | ||
2024-05-03 | CVE-2024-28072 | A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly. | Serv\-U | 4.9 | ||
2022-01-10 | CVE-2021-35247 | Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U. | Serv\-U | 5.3 | ||
2024-04-17 | CVE-2024-28073 | SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited. | Serv\-U | 7.2 | ||
2024-06-06 | CVE-2024-28995 | SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. | Serv\-U | 7.5 | ||
2020-07-07 | CVE-2020-15573 | SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421. | Serv\-U | 6.1 | ||
2020-07-07 | CVE-2020-15574 | SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893. | Serv\-U | 7.5 | ||
2020-07-07 | CVE-2020-15575 | SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194. | Serv\-U | 6.1 | ||
2020-07-07 | CVE-2020-15576 | SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response. | Serv\-U | 7.5 | ||
2021-02-03 | CVE-2020-27994 | SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal. | Serv\-U | 6.5 |