Product:

Serv\-U

(Solarwinds)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 31
Date Id Summary Products Score Patch Annotated
2021-07-14 CVE-2021-35211 Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability. Serv\-U 10.0
2024-05-03 CVE-2024-28072 A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly. Serv\-U 4.9
2022-01-10 CVE-2021-35247 Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U. Serv\-U 5.3
2024-04-17 CVE-2024-28073 SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited. Serv\-U 7.2
2024-06-06 CVE-2024-28995 SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. Serv\-U 7.5
2020-07-07 CVE-2020-15573 SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421. Serv\-U 6.1
2020-07-07 CVE-2020-15574 SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893. Serv\-U 7.5
2020-07-07 CVE-2020-15575 SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194. Serv\-U 6.1
2020-07-07 CVE-2020-15576 SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response. Serv\-U 7.5
2021-02-03 CVE-2020-27994 SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal. Serv\-U 6.5