Product:

Serv\-U

(Solarwinds)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 31
Date Id Summary Products Score Patch Annotated
2024-05-03 CVE-2024-28072 A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly. Serv\-U 4.9
2022-01-10 CVE-2021-35247 Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U. Serv\-U 5.3
2024-04-17 CVE-2024-28073 SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited. Serv\-U 7.2
2024-06-06 CVE-2024-28995 SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. Serv\-U 7.5
2020-07-07 CVE-2020-15573 SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421. Serv\-U 6.1
2020-07-07 CVE-2020-15574 SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893. Serv\-U 7.5
2020-07-07 CVE-2020-15575 SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194. Serv\-U 6.1
2020-07-07 CVE-2020-15576 SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response. Serv\-U 7.5
2021-02-03 CVE-2020-27994 SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal. Serv\-U 6.5
2021-02-03 CVE-2020-28001 SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS. Serv\-U 5.4