CVE-2021-35250
- EPSS 90.32%
- Veröffentlicht 25.04.2022 20:15:41
- Zuletzt bearbeitet 21.11.2024 06:12:09
A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.
CVE-2021-35247
- EPSS 3.18%
- Veröffentlicht 10.01.2022 14:10:17
- Zuletzt bearbeitet 27.10.2025 17:01:25
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been dete...
CVE-2021-35245
- EPSS 0.33%
- Veröffentlicht 06.12.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:08
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.
CVE-2021-35242
- EPSS 0.59%
- Veröffentlicht 06.12.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:08
Serv-U server responds with valid CSRFToken when the request contains only Session.
CVE-2021-35223
- EPSS 5.28%
- Veröffentlicht 31.08.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:05
The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of user string variables, allowing remote code execution.
- EPSS 94.32%
- Veröffentlicht 14.07.2021 21:15:08
- Zuletzt bearbeitet 27.10.2025 17:01:30
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. S...
CVE-2021-32604
- EPSS 1.76%
- Veröffentlicht 11.05.2021 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:21
Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS."
CVE-2021-3154
- EPSS 2.91%
- Veröffentlicht 04.05.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:21:00
An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: this had a distinct fix relative to CVE-2020-35481.
CVE-2021-25276
- EPSS 0.41%
- Veröffentlicht 03.02.2021 17:15:16
- Zuletzt bearbeitet 21.11.2024 05:54:39
In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world readable and writable. An unprivileged Windows user (having access to the server's filesystem) can add...
CVE-2020-35482
- EPSS 4.26%
- Veröffentlicht 03.02.2021 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:27:23
SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.