Solarwinds

Serv-u

39 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 90.32%
  • Veröffentlicht 25.04.2022 20:15:41
  • Zuletzt bearbeitet 21.11.2024 06:12:09

A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.

Warnung
  • EPSS 3.18%
  • Veröffentlicht 10.01.2022 14:10:17
  • Zuletzt bearbeitet 27.10.2025 17:01:25

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been dete...

  • EPSS 0.33%
  • Veröffentlicht 06.12.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:12:08

When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.

  • EPSS 0.59%
  • Veröffentlicht 06.12.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:12:08

Serv-U server responds with valid CSRFToken when the request contains only Session.

  • EPSS 5.28%
  • Veröffentlicht 31.08.2021 16:15:07
  • Zuletzt bearbeitet 21.11.2024 06:12:05

The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of user string variables, allowing remote code execution.

Warnung
  • EPSS 94.32%
  • Veröffentlicht 14.07.2021 21:15:08
  • Zuletzt bearbeitet 27.10.2025 17:01:30

Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. S...

Exploit
  • EPSS 1.76%
  • Veröffentlicht 11.05.2021 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:07:21

Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS."

  • EPSS 2.91%
  • Veröffentlicht 04.05.2021 14:15:08
  • Zuletzt bearbeitet 21.11.2024 06:21:00

An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: this had a distinct fix relative to CVE-2020-35481.

Exploit
  • EPSS 0.41%
  • Veröffentlicht 03.02.2021 17:15:16
  • Zuletzt bearbeitet 21.11.2024 05:54:39

In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world readable and writable. An unprivileged Windows user (having access to the server's filesystem) can add...

  • EPSS 4.26%
  • Veröffentlicht 03.02.2021 16:15:14
  • Zuletzt bearbeitet 21.11.2024 05:27:23

SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.