Solarwinds

Serv-u

55 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.87%
  • Veröffentlicht 07.09.2023 16:15:08
  • Zuletzt bearbeitet 21.11.2024 08:18:37

A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 15.4.  So...

  • EPSS 1.06%
  • Veröffentlicht 11.08.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 08:08:06

A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 

  • EPSS 0.46%
  • Veröffentlicht 15.06.2023 22:15:09
  • Zuletzt bearbeitet 25.02.2026 17:18:56

SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request.  Part of the URL of the request discloses sensitive data.

  • EPSS 0.69%
  • Veröffentlicht 16.12.2022 16:15:22
  • Zuletzt bearbeitet 25.02.2026 16:20:46

This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.

  • EPSS 0.52%
  • Veröffentlicht 16.12.2022 16:15:16
  • Zuletzt bearbeitet 21.11.2024 06:12:09

Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.

  • EPSS 0.71%
  • Veröffentlicht 17.05.2022 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:12:09

This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to. Please note the admin is unable to modify the data (read only operation)....

  • EPSS 12.8%
  • Veröffentlicht 25.04.2022 20:15:41
  • Zuletzt bearbeitet 21.11.2024 06:12:09

A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.

Warnung
  • EPSS 3.45%
  • Veröffentlicht 10.01.2022 14:10:17
  • Zuletzt bearbeitet 27.10.2025 17:01:25

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been dete...

  • EPSS 1.17%
  • Veröffentlicht 06.12.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:12:08

When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.

  • EPSS 0.73%
  • Veröffentlicht 06.12.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:12:08

Serv-U server responds with valid CSRFToken when the request contains only Session.