CVE-2021-35247
Improper Input Validation Vulnerability in Serv-U
SolarWinds Serv-U Improper Input Validation Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.
Required action
Apply updates per vendor instructions.
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2021-35247
Description
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NAffected Products
| Vendor | Product | Affected versions |
|---|---|---|
| SolarWinds | Serv-U | 15.2.5 and previous versions to <15.3 |
References
2 LinksRecord Details
More from SolarWinds
SolarWinds Serv-U L Directory Transversal Vulnerability
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
Serv-U Remote Memory Escape Vulnerability
Related Tool Categories
Tool categories that test for or protect against this vulnerability class.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.