QID 376260
Date Published: 2022-01-20
QID 376260: SolarWinds Serv-U Improper Input Validation Vulnerability
SolarWinds Serv-U Managed File Transfer Server is a versatile, easy-to-deploy solution that integrates well into existing infrastructure. It allows us to meet all our compliance requirements and ensures peace of mind for file transfers.
The SolarWinds Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized.
Affected versions:
15.2.5 and previous versions
QID Detection Logic(UnAuthenticated):
This QID checks the banner to detect if the device is running vulnerable SolarWinds Serv-U version or not.
Successful exploitation of this vulnerability may allow attackers to build a query given some input and send that query over the network without sanitation.
Solution
Customers are advised to install fixed software release Serv-U 15.3 available on the vendor's website.
For more information about patch and fixes visit Serv-U 15.3 Security Advisory.
Vendor References
- SolarWinds Trust Center Security Advisories -
www.solarwinds.com/trust-center/security-advisories/cve-2021-35247
CVEs related to QID 376260
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SolarWinds Serv-U |
|