QID 376260

Date Published: 2022-01-20

QID 376260: SolarWinds Serv-U Improper Input Validation Vulnerability

SolarWinds Serv-U Managed File Transfer Server is a versatile, easy-to-deploy solution that integrates well into existing infrastructure. It allows us to meet all our compliance requirements and ensures peace of mind for file transfers.

The SolarWinds Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized.

Affected versions:
15.2.5 and previous versions

QID Detection Logic(UnAuthenticated):
This QID checks the banner to detect if the device is running vulnerable SolarWinds Serv-U version or not.

Successful exploitation of this vulnerability may allow attackers to build a query given some input and send that query over the network without sanitation.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to install fixed software release Serv-U 15.3 available on the vendor's website. For more information about patch and fixes visit Serv-U 15.3 Security Advisory.
    Vendor References

    CVEs related to QID 376260

    Software Advisories
    Advisory ID Software Component Link
    SolarWinds Serv-U URL Logo www.solarwinds.com/trust-center/security-advisories/cve-2021-35247