Known Vulnerabilities for Serv-u by Solarwinds
Listed below are 10 of the newest known vulnerabilities associated with "Serv-u" by "Solarwinds".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-35250 | A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Se... | 7.5 - HIGH | 2022-04-25 | 2023-08-03 |
| CVE-2021-35249 | This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of ... | 4.3 - MEDIUM | 2022-05-17 | 2022-10-27 |
| CVE-2021-35247 | Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has u... | 5.3 - MEDIUM | 2022-01-10 | 2022-02-10 |
| CVE-2021-35245 | When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the... | 6.8 - MEDIUM | 2021-12-06 | 2022-10-27 |
| CVE-2021-35242 | Serv-U server responds with valid CSRFToken when the request contains only Session. | 8.8 - HIGH | 2021-12-06 | 2021-12-07 |
| CVE-2021-35223 | The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can b... | 8.8 - HIGH | 2021-08-31 | 2021-09-16 |
| CVE-2021-35211 | Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory E... | 10 - CRITICAL | 2021-07-14 | 2023-08-08 |
| CVE-2021-32604 | Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share UR... | 5.4 - MEDIUM | 2021-05-11 | 2022-05-13 |
| CVE-2021-25276 | In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password... | 7.1 - HIGH | 2021-02-03 | 2022-07-12 |
| CVE-2021-3154 | An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via ma... | 7.5 - HIGH | 2021-05-04 | 2022-07-12 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Solarwinds | Serv-u | 15.2.1 | All | All | All |
| Application | Solarwinds | Serv-u | 15.1.6 | All | All | All |