Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
History

Fri, 14 Feb 2025 17:00:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 29 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-01-21'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Sep 2024 03:30:00 +0000

Type Values Removed Values Added
Title Improper Input Validation Vulnerability in Serv-U Improper Input Validation Vulnerability in Serv-U

cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2025-01-29T20:23:27.816Z

Reserved: 2021-06-22T00:00:00.000Z

Link: CVE-2021-35247

cve-icon Vulnrichment

Updated: 2024-08-04T00:33:51.288Z

cve-icon NVD

Status : Analyzed

Published: 2022-01-10T14:10:17.667

Modified: 2025-02-14T16:44:08.310

Link: CVE-2021-35247

cve-icon Redhat

No data.