CVE-2021-35247
Improper Input Validation Vulnerability in Serv-U
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- June 22, 2021
- Published Date
- January 07, 2022
- Last Updated
- January 29, 2025
- Vendor
- SolarWinds
- Product
- Serv-U
- Description
- Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
- Tags
- Exploitation
- active
- Technical Impact
- partial
- Exploited in the Wild
- Yes (2022-01-21 00:00:00 UTC) Source
cisa
CVSS Scores
CVSS v3.1
4.3 - MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
SSVC Information
Exploit Status
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-01-21 00:00:00 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel