Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-35247

Опубликовано: 10 янв. 2022
Источник: nvd
CVSS3: 4.3
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*
Версия до 15.3 (исключая)

EPSS

Процентиль: 86%
0.02918
Низкий

4.3 Medium

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.3
github
около 4 лет назад

Serv-U web login screen was allowing characters that were not sanitized by the authentication mechanism. SolarWinds has updated the authentication mechanism to remedy this issue and prevent unauthorized parameters to be used in the Serv-U login screen With the Log4j issue in the wild, input fields across the internet have been tested for vulnerability. Although Serv-U was not affected by the log4j issue, It was discovered that better input validation could be implemented.

CVSS3: 4.7
fstec
около 4 лет назад

Уязвимости функции веб-аутентификации файлового сервера SolarWinds Serv-U File Server, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 86%
0.02918
Низкий

4.3 Medium

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
NVD-CWE-noinfo