Описание
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments.
Ссылки
- Release NotesVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
EPSS
9.1 Critical
CVSS3
Дефекты
Связанные уязвимости
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments.
Уязвимость программного обеспечения для безопасного обмена и передачи файлов SolarWinds Serv-U, связанная с обходом авторизации посредством использования ключа, контролируемого пользователем, позволяющая нарушителю выполнить произвольный код
EPSS
9.1 Critical
CVSS3