PromptRiskDBThreat intelligence atlas

CVE-2021-35247 - SolarWinds Serv-U

AI Vulnerability Context

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to...

Overview

A source-backed snapshot of this vulnerability.

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEVMEDIUM
CVE ID
CVE-2021-35247
Vendor/project
SolarWinds
Product
Serv-U
Vulnerability name
SolarWinds Serv-U Improper Input Validation Vulnerability
Date added
2022-01-21
Due date
2022-02-04
Known ransomware campaign use
Unknown
CVSS v3
4.3
CWE-20

Exploit context

What the vulnerability is about.

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.

Source evidence

Original public records and references for this page.

Original source

Original source links

Open the public records and source datasets used for this page.