CVE-2021-35247 - SolarWinds Serv-U
AI Vulnerability ContextServ-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to...
Overview
A source-backed snapshot of this vulnerability.
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2021-35247
- Vendor/project
- SolarWinds
- Product
- Serv-U
- Vulnerability name
- SolarWinds Serv-U Improper Input Validation Vulnerability
- Date added
- 2022-01-21
- Due date
- 2022-02-04
- Known ransomware campaign use
- Unknown
- CVSS v3
- 4.3
Exploit context
What the vulnerability is about.
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
Source evidence
Original public records and references for this page.
Original source
Original source links
Open the public records and source datasets used for this page.
