Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
History

Tue, 17 Sep 2024 03:30:00 +0000

Type Values Removed Values Added
Title Improper Input Validation Vulnerability in Serv-U Improper Input Validation Vulnerability in Serv-U

cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published: 2022-01-07T22:39:50.564321Z

Updated: 2024-09-17T03:22:47.259Z

Reserved: 2021-06-22T00:00:00

Link: CVE-2021-35247

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-01-10T14:10:17.667

Modified: 2022-02-10T15:08:52.357

Link: CVE-2021-35247

cve-icon Redhat

No data.