Description
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
No analysis available yet.
Remediation
Vendor Solution
SolarWinds recommends that customers upgrade to SolarWinds Serv-U version 15.4.2 Hotfix 1 as soon as it becomes available.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-25239 | A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly. |
References
History
Tue, 25 Feb 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Solarwinds
Solarwinds serv-u |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:* cpe:2.3:a:solarwinds:serv-u:15.4.2:-:*:*:*:*:*:* |
|
| Vendors & Products |
Solarwinds
Solarwinds serv-u |
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2024-08-02T00:48:48.228Z
Reserved: 2024-03-01T08:53:44.513Z
Link: CVE-2024-28072
Updated: 2024-08-02T00:48:48.228Z
Status : Analyzed
Published: 2024-05-03T08:15:07.217
Modified: 2025-02-25T17:12:45.987
Link: CVE-2024-28072
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD