MEDIUM

CVE-2021-35247

Solarwinds Serv U 2022-01-10 CVSS v3.1
CVSS
5.3
KEV

Description

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.

Summary dbcve.org

Serv-U's web login screen used for LDAP authentication did not properly sanitize certain input characters, allowing potentially malicious input. SolarWinds has addressed this by implementing additional input validation. No actual exploitation was observed as LDAP servers rejected the improper characters.

Mitigation

Update Serv-U to the latest version to incorporate the improved input validation. Schedule the update during a maintenance window and verify LDAP authentication continues to function properly after the update.

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

3.45%
Probability of exploitation in next 30 days
88.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE