CVE-2021-35247
Description
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
Summary dbcve.org
Serv-U's web login screen used for LDAP authentication did not properly sanitize certain input characters, allowing potentially malicious input. SolarWinds has addressed this by implementing additional input validation. No actual exploitation was observed as LDAP servers rejected the improper characters.
Mitigation
Update Serv-U to the latest version to incorporate the improved input validation. Schedule the update during a maintenance window and verify LDAP authentication continues to function properly after the update.