Vulnerabilities > CVE-2024-28072 - Unspecified vulnerability in Solarwinds Serv-U
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
Vulnerable Configurations
References
- https://solarwindscore.my.site.com/SuccessCenter/s/article/Serv-U-15-4-2-Hotfix-1-Release-Notes?language=en_US
- https://solarwindscore.my.site.com/SuccessCenter/s/article/Serv-U-15-4-2-Hotfix-1-Release-Notes?language=en_US
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28072
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28072