Vulnerabilities > Solarwinds > Serv U

DATE CVE VULNERABILITY TITLE RISK
2023-12-06 CVE-2023-40053 Unspecified vulnerability in Solarwinds Serv-U 15.4.0
A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Serv-U, which could be used maliciously.
network
low complexity
solarwinds
5.0
2023-09-07 CVE-2023-40060 Improper Access Control vulnerability in Solarwinds Serv-U 15.4.0
A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication.
network
low complexity
solarwinds CWE-284
7.2
2023-08-11 CVE-2023-35179 Improper Access Control vulnerability in Solarwinds Serv-U 15.4.0
A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication.
network
low complexity
solarwinds CWE-284
7.2
2023-06-15 CVE-2023-23841 Cleartext Transmission of Sensitive Information vulnerability in Solarwinds Serv-U
SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request.? Part of the URL of the request discloses sensitive data. 
network
low complexity
solarwinds CWE-319
7.5
2022-12-16 CVE-2021-35252 Improper Authentication vulnerability in Solarwinds Serv-U
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server.
network
low complexity
solarwinds CWE-287
7.5
2022-12-16 CVE-2022-38106 Cross-site Scripting vulnerability in Solarwinds Serv-U 15.3.0/15.3.1
This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1.
network
low complexity
solarwinds CWE-79
5.4
2022-05-17 CVE-2021-35249 Unspecified vulnerability in Solarwinds Serv-U
This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to.
network
low complexity
solarwinds
4.3
2022-04-25 CVE-2021-35250 Path Traversal vulnerability in Solarwinds Serv-U 15.3
A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3.
network
low complexity
solarwinds CWE-22
7.5
2022-01-10 CVE-2021-35247 Improper Input Validation vulnerability in Solarwinds Serv-U
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized.
network
low complexity
solarwinds CWE-20
5.0
2021-12-06 CVE-2021-35242 Cross-Site Request Forgery (CSRF) vulnerability in Solarwinds Serv-U
Serv-U server responds with valid CSRFToken when the request contains only Session.
6.8