Vulnerabilities > Solarwinds > Serv U > 15.1.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-10-16 | CVE-2024-45711 | Path Traversal vulnerability in Solarwinds Serv-U SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. | 8.8 |
2024-10-16 | CVE-2024-45714 | Cross-site Scripting vulnerability in Solarwinds Serv-U Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload. | 4.1 |
2024-06-06 | CVE-2024-28995 | Unspecified vulnerability in Solarwinds Serv-U SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. | 7.5 |
2024-05-03 | CVE-2024-28072 | Unspecified vulnerability in Solarwinds Serv-U A highly privileged account can overwrite arbitrary files on the system with log output. | 4.9 |
2024-04-17 | CVE-2024-28073 | Unspecified vulnerability in Solarwinds Serv-U SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. | 7.2 |
2023-06-15 | CVE-2023-23841 | Cleartext Transmission of Sensitive Information vulnerability in Solarwinds Serv-U SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request.? Part of the URL of the request discloses sensitive data. | 7.5 |
2022-12-16 | CVE-2021-35252 | Improper Authentication vulnerability in Solarwinds Serv-U Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. | 7.5 |
2022-05-17 | CVE-2021-35249 | Unspecified vulnerability in Solarwinds Serv-U This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to. | 4.3 |
2022-01-10 | CVE-2021-35247 | Unspecified vulnerability in Solarwinds Serv-U Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. | 5.3 |
2021-12-06 | CVE-2021-35242 | Cross-Site Request Forgery (CSRF) vulnerability in Solarwinds Serv-U Serv-U server responds with valid CSRFToken when the request contains only Session. | 8.8 |