Vulnerabilities > Solarwinds > Serv U > 15.1.6

DATE CVE VULNERABILITY TITLE RISK
2021-02-03 CVE-2021-25276 Incorrect Permission Assignment for Critical Resource vulnerability in Solarwinds Serv-U 15.1.6/15.2.1/15.2.2
In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world readable and writable.
local
low complexity
solarwinds CWE-732
3.6
2021-02-03 CVE-2020-35482 Cross-site Scripting vulnerability in Solarwinds Serv-U 15.1.6/15.2.1
SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.
network
solarwinds CWE-79
3.5
2021-02-03 CVE-2020-35481 Unspecified vulnerability in Solarwinds Serv-U 15.1.6/15.2.1
SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
network
low complexity
solarwinds
7.5
2021-02-03 CVE-2020-28001 Cross-site Scripting vulnerability in Solarwinds Serv-U 15.1.6/15.2.1
SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.
network
solarwinds CWE-79
3.5
2021-02-03 CVE-2020-27994 Path Traversal vulnerability in Solarwinds Serv-U 15.1.6/15.2.1
SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.
network
low complexity
solarwinds CWE-22
4.0
2020-07-07 CVE-2020-15576 Information Exposure vulnerability in Solarwinds Serv-U 15.1.6
SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response.
network
low complexity
solarwinds CWE-200
5.0
2020-07-07 CVE-2020-15575 Cross-site Scripting vulnerability in Solarwinds Serv-U 15.1.6
SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194.
network
solarwinds CWE-79
4.3
2020-07-07 CVE-2020-15574 Missing Encryption of Sensitive Data vulnerability in Solarwinds Serv-U 15.1.6
SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893.
network
low complexity
solarwinds CWE-311
5.0
2020-07-07 CVE-2020-15573 Cross-site Scripting vulnerability in Solarwinds Serv-U 15.1.6
SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421.
network
solarwinds CWE-79
4.3
2018-05-16 CVE-2018-10241 NULL Pointer Dereference vulnerability in Solarwinds Serv-U 15.1.6
A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning with the /Web%20Client/ substring.
network
low complexity
solarwinds CWE-476
4.0