Vulnerabilities > Solarwinds > Serv U > 15.2.3

DATE CVE VULNERABILITY TITLE RISK
2023-06-15 CVE-2023-23841 Cleartext Transmission of Sensitive Information vulnerability in Solarwinds Serv-U
SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request.? Part of the URL of the request discloses sensitive data. 
network
low complexity
solarwinds CWE-319
7.5
2022-12-16 CVE-2021-35252 Improper Authentication vulnerability in Solarwinds Serv-U
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server.
network
low complexity
solarwinds CWE-287
7.5
2022-05-17 CVE-2021-35249 Unspecified vulnerability in Solarwinds Serv-U
This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to.
network
low complexity
solarwinds
4.3
2022-01-10 CVE-2021-35247 Improper Input Validation vulnerability in Solarwinds Serv-U
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized.
network
low complexity
solarwinds CWE-20
5.0
2021-12-06 CVE-2021-35242 Cross-Site Request Forgery (CSRF) vulnerability in Solarwinds Serv-U
Serv-U server responds with valid CSRFToken when the request contains only Session.
6.8
2021-12-06 CVE-2021-35245 Unspecified vulnerability in Solarwinds Serv-U
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.
network
low complexity
solarwinds
6.8
2021-08-31 CVE-2021-35223 Unspecified vulnerability in Solarwinds Serv-U
The Serv-U File Server allows for events such as user login failures to be audited by executing a command.
network
low complexity
solarwinds
6.5
2021-07-14 CVE-2021-35211 Out-of-bounds Write vulnerability in Solarwinds Serv-U
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability.
network
low complexity
solarwinds CWE-787
critical
10.0