Vulnerabilities > Solarwinds > Serv U
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-02-03 | CVE-2020-35481 | Unspecified vulnerability in Solarwinds Serv-U 15.1.6/15.2.1 SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection. | 7.5 |
2021-02-03 | CVE-2020-28001 | Cross-site Scripting vulnerability in Solarwinds Serv-U 15.1.6/15.2.1 SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS. | 3.5 |
2021-02-03 | CVE-2020-27994 | Path Traversal vulnerability in Solarwinds Serv-U 15.1.6/15.2.1 SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal. | 4.0 |
2020-07-07 | CVE-2020-15576 | Information Exposure vulnerability in Solarwinds Serv-U 15.1.6 SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response. | 5.0 |
2020-07-07 | CVE-2020-15575 | Cross-site Scripting vulnerability in Solarwinds Serv-U 15.1.6 SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194. | 4.3 |
2020-07-07 | CVE-2020-15574 | Missing Encryption of Sensitive Data vulnerability in Solarwinds Serv-U 15.1.6 SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893. | 5.0 |
2020-07-07 | CVE-2020-15573 | Cross-site Scripting vulnerability in Solarwinds Serv-U 15.1.6 SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421. | 4.3 |
2018-05-16 | CVE-2018-10241 | NULL Pointer Dereference vulnerability in Solarwinds Serv-U 15.1.6 A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning with the /Web%20Client/ substring. | 4.0 |
2018-05-16 | CVE-2018-10240 | Insufficient Entropy vulnerability in Solarwinds Serv-U 15.1.6 SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. | 5.0 |