Vulnerabilities > Solarwinds > Serv U > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-16 CVE-2024-45711 Path Traversal vulnerability in Solarwinds Serv-U
SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user.
network
low complexity
solarwinds CWE-22
8.8
2024-06-06 CVE-2024-28995 Path Traversal vulnerability in Solarwinds Serv-U
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
network
low complexity
solarwinds CWE-22
7.5
2023-09-07 CVE-2023-40060 Improper Access Control vulnerability in Solarwinds Serv-U 15.4.0
A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication.
network
low complexity
solarwinds CWE-284
7.2
2023-08-11 CVE-2023-35179 Improper Access Control vulnerability in Solarwinds Serv-U 15.4.0
A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication.
network
low complexity
solarwinds CWE-284
7.2
2023-06-15 CVE-2023-23841 Cleartext Transmission of Sensitive Information vulnerability in Solarwinds Serv-U
SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request.? Part of the URL of the request discloses sensitive data. 
network
low complexity
solarwinds CWE-319
7.5
2022-12-16 CVE-2021-35252 Improper Authentication vulnerability in Solarwinds Serv-U
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server.
network
low complexity
solarwinds CWE-287
7.5
2022-04-25 CVE-2021-35250 Path Traversal vulnerability in Solarwinds Serv-U 15.3
A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3.
network
low complexity
solarwinds CWE-22
7.5
2021-02-03 CVE-2020-35481 Unspecified vulnerability in Solarwinds Serv-U 15.1.6/15.2.1
SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
network
low complexity
solarwinds
7.5