CVE-2019-12181: OS Command Injection
Published Jun 17, 2019
·Updated
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
Affected Software
2 affected components
SolarWinds Serv-u Ftp Server Linux<15.1.7
SolarWinds Serv-u Mft Server Linux<15.1.7
Event History
Jun 17, 2019
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
Description
Frequently Asked Questions
1
What is CVE-2019-12181?
CVE-2019-12181 is a privilege escalation vulnerability in SolarWinds Serv-U before version 15.1.7 for Linux.
2
What is the severity of CVE-2019-12181?
CVE-2019-12181 has a severity score of 8.8 (high).
3
Which software is affected by CVE-2019-12181?
SolarWinds Serv-U FTP Server and SolarWinds Serv-U MFT Server versions before 15.1.7 for Linux are affected by CVE-2019-12181.
4
How can I fix CVE-2019-12181?
To fix CVE-2019-12181, upgrade SolarWinds Serv-U FTP Server and SolarWinds Serv-U MFT Server to version 15.1.7 or later on Linux.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-12181?
The Common Weakness Enumeration (CWE) ID for CVE-2019-12181 is CWE-78.