CVE-2021-35245: Broken Access Control Vulnerability for SolarWinds Serv-U
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-35245?
CVE-2021-35245 is considered a high-severity vulnerability due to its potential to allow unauthorized file access and modifications by users with admin rights.
How do I fix CVE-2021-35245?
To fix CVE-2021-35245, ensure you apply the latest patches provided by SolarWinds for Serv-U, specifically versions newer than 15.2.4 and 15.2.5.
Who is affected by CVE-2021-35245?
CVE-2021-35245 affects users of SolarWinds Serv-U versions up to 15.2.4 and 15.2.4-hotfix1, and Serv-U version 15.2.5.
What impact does CVE-2021-35245 have?
CVE-2021-35245 allows users with admin rights to manipulate files on the Serv-U host machine, posing data integrity and confidentiality risks.
Is my installation at risk for CVE-2021-35245?
If you are using a vulnerable version of SolarWinds Serv-U, your installation is at risk for CVE-2021-35245.