First published: Fri Jan 07 2022(Updated: )
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
Credit: psirt@solarwinds.com psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Serv-U | <15.3 | |
SolarWinds Serv-U | ||
<15.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35247 is a vulnerability in SolarWinds Serv-U that allows unauthorized characters in LDAP authentication, leading to improper input validation.
The severity of CVE-2021-35247 is medium with a CVSS score of 5.3.
CVE-2021-35247 affects SolarWinds Serv-U by allowing characters that were not sufficiently sanitized in the web login screen to LDAP authentication.
Yes, SolarWinds has updated the input mechanism in Serv-U to perform additional validation and sanitization to address CVE-2021-35247.
No downstream effects have been detected as the LDAP servers ignored the improper characters.