Show filters
70 Total Results
Displaying 11-20 of 70
Sort by:
Attacker Value
Unknown
CVE-2023-40060
Disclosure Date: September 07, 2023 (last updated October 08, 2023)
A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action.
15.4. SolarWinds found that the issue was not completely fixed in 15.4 Hotfix 1.
0
Attacker Value
Unknown
CVE-2023-35179
Disclosure Date: August 11, 2023 (last updated October 08, 2023)
A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action.
0
Attacker Value
Unknown
CVE-2023-23841
Disclosure Date: June 15, 2023 (last updated November 08, 2023)
SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request. Part of the URL of the request discloses sensitive data.
0
Attacker Value
Unknown
CVE-2022-38106
Disclosure Date: December 16, 2022 (last updated October 08, 2023)
This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.
0
Attacker Value
Unknown
CVE-2021-35252
Disclosure Date: December 16, 2022 (last updated October 08, 2023)
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.
0
Attacker Value
Unknown
CVE-2021-35249
Disclosure Date: May 17, 2022 (last updated November 29, 2024)
This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to. Please note the admin is unable to modify the data (read only operation). This UAC issue leads to a data leak to unauthorized users for a domain, with no log of them accessing the data unless they attempt to modify it. This read-only activity is logged to the original domain and does not specify which domain was accessed.
0
Attacker Value
Unknown
CVE-2021-35250
Disclosure Date: April 25, 2022 (last updated September 17, 2024)
A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.
0
Attacker Value
Unknown
CVE-2021-35242
Disclosure Date: December 06, 2021 (last updated October 07, 2023)
Serv-U server responds with valid CSRFToken when the request contains only Session.
0
Attacker Value
Unknown
CVE-2021-35245
Disclosure Date: December 02, 2021 (last updated November 28, 2024)
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.
0
Attacker Value
Unknown
CVE-2021-35223
Disclosure Date: August 31, 2021 (last updated November 28, 2024)
The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of user string variables, allowing remote code execution.
0