Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
History

Wed, 22 Oct 2025 00:30:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Fri, 14 Feb 2025 17:00:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 29 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-01-21'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Sep 2024 03:30:00 +0000

Type Values Removed Values Added
Title Improper Input Validation Vulnerability in Serv-U Improper Input Validation Vulnerability in Serv-U

cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published: 2022-01-07T22:39:50.564Z

Updated: 2025-10-21T23:15:49.752Z

Reserved: 2021-06-22T00:00:00.000Z

Link: CVE-2021-35247

cve-icon Vulnrichment

Updated: 2024-08-04T00:33:51.288Z

cve-icon NVD

Status : Modified

Published: 2022-01-10T14:10:17.667

Modified: 2025-10-22T00:17:38.717

Link: CVE-2021-35247

cve-icon Redhat

No data.