CVE-2021-35247
SolarWinds Serv-U
Published 10 Jan 2022 · updated 17 Jun 2026 · Analyzed
5.3 Medium · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 21 Jan 2022, with a remediation deadline of 4 Feb 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
References
- documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-3_release_notes.htm · Release Notes, Vendor Advisory
- www.solarwinds.com/trust-center/security-advisories/cve-2021-35247 · Broken Link, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35247 · US Government Resource