Tools

Improper Input Validation Vulnerability in Serv-U (CVE-2021-35247)

This article addresses the Improper Input Validation Vulnerability in Serv-U (CVE-2021-35247)

First published date

1/20/2022 6:15 PM

Last published date

4/29/2022 7:38 AM

Overview

The Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized.
SolarWinds has updated the input mechanism to perform additional validation and sanitization.
Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters.

Affected Product Versions: 
  • 15.2.5 and previous versions. 
  • 15.3.x with Echidna MFA Server an acting LDAP Proxy in customers environment.

Note: Serv-U is not affected by the recent Apache Log4j vulnerability as Serv-U does not utilize Apache.

Product section

Serv-U Managed File Transfer & Serv-U FTP Server

Resolution


How to determine the current Serv-U version:
  1. Launch the Management Console
  2. Go to Global and click on Server Details
  3. Click the Program Information tab and take note of the Serv-U version

image.png

Resolution:
  • Upgrade to Serv-U FTP/MFT version 15.3 or newer. - See the Serv-U Upgrade Guide
  • Exclude below characters from user credentials. 
    / \ [ ] : ; | = , + * ? < > "

Reference Article:
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35247