Tools
Improper Input Validation Vulnerability in Serv-U (CVE-2021-35247)
This article addresses the Improper Input Validation Vulnerability in Serv-U (CVE-2021-35247)
First published date
Last published date
Overview
SolarWinds has updated the input mechanism to perform additional validation and sanitization.
Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters.
Affected Product Versions:
- 15.2.5 and previous versions.
- 15.3.x with Echidna MFA Server an acting LDAP Proxy in customers environment.
Note: Serv-U is not affected by the recent Apache Log4j vulnerability as Serv-U does not utilize Apache.
Product section
Resolution
How to determine the current Serv-U version:
- Launch the Management Console
- Go to Global and click on Server Details
- Click the Program Information tab and take note of the Serv-U version
Resolution:
- Upgrade to Serv-U FTP/MFT version 15.3 or newer. - See the Serv-U Upgrade Guide
- Exclude below characters from user credentials.
/ \ [ ] : ; | = , + * ? < > "
Reference Article:
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35247